Requirements
Experience:
35 years of experience in cybersecurity
Minimum of 35 years in cybersecurity roles such as Threat Hunter or Detection Engineer.
Demonstrated success in developing and refining detection mechanisms in enterprise environments.
Requirements:
Threat Detection Expertise:
Experience with endpoint detection and response (EDR) solutions (e.g. CrowdStrike FortiEDR Defender for Endpoint).
Familiarity with behavioural analytics and anomaly detection techniques.
Threat Intelligence and Analysis:
Understanding of threat intelligence sources (e.g. MITRE ATT&CK D3FEND) and their application in detection strategies.
Ability to research and adapt to emerging threats and attack methodologies.
Programming and Automation:
Scripting skills in Python PowerShell or Bash for automating security tasks.
Experience developing integrations and automated workflows using APIs.
Cloud and Network Security:
Handson experience with cloud security tools (e.g. AWS GuardDuty Azure Security Center).
Indepth knowledge of IP networks firewalls intrusion detection/prevention systems (IDS/IPS) and packet analysis.
Operating Systems:
Strong knowledge of Linux and Windows internals including log analysis and common attack vectors.
Tool Proficiency:
Familiarity with opensource tools like Zeek Falco Wireshark and OSQuery.
Knowledge of malware analysis tools and techniques.
Other Skills:
Collaboration and Communication:
o Ability to work effectively with crossfunctional teams including Incident Response IT and Risk Management.
o Strong written and verbal communication skills to document detection logic and present findings to technical and nontechnical stakeholders.
Problem Solving and Analytical Thinking:
o Excellent troubleshooting skills for identifying root causes of detected threats.
o Analytical mindset to assess complex technical issues and develop creative detection solutions.
Adaptability and Continuous Learning:
o Ability to quickly adapt to new technologies frameworks and threat landscapes.
o Willingness to stay current with industry trends and certifications.
Attention to Detail:
o High level of precision in rule creation and tuning to minimize false positives and ensure detection accuracy.
Languages: English (High level)
Certifications:
Certified Detection Analyst (CDA)
Certified Red Team Professional (CRTP) or expert (CRTE)
Certified Azure Red Team Professional (CARTP) or expert (CARTE)
OffSec Certified Professional (OSCP)
GIAC Defending Advanced Threats (GDAT)