Perform security assessments of business-initiated projects and technologies (e.g., python-based web stacks) to drive the adoption of application and infrastructure security controls, ensuring security and privacy by design. Partner with technical teams on major technology initiatives to ensure security and "detection by design" principles are integrated at the outset of the system development lifecycle (SDLC). Advise on engineering solutions to protect the firm’s network and Cloud architectures (e.g., AWS or Azure) from security risks related to web services, mobile applications, and client/server environments. Review security controls across diverse systems to identify gaps and drive the implementation of technical mitigations, including cryptographic implementations and data model assessments. Collaborate with global teams to enhance detection effectiveness by providing technical input on sensory tool uplift, logging telemetry, and the tuning of SIEM/EDR detection logic. Execute hypothesis-driven threat hunting missions across enterprise infrastructure to identify undetected malicious activity using threat intelligence and statistical analysis (e.g., stack counting, outlier detection). Develop detection strategies and incident response playbooks to protect the firm from advanced persistent threats (APTs) targeting hybrid environments and mobile applications. Convey complex forensic and threat analyses via comprehensive presentations and incident post-mortems to senior stakeholders and engineering teams. Drive the implementation and optimization of security sensors and logging configurations across various platforms by collaborating with technology infrastructure teams to ensure full visibility for the SOC.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Entry Level