Jobs and Careers
EX

Manager, GSOC Cyber Signal Engineering - 100% US Remote

Experian
United StatesRemotefull_timeVerifiedPosted 10 Jan 2023

About the role

Company Description

Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years we’ve been name in the 100 “World’s Most Innovative Companies” by Forbes Magazine.

Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years we’ve been name in the 100 “World’s Most Innovative Companies” by Forbes Magazine.

Job Description

Global Security Operations Center’s mission is to protect the confidentiality, integrity, and availability of all Experian assets by executing and maintaining the incident response framework. The GSOC proactively and iteratively identify new attacks or attacks underway and then coordinate containment and remediation to minimize the impact as quickly as possible. The GSOC recognizes the importance of effective and efficient content to generate high fidelity alerts and investigations. The Cyber Signal Engineering Manager will be responsible for curating, prioritizing, and driving closure on all the GSOC content development tasks and use case requests based on the mission requirements and future initiatives.

 

Responsibilities:

·       Develop and mature a world class cyber threat content research and development team.

·       Support operational leadership tasking as it relates to content development functions and responsibilities.

·       Lead a highly skilled and motivated team of threat content developers

·       Manage and maintain operational content for global threat detection and liaison as the primary point of contact for the GSOC with security engineering and external stakeholders.

·       Performing activities within the use case life cycle and MITRE ATT&CK Framework prioritized by cyber threat intelligence and situational awareness.

·       Drive MITRE ATT&CK roadmap and threat informed use cases across all security tooling, and highlight required log sources for operationalizing rules

·       Stay on top of ongoing cyber threats and embed intelligence driven incident response by producing emerging content derived from IOCs and TTPs.

·       Drive research and development of use case creation and refinement of rules and logic within SIEM/UEBA/EDR platforms to improve GSOC efficiency and effectiveness.

·       Proactive housekeeping and documentation of associated use cases with consideration for revisions, decommissioning, and metrics and reporting.

·       Effectively collaborate with colleagues and the other security functions and product SMEs internally and externally to identify gaps within the existing analytical capabilities.

·       Acting as the liaison to fulfill audit, regulatory compliance as well as corporate security policy requirements.

 

Qualifications

Required Experience: 5 years’ experience in the following areas:

·       Working knowledge of SIEM technologies and an understanding of their underlying content and alerting logic

·       In-depth packet analysis skills, core forensic familiarity, strong incident handling/incident response/security analytics skills, and data fusion skills based on multiple security data sources

·       Defensive network infrastructure (operations or engineering)

·       Malware analysis concepts, techniques, and reverse engineering

·       In-depth knowledge of network and host security technologies and products (such as firewalls, network IDS, scanners) and continuously improve these skills

·       Deep understanding of security monitoring technologies, such as WAF, Web Proxies, UEBA, DLP, among others.

·       Extensive knowledge of MITRE ATT&CK framework and its uses.

Demonstrates behavioral skills, such as:

·       Demonstrated ability to work in a team environment, able to train and coach other team members

·       Excellent verbal and written communications skills and ability to produce clear and thorough security incident reports and briefings.

·       Strong logical thinking abilities, especially with content logic

·       Excellent analytical and problem-solving abilities

·       Excellent organizational and attention to details in tracking activities within various Security Operation workflows.

·       Well established client-focused communication skills that requires to read, review, investigate, and summarize reports on

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Experian

View company profile →