Social network you want to login/join with:
As one of the most established cybersecurity companies in the world, we at NetWitness are dedicated to helping our customers and partners protect their organizations from cyberattacks. Our products and incident response services are used by large enterprises, governments, and militaries for incident response and threat hunting.
We are seeking a candidate with in-depth industry knowledge and technical expertise to assist customers in gaining market share and increasing operational efficiencies. The role involves providing technical and consultative leadership on complex engagements, focusing on specific industries or service offerings.
Responsibilities
- Provide technical and consultative services on NetWitness solutions across various complex projects.
- Conduct workshops, analyze requirements, develop solution designs, prepare documentation, and deliver training on NetWitness solutions.
- Collaborate with project managers, team members, and clients to ensure smooth project execution and transition.
- Deliver services independently and as part of a team, working with sales, other personnel, and clients.
- Manage multiple project streams, define deliverables, and adhere to approved methodologies, budgets, and scopes.
- Lead quality assurance activities, including technical reviews, and ensure proper escalation and change management.
- Manage or serve as a technical lead on projects, understanding customer challenges and providing strategic solutions.
- Analyze data, produce documentation, and ensure customer satisfaction through quality work products.
- Maintain activity reports, keep stakeholders informed, and complete project documentation and knowledge transfer.
- Develop detailed project plans, validate statements of work, and categorize requirements accordingly.
Technical Responsibilities
- Assist customers in threat hunting and detection capabilities.
- Track threat actors and their TTPs.
- Identify threat groups and their techniques, tools, and procedures.
- Provide cybersecurity best practices related to threat intelligence, hunting, and analysis using NDR, EDR, and SIEM tools.
- Develop detection content, use cases, queries, alerts, dashboards, and reports to identify threats and anomalies.
- Assess visibility gaps and recommend improvements.
- Support customers in enhancing detection and investigation capabilities, collaborating with incident response teams.
- Contribute to sales scoping and technical training development.
- Create and maintain lab use-cases, assist with lab deployments and upgrades.
- Deliver webinars and participate in customer training events.
Required Experience/Qualifications:
- Understanding of logging mechanisms for network, security solutions, servers, and databases.
- Knowledge of networking and security infrastructure.
- Ability to analyze data flow in network topologies.
- Strong communication, presentation, and interpersonal skills.
- Analytical and problem-solving skills.
- Understanding of logs, events, packets, and incidents.
- Experience with collection methodologies such as Syslog, SNMP, ODBC, LEA, FTP, SFTP.
- Knowledge of security threats, trends, and policies.
- Professional English communication skills.
- Possession of or eligibility for federal security clearance is advantageous.