As one of the most established cybersecurity companies in the world, we at NetWitness are dedicated to helping our customers and partners protect their organizations from cyberattacks. Our products and incident response services are used by large enterprises, governments, and militaries for incident response and threat hunting.
We are seeking a candidate with in-depth industry knowledge of the business environment and technical solutions to assist customers in gaining market share and increasing operational efficiencies. The role involves providing technical and consultative leadership on complex engagements, focusing on industry or service offerings.
Responsibilities
- Provide technical and consultative services on NetWitness solutions across complex projects.
- Conduct workshops, analyze requirements, develop solutions, document, and deliver training on NetWitness solutions.
- Collaborate with project managers, team members, and clients to ensure smooth project execution and transition.
- Deliver services independently and in teams, working with sales, personnel, and clients.
- Manage multiple work streams on complex projects, define deliverables, and adhere to methodologies, margins, and SOWs.
- Lead quality assurance activities, including technical reviews, and follow escalation and change control procedures.
- Possibly manage or serve as technical lead on smaller projects, understanding customer challenges and providing strategic solutions.
- Analyze data, prepare reports, and ensure customer satisfaction through quality deliverables.
- Maintain activity reports, keep stakeholders informed, and complete end-of-project documentation.
- Develop detailed project plans, validate SOWs, and categorize requirements.
Technical Responsibilities
- Enhance customer capabilities in threat hunting and detection.
- Track threat actors, TTPs, and develop detection content and use cases within NetWitness.
- Create dashboards, reports, and advanced queries to identify threats and anomalies.
- Assess visibility gaps and recommend improvements.
- Support customers in increasing detection capabilities and investigating attacks.
- Assist in sales scoping and provide guidance.
- Contribute to technical course development, assessments, and content QA.
- Maintain instructor documentation and lab use-cases, assist with lab deployments and upgrades.
- Deliver webinars and participate in customer training events.
Required Experience / Qualifications
- Understanding of logging mechanisms for network, security solutions, servers, and databases.
- Knowledge of networking/security infrastructure and data flow analysis.
- Strong communication, analytical, and problem-solving skills.
- Proficiency in logs, events, packets, and incident analysis.
- Experience with collection methodologies like Syslog, SNMP, ODBC, LEA, FTP, SFTP.
- Knowledge of security threats, trends, and policies.
- Excellent presentation, facilitation, and interpersonal skills.
- Professional English communication skills.
- Federal security clearance is a plus.