Expoint - all jobs in one place

Finding the best job has never been easier

Limitless High-tech career opportunities - Expoint

Cybereason Blue Team Investigator - German Speaking 
Germany, Saarland, Saarbrücken 
958534767

31.08.2024


What you will do:

  • Develop tools and automation that leverage the Cybereason Defence Platform and Global SOC technology to aggressively identify, triage, and respond to emerging threats including, but not limited to, those used in attacker toolkits and related TTPs.
  • Perform detailed analysis of emerging threats from which detection and mitigation solutions are designed and implemented.
  • Assist other Global SOC teams and relevant stakeholders in the detection and mitigation of advanced attacks and attacker emulation in customer environments.
  • Create and deliver public and private technical documentation on research and analysis findings, mitigation mechanisms and implementations, as well as ‘best practices’ to ensure the security of customer environments.
  • Interface with customers in the presentation of findings and recommendations at all levels from SOC analysts to c-suite executives
  • Work closely with internal company teams both in Product and R&D, as well as customer-facing teams
  • Assist in the continued creation, maintenance, and improvement of the Blue Team’s tech stack
  • Work closely with and enable other customer-facing teams in the analysis and reporting of red team and penetration testing events in customer environments.

What we are looking for

  • 7+ years of experience working in IT, cybersecurity or IT administration
  • 4+ years of relevant cybersecurity experience in Incident Response, endpoint security, digital forensics, or red teams
  • Candidate MUST speak fluent German.
  • Background and experience in at least two of the following four areas required:
    • Red Team or attacker processes, methodologies, techniques, and tactics
    • Binary analysis and OS internals
    • SOAR/SOAPA infrastructure creation/maintenance, including playbook, automation, orchestration development
    • Cybersecurity tool design and development
  • Strong knowledge of modern operating systems (Windows – a must, OS X and Linux – advantage)
  • Solid foundation in networking protocols and architectures
  • Experience with security tools and frameworks, particularly with open-source tools (such as Sysinternals, OLE tools, Volatility, debuggers, disassemblers, etc.)
  • Solid foundation with a scripting language (Python, Bash, PowerShell, etc.)
  • Experience with a coding language (C, C++, Java, etc) an advantage
  • Self-motivated and results-oriented; capable of leading and completing assignments without supervision
  • Comfortable working in remote work environments with a globally distributed team in multiple countries.
  • Strong organizational skills and ability to handle a wide range of tasks and re-prioritize them on short notice
  • Motivation to constantly improve processes and methodologies
  • Good written and oral communication skills, experience working with international customers

Core Values:

  • Win As One: The power of an individual is less than the power of a team.
  • Ever Evolving: Change keeps us at the forefront, so we encourage it.
  • Daring: To achieve the impossible, we must dare to be different.
  • Obsessed with Customers: We believe gaining our customers’ trust is the most important part of what we do.
  • Never Give Up: We are tenacious and resilient, and we never stop.
  • UbU: We believe people can only unlock their full potential when they work somewhere that accepts who they are.