Project information:
Key components of this project include:
Responsibilities:
Investigation and Support: Conduct investigations and provide remediation support to IT teams
Procedure Development and Updates: Contribute to the creation and updating of procedures (incident response, crisis management with CERT, etc.)
Continuous Improvement of Detection Capabilities: Enhance detection capabilities through detection rules, integration of new sensors, logging policies, etc
Reporting and Dashboard Creation: Produce reports and develop dashboards
Client Projects: Participate in client security hardening projects
Location:
Salary:
Requirements:
Experience with SIEM or XDR Splunk - must have
Knowledge of other XDR tools like Sekoia, Sentinel, is a big plus
Security solutions like EDR (Sysmon, CrowdStrike, Sentinel One), proxy, etc.
Common production environments: network (TCP/IP), systems (Windows, Unix), applications, and Cloud (AWS, Azure)
Best practices for logging and attack methodologies across various security solutions
Incident tracking tools (SIRP)
Advanced investigations (Threat Hunting) is a plus
Knowledge of SOAR, proficiency in threat hunting, and development skills (e.g., Python) are advantages
Familiarity with the standard process for handling security incidents, as documented in NIST
We offer:
We proudly deliver to the leaders across industries.