Job Summary:
THE TEAM The Cyber Defense and Incident Response team operates within the Corporate Information Security and Privacy Organization and are a critical function within Live Nation Entertainment. We specialize in detecting and responding to adverse events within our global network and provide snap response times to mitigate the impact of potential threats.
THE ROLEAs Manager of the Cyber Defense team, you will provide the first layer of defense by continuously improving current detections through innovative automation techniques that improve detection and response times to intercept and defend against cyberattacks.
You will be the subject matter expert in all things related to threat detection and response. Learning how the adversary operates and their key objectives is imperative to protecting and defending against damage to mission-critical systems. Detecting these precursors allow the team to respond quickly to reduce the risk to the organization.
You will work with a team that shares a common goal: continuously improving threat detection and response by building a strong team of SMEs who share ownership of the mission and the duty to protect the global organization.
We are growing our team to provide threat detection and incident response capabilities for Live Nation Entertainment; this is an exciting time to join!
WHAT THIS ROLE WILL DO- Prepare, detect, respond and mitigate against cyber threats, protecting Live Nation Entertainment data and assets utilizing industry information security best practices
- Lead a geographically dispersed team of technical detection and response analysts who are responsible for monitoring, detecting, triaging, and responding to security events and incidents in Live Nation Entertainment's 24x7 global network
- Implementation of detection methodologies with a solid understanding of how to baseline network traffic and monitor for anomalous activity for early detection and mitigation
- Responsible for all management activities related to the Threat Detection and Response team's operations including people management, training, and mentoring of direct reports
- Leverage automation and orchestration solutions to automate repetitive tasks
- Network, collaborate and engage multiple internal and external teams and subject matter experts to address cyber security issues to reduce overall organizational risk
- Contribute to and support team projects and strategic initiatives, including improving current workflows and processes to mature our monitoring and response capabilities
- Assist with incident response as events are escalated to include threat hunting, data collection/analysis, triage, containment, remediation and documentation
- Champion process documentation and lessons learned to improve team efficiency and consistency for scalable response operations to ensure continuous improvement of internal playbooks
- Develop and deliver metrics that measure the team's efficiency and effectiveness to leadership
- Manage career development for team members, including training and mentoring, conducting performance reviews and exhibiting behaviors to be modeled by team members
- Drive a culture of inclusiveness and team unity to deliver exceptional customer services within the team and to our partner teams
- Research and stay current on the latest trends, best practices, and technology developments
- Participate in on-call weekly rotations with other team members (Required)
WHAT THIS PERSON WILL BRING - REQUIRED - 8+ years of Information Technology experience
- Member of a Security Operations Center (SOC)
- Security Incident Response Analyst or supporting function (2 years minimum)
- eDiscovery or related role performing forensic functions
- 2+ years of Information Security and Incident Response or similar discipline
- 2+ years of Linux/Unix, Mac and Windows system analysis experience
- Technical Cyber Security Certification(s) required (min. 1): GCED, GCDA, GDAT etc.
- BA/BS in Computer Science, Information Security, or Information Systems or equivalent related work experience
- Experience working in a large enterprise and management of a wide range of security tools such as IDS/IPS (network and host), advanced anti-malware (network and endpoint), DLP, encryption, anti-virus, firewalls, identity management, NAC, etc.
- Familiarity with security standards NIST Cyber Security Framework, NIST SP800-61 R2 and ISO/IEC 27035
- Experience with threat modeling concepts such as threat indicators, threats actors and attack surfaces
- Understanding of network architecture and security infrastructure placement
- Experience with SIEM technologies (i.e. ArcSight, Splunk, Elk Stack)
- In-depth technical knowledge of Windows and Unix/Linux based operating systems
- Travel is at a minimum, but some domestic and international travel is required
- Must be willing to be available 24x7 during weekly on-call rotations
- Must be willing to work non-traditional hours which may occur over weekends and holidays in support of incidents as needed
- Exceptional ability to remain calm under stress
- Must be able to pass a criminal background check and a U.S. government security clearance if requested
WHAT THIS PERSON WILL BRING - TECHNICAL SKILLS- Identify and understand how malware and threat actors operate at a functional level, as well as understanding their main objectives, to reduce the potential spread and impact
- Demonstrate knowledge of relevant data sources to log in the SIEM
- Utilize threat detection and other tools to analyze event logs to prevent and detect adversary attacks
- Experience with containment, eradication, and remediation while preserving forensic artifacts for analysis
- Practical level of understanding of security benchmarks and hardening of devices to reduce their attack surface, both physical and cloud devices
- Innovative Content Development. Develop detection rules that perform aggregate and correlated activity detections across the security stack leveraging API automation integrations
- Experience with escalating and participating in small- and large-scale incident response activities to include threat hunting, containment, and remediation
- Technical Savvy. Must be able to design and implement dashboards, reports and queries using various query and scripting languages
- Ability to reverse engineer how a network or endpoint was compromised to develop new detections to prevent future attacks of the same
- Consistent and proven ability to generate well-organized notes at a high-level and ability to document timelines of events and incidents in the internal ticketing system
WHAT THIS PERSON WILL BRING - BEHAVIORS AND SKILLS - Strong sense of moral character, high-ethical standards, servant-leader and accountability
- Very strong leadership skills with the ability to maintain team composure during times of high stress
- Highly meticulous with exceptional attention to detail
- Analytical and strategic mindset to overcome obstacles and solve complex problems
- Have a global mind-set for working with different cultures and backgrounds
- Strong organizational and time-management skills with the ability to complete tasks assigned in a timely manner
- Ability to develop team projects and execute strategic initiatives to completion
- Strong negotiation, influence, mediation & conflict management skills
- Embraces mentorship, knowledge sharing and teaming skills
- Excellent English written and verbal communication skills, additional languages is a plus
- Excellent customer service skills required
- Flexible and responsive to changing situations
- Self-driven, self-disciplined to perform tasks and complete projects with little to no supervision, with a high sense of duty
This job description is a summary of duties that are expected to be performed. Duties outlined in this job description may not be all-inclusive and can be modified at any time if requested by management.
BENEFITS & PERKSOur motto is 'Taking Care of Our Own' through 6 pillars of benefits:
- HEALTH: Medical, vision, dental and mental health benefits for you and your family, with access to a health care concierge, and Flexible or Health Savings Accounts (FSA or HSA)
- YOURSELF: Free concert tickets, generous paid time off including paid holidays, sick time, and personal days
- WEALTH: 401(k) program with company match, stock reimbursement program
- FAMILY: New parent programs including caregiver leave and baby bonuses, plus fertility, adoption, foster, or surrogacy support
- CAREER: Career and skill development programs with School of Live, tuition reimbursement, and student loan repayment
- OTHERS: Volunteer time off, crowdfunding match
This job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.
Live Nation recruitment policies are designed to place the most highly qualified persons available in a timely and efficient manner. Live Nation may pursue all avenues available, including promotion from within, employee referrals, outside advertising, employment agencies, internet recruiting, job fairs, college recruiting and search firms.
#LI-EF1
#LI-REMOTEUNITEDSTATES
Live Nation Entertainment will never request payment or equipment purchases as part of the hiring process. Recruiters will only contact candidates from official Live Nation or affiliated brand email domains.