Senior Cybersecurity Threat Investigator

CiscoSan Jose, CA
256d$155,900 - $195,200Remote

About The Position

The successful applicant will be performing work in FedRAMP High or IL-5 environments, and therefore, must be a U.S. Person (i.e. U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee). This position may also perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil. Security Visibility and Incident Command (SVIC) is part of the investigative branch of Cisco's Security and Trust Organization (S&TO) and serves as Cisco's information security, cyber investigations, and forensics team. We provide Cisco with tailored security monitoring services to protect the company from cyber-attacks and the loss of its intellectual assets. The primary mission of SVIC is to ensure company, system, and data preservation by performing comprehensive investigations into computer security incidents. Our mission also extends to assisting in the prevention of such incidents by engaging in root cause analysis, dedicated threat assessment, mitigation planning, and architectural review. SVIC is a highly skilled, diverse, and globally distributed group of outstanding professionals from a wide variety of technical backgrounds. We are open-source software contributors, technical authors, tool builders, DFIR community members, lock pickers, makers, and breakers. SVIC is looking for an experienced security professional to join our Security Investigations Team, which is our top-tier investigative body.

Requirements

  • 7+ years' experience in technical roles in Information Technology and / or Information Security or Cybersecurity.
  • Experience in networking and core Internet protocols (e.g., TCP/IP, DNS, SMTP, HTTP, and distributed networks).
  • Experience with Linux/UNIX systems and the standard methodologies for deploying applications to those stacks.
  • Experienced in data querying and data analysis.
  • Experience working with third party cloud and virtualization platforms, e.g. AWS, GCP, Azure, VMware.

Nice To Haves

  • Reasonable scripting/coding abilities to effectively recognize and implement automation opportunities.
  • Familiarity with Windows Server and Active Directory administration.

Responsibilities

  • Respond to and investigate computer security incidents, assessing the scope of impact and guiding the teams involved in the investigation to containment and resolution.
  • Communicate incident root cause analysis with management and partner teams.
  • Research and deploy new technologies as needed to support business objectives related to security detection, threat hunting, forensics and response.
  • Collaborate with data source SMEs in SVIC and InfoSec to enhance, improve, or modify cloud-based security detection and response.
  • Continuously strive to improve processes for high-accuracy attack detection and response as attacker tactics and techniques evolve, setting up our SOC Analysts for success.
  • Apply and cultivate your expertise in the subject areas you are passionate about, to guide SVIC towards innovative ways of doing things.
  • Participate in a follow-the-sun on-call rotation.
  • As a senior member of SVIC, guide and mentor our security analysis / detection engineers.

Benefits

  • Medical, dental and vision insurance.
  • 401(k) plan with a Cisco matching contribution.
  • Short and long-term disability coverage.
  • Basic life insurance.
  • Numerous wellbeing offerings.
  • Up to twelve paid holidays per calendar year, including one floating holiday.
  • Flexible Vacation Time Off policy for exempt new hires.
  • Sick Time Off policy with 80 hours provided on hire date and annually.
  • Paid time away to deal with critical or emergency issues.
  • Additional paid time to volunteer and give back to the community.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service