CyberArk the global leader in Identity Security is looking for a skilled and passionate Senior DFIR & Threat Hunting Researcher to join its Global Information Security Team. In this role you will conduct digital forensics and threathunting activities across CyberArks global network endpoints and cloud environments. You will also research and develop new methods and tools to enhance the detection and response capabilities of the CyberArk Information Security team.
Responsibilities:
- Digital Forensics and Incident Response (DFIR):
- Perform digital forensics analysis on various types of evidence such as disk memory network and cloud artifacts (AWS advantage).
- Support incident response efforts by providing technical expertise containment eradication and recovery guidance.
- Maintain and operate forensic tools and platforms ensuring they are uptodate and reliable.
- Document and report on forensic findings and recommendations following the established procedures and standards.
- Threat Hunting:
- Proactively hunt for malicious activity and indicators of compromise across CyberArks network endpoints and cloud environments using various data sources and analytical techniques.
- Develop and refine custom threathunting hypotheses queries and dashboards based on the latest threat intelligence and trends.
- Collaborate with the SOC team to validate escalate and respond to identified threats.
- Research and Development:
- Research emerging threats attack vectors threat actors ATPs security technologies and CyberArk products and share insights and best practices with the team and the broader security community.
- Develop and improve tools scripts correlation alerts and automation to enhance the SOC teams DFIR and threathunting capabilities.
#LIJH1
Qualifications :
- Proven (5 years) experience in digital forensics and incident response preferably in a tech company or a security consulting firm.
- Handson experience with industry standard forensic tools and platforms.
- Handson experience with threat hunting tools query languages and platforms such as ELK Splunk QRadar KQL SQL etc.
- Strong knowledge of network protocols operating systems malware analysis and cloud security.
- Ability to automate tasks using a scripting language such as Python & JS.
- Excellent communication and interpersonal skills.
- Excellent proficiency in English both written and verbal is a must.
- Curious and creative mindset with a passion for learning and solving complex problems.
- Ability to work independently and collaboratively in a fastpaced dynamic environment and with a multiregion team.
Additional Information :
CyberArk is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race color religion creed sex sexual orientation gender identity national origin disability or protected Veteran status.
The salary range for this position is $150000 $210000/year plus commissions or discretionary bonus which will be based on the employees performance. Base pay may also vary considerably depending on jobrelated knowledge skills and experience. The compensation package includes a wide range of medical dental vision financial and other benefits.
Remote Work :
Yes
Employment Type :
Fulltime