3
Security Engineer – Incident Response and Digital Forensics SpearTip - Mission Statement Blend cutting-edge technologies, unique skill sets and proven military cyber counterintelligence strategies, SpearTip partners with our Partners to protect shareholder value, shield corporate reputations and enhance long-term profits. Core Values Position Description This position will be responsible for protecting company assets including information systems, networks, devices, and data from threats, such as security breaches, computer viruses or attacks by cyber-criminals. A key focus on this position is on SpearTip’s Incident Response and Digital Forensics engagements. Characteristics Requirements Not all of the following requirements are expected for every potential candidate. SpearTip considers both the character of person and their experience when making hiring decisions. For a strong candidate, SpearTip is willing to offer training (internal and external) to fill necessary knowledge gaps. Personal Attributes: Creative brainstormer willing to build solutions collaboratively to solve complex cyber security problems Self-motivated, decisive decision maker with the ability to take ownership and willingness to be accountable Willing to stick with difficult problems to consistently produce the best solution for our partners and willing to champion new technology and different approaches Desires to be immersed in a training culture to both develop others and improve self

Security Engineer - Incident Response and Digital Forensics · 2020-05-13 · Security Engineer – Incident Response and Digital Forensics SpearTip - Mission Statement Blend cutting-edge

  • Upload
    others

  • View
    17

  • Download
    0

Embed Size (px)

Citation preview

SecurityEngineer–IncidentResponseandDigitalForensics

SpearTip-MissionStatementBlendcutting-edgetechnologies,uniqueskillsetsandprovenmilitarycybercounterintelligencestrategies,SpearTippartnerswithourPartnerstoprotectshareholdervalue,shieldcorporatereputationsandenhancelong-termprofits.CoreValues

PositionDescriptionThispositionwillberesponsibleforprotectingcompanyassetsincludinginformationsystems,networks,devices,anddatafromthreats,suchassecuritybreaches,computervirusesorattacksbycyber-criminals.AkeyfocusonthispositionisonSpearTip’sIncidentResponseandDigitalForensicsengagements.CharacteristicsRequirementsNotallofthefollowingrequirementsareexpectedforeverypotentialcandidate.SpearTipconsidersboththecharacterofpersonandtheirexperiencewhenmakinghiringdecisions.Forastrongcandidate,SpearTipiswillingtooffertraining(internalandexternal)tofillnecessaryknowledgegaps.

PersonalAttributes: Creativebrainstormerwillingtobuildsolutionscollaborativelytosolvecomplexcybersecurityproblems

Self-motivated,decisivedecisionmakerwiththeabilitytotakeownershipandwillingnesstobeaccountable

Willingtostickwithdifficultproblemstoconsistentlyproducethebestsolutionforourpartnersandwillingtochampionnewtechnologyanddifferentapproaches

Desirestobeimmersedinatrainingculturetobothdevelopothersandimproveself

EducationalandExperience:

ComputerScience,Cybersecurity,orInformationSystemsBachelor’sDegreeorequivalentprofessionalexperienceinadevelopmentorIToperationsrole

Oneintermediatecybersecuritycertification–desiredbutnotrequired(e.g.GCIH,GCFA,CHFI,CySA+,etc.)

Proficientinincidenthandlingprocedures(NIST.SP.800-61r2) Experienceorknowledgeofwithdigitalforensictools(forexample,FTK,EnCase,MagnetAxiom) Experienceorknowledgeofmemoryforensictools(forexample,Volatility) Experienceorknowledgeofenterprisedetectionandresponsetools(CarbonBlack,CrowdStrike,SentinelOne,Cylance,etc.)

ExperienceorknowledgeofSIEMtools(SplunkorLogRhythm) ProficientinWindowsandLinuxoperatingsystems Proficientincomputernetworkingconcepts

Responsibilities: Responsibleforleadingorparticipatinginonsiteincidentresponseanddigitalengagements Maintainchainofcustodyandproperevidencehandlingproceduresduringengagements Whenrequiredbythenatureoftheengagement,actasaconsultingorexpertcourtwitness Datacollection,analysis,andreportwriting-collectanddocumentthetimelineofevents,collect,analyze,andvalidatefindings,andprovide“bestpractice”recommendationstotheclient;withtheunderstandingthatyourrecommendationshavesignificantimpacttoclientoperations

Assistintriageandvalidationofalertsfromenterprisedetectionandresponsetools MaintainandcultivateworkingknowledgeofAxiom,ShadowSpear,Paladin,SpearPortal,FTK,andadditionalDigitalForensicsandManagedDetectionandResponsetools

Problemsolve;independentlyandinateamenvironment Exercisingindependentjudgmentanddiscretion,communicate/coordinatewithclientsregardingalerts,projectupdates,andprojectstatusthroughoutanengagement

Responsibleforthetimelycompletionofengagementsandappropriatelycommunicateprojectstatusandworkloadtocompanyleadershipthroughtherequiredchannels

Maintaincurrentcertifications(asapplicable) Whenappropriate,problemsolveindependentlyandinateamenvironment Beavailableforshort-termperiodictraveltosupportregional,national,andinternationalclients BewillingtoworktowardsnewcertificationswithpropertrainingatSpearTip’sexpenseatthediscretionofcompanyleadership

AttendandactivelyparticipateintheOperationsL10MeetingsandEOSprocess Responsibilitiessubjecttochangeatthediscretionofcompanyleadership ProjectManagement-Exercisingindependentjudgmentanddiscretion,communicate/coordinatewithclientsregardingalerts,projectupdates,andprojectstatusthroughoutanengagement

Benefits:

HealthInsuranceCoverage–100%coverageplan,currentemployeecontributionis$0 Dental&VisionCoverage–currentemployeecontributionis$0 Participationin401(K)Plan,employermatchof100%fortheinitial3%ofcontributionand50%fornext2%ofcontributedfunds,immediatevesting

SpearTipapprovedholidays(currently8approvedholidays) Personalleavedays