About the role
Formulate and define the strategic direction for Managed Detection & Response as a managed service. Grow pipeline of the solution by working closely with internal and external channels. Identify and create pull through opportunity for other managed services and consulting services. Keep abreast of industrial, technology and business trends. Perform investigation and orchestration for complex/high severity security alerts, threats or incidents. Serve as the lead point of contact facilitating incident response orchestration with client. Lead research, analysis and correlation efforts across a variety of all source data sets/collectors, log collectors and threat feeds to inform and guide the strategic direction of the offering. Monitor competitive landscape in pricing, capabilities and offerings to analyze and report system security posture trends. As a leader of a team, ensure that the right things are being worked on at the right time, and ensure quality throughout.
Key responsibilities
- Formulate and define the strategic direction for Managed Detection & Response as a managed service
- Grow pipeline of the solution by working closely with internal and external channels
- Identify and create pull through opportunity for other managed services and consulting services
- Perform investigation and orchestration for complex/high severity security alerts, threats or incidents
- Provide the people, process and technology background to ensure timely detection, identification and alerting of possible attacks/intrusions, anomalous activities, intrusion attempts/compromises, malicious behavior, insider risk, and misuse activities
- Isolate, triage and eradicate malicious behaviors
- Serve as the lead point of contact facilitating incident response orchestration with client
- Lead research, analysis and correlation efforts across a variety of all source data sets/collectors, log collectors and threat feeds
- Direct technical product managers in developing new or modified solutions for Managed Detection and Response
- Create and develop SOC processes and procedures, lead strategy development, methodology and execution of Use Case Catalog
About you
- At least 7+ years of experience leading Enterprise Security Operations Centers or Managed Detection and Response analyst or incident response teams
- Experience in lead security operations center analyst (L3), threat hunting, penetration testing, digital forensics, incident response, recognizing and categorizing organizational vulnerabilities and attacks, on-prem, hybrid and cloud security concepts and protocols
- Certifications: CEH, GIAC, OSCP, CREST, GCIH, CCIA, GPEN, Platform Certifications (Microsoft, Splunk, Sentinel, etc.)
- Experience with one or more of the following: Cyber-Security solutions, Security Operation Center, Threat Intelligence Management, Vulnerability Research, Digital Forensics, Incident Response, Endpoint Management, Network Security
- Product Management experience with Software as a Service (SaaS) or Infrastructure as a Service (IaaS) offerings for enterprises
- Experience in the enterprise software market and with services / product companies
- Demonstrated understanding of the techniques and methods of modern product discovery and product delivery
- Knowledge of a global, 24/7, high availability and high trust operation aspects of managed services
- Familiarity with engineering work of a security operation center
- 3+ years Level 3 SOC Analyst experience
Benefits
- HMO with 2 Free Dependents
- Communication Allowance
- Rice Allowance
- Clothing Allowance
- Christmas/Holiday Gift (Christmas Cash Gift)
- Group Personal Accident Insurance
- Life Insurance
- Optical, Medicine, and Dental Allowance
- Bereavement Assistance