The ideal candidate brings a strong background in Amazon Web Services (AWS), Azure or Oracle, cyber development, scripting, and automation, coupled with deep expertise in Security Information and Event Management (SIEM) tools.
Responsibilities- Systems Design & Architecture: Consult on the design, architecture, and implementation of cloud security monitoring systems at enterprise scale
- Development and Scripting: Develop and maintain scripts and automation tools using Python or similar programming languages
- Automation and Orchestration: Design and implement automated incident response playbooks to streamline CSOC processes
- Collaboration and Mentorship: Work closely with CSOC team members to share insights and coordinate response efforts. Provide technical expertise and mentorship to junior staff; plan and implement cyber exercises and drills to sharpen team skills; and prepare reference and training materials for cloud and incident response.
- Continuous Improvement: Stay current on cybersecurity trends, threats, and technologies. Identify opportunities for process improvement and implement best practices. Maintain up-to-date knowledge of relevant AI concepts pertaining to cloud and incident response security.
- Splunk Detection Development: Develop, tune, and optimize detection rules for AWS and other cloud-based platforms using Splunk Query Language
Requirements- TS/SCI FSP Clearance
- 7+ years of experience with cloud security, cloud engineering or cyber operations
- 7+ years of experience with Operating Systems, Network Infrastructure, Security Principles or System Architecture
- 5+ years of experience with AWS
- 3+ years of experience coding and scripting in Python