Develop tools and automation that leverage the Cybereason Defence Platform and Global SOC technology to aggressively identify, triage, and respond to emerging threats including, but not limited to, those used in attacker toolkits and related TTPs.
Perform detailed analysis of emerging threats from which detection and mitigation solutions are designed and implemented.
Assist other Global SOC teams and relevant stakeholders in the detection and mitigation of advanced attacks and attacker emulation in customer environments.
Create and deliver public and private technical documentation on research and analysis findings, mitigation mechanisms and implementations, as well as ‘best practices’ to ensure the security of customer environments.
Interface with customers in the presentation of findings and recommendations at all levels from SOC analysts to c-suite executives
Work closely with internal company teams both in Product and R&D, as well as customer-facing teams
Assist in the continued creation, maintenance, and improvement of the Blue Team’s tech stack
Work closely with and enable other customer-facing teams in the analysis and reporting of red team and penetration testing events in customer environments.
What we are looking for
7+ years of experience working in IT, cybersecurity or IT administration
4+ years of relevant cybersecurity experience in Incident Response, endpoint security, digital forensics, or red teams
Candidate MUST speak fluent German.
Background and experience in at least two of the following four areas required:
Red Team or attacker processes, methodologies, techniques, and tactics
Binary analysis and OS internals
SOAR/SOAPA infrastructure creation/maintenance, including playbook, automation, orchestration development
Cybersecurity tool design and development
Strong knowledge of modern operating systems (Windows – a must, OS X and Linux – advantage)
Solid foundation in networking protocols and architectures
Experience with security tools and frameworks, particularly with open-source tools (such as Sysinternals, OLE tools, Volatility, debuggers, disassemblers, etc.)
Solid foundation with a scripting language (Python, Bash, PowerShell, etc.)
Experience with a coding language (C, C++, Java, etc) an advantage
Self-motivated and results-oriented; capable of leading and completing assignments without supervision
Comfortable working in remote work environments with a globally distributed team in multiple countries.
Strong organizational skills and ability to handle a wide range of tasks and re-prioritize them on short notice
Motivation to constantly improve processes and methodologies
Good written and oral communication skills, experience working with international customers
Core Values:
Win As One: The power of an individual is less than the power of a team.
Ever Evolving: Change keeps us at the forefront, so we encourage it.
Daring: To achieve the impossible, we must dare to be different.
Obsessed with Customers: We believe gaining our customers’ trust is the most important part of what we do.
Never Give Up: We are tenacious and resilient, and we never stop.
UbU: We believe people can only unlock their full potential when they work somewhere that accepts who they are.