A large financial Service Company based in Johannesburg seeks a Threat Intelligence with:
Minimum Requirements
- A passion for Cyber Threat Hunting, research, and uncovering the unknown about threats and threat actors
- Bachelor’s degree or higher in a technical field such as Computer Science, Information Security, Information Technology, Computer Engineering, Information Systems, etc.
- Ability to understand big data and query languages (Splunk, SQL, etc.)
- Experience setting up infrastructure to support Hunt Team operations
- Previous experience working in the financial industry
- CISSP
- 5 years+ of background in information security, cyber security or network engineering
Role Purpose:
In this highly visible role, candidate will perform research and analysis searching for indications of advanced threat actors existing on the network. Analyse available data sources, security tools, and threat trends and lead security analysis techniques to identify attacks against the enterprise. Works with the greater Information Security team to operationalize new and innovative techniques of discovering advanced threat actors. This role is operational and requires that active threat hunting occurs daily complete to remediation of the attack vector.
Responsibilities:
- Must understand typical threat actor profiles, the typical indicators associated with those profiles, and be able to synthesize the two to develop innovative techniques to detect threat actor activity.
- Must demonstrate knowledge of tactics, techniques, and procedures associated with malicious insider activity, organized crime/fraud groups and both state and non-state sponsored threat actors.
- Must be able to critically examine an organization and system through the perspective of a threat actor and articulate risk in clear, precise terms.
- Analyse available data sources, security tools, and threat trends and lead security monitoring and analysis techniques to identify attacks against the enterprise
- Ability to analyse logs, normalize and perform automated log correlations utilizing big data analysis or hunt tools to identify anomalous and potentially malicious behaviour.
- Strong experience with Digital forensics on host or network from malware perspective, ability to identify anomalous behaviour on network or endpoint devices.
- Experience with information security tools such as an enterprise SIEM solution, IDS/IPS, endpoint security, and security monitoring solutions.
- Self-starting, organized, proactive, and requiring minimal management oversight.
- Ability to quickly learn new and complex concepts.
- Strong analytical skills/problem solving/conceptual thinking/attention to detail.
- Ability to work effectively with peers and multiple levels of management.
- Well organized, thorough, with the ability to balance and prioritize competing priorities.
- Excellent verbal and written communication skills across multiple levels of the organization.
- Experience in Incident Response.
- Experience with either Red team or Blue team operations and ability to think both like an attacker and defender.
- Experience with one or more scripting languages (e.g., Python, JavaScript, Perl etc.)
- Perform memory analysis
- Perform malware analysis
- Experience with computer exploitation methodologies
For more information please contact Sinisa 011 234 0388, alternatively email your updated CV to Sinisa@esmartgroup.co.za
If you do not receive a response within 2 weeks please consider your application declined.
Please be advised that we are currently experiencing technical problems receiving emails from Yahoo account, please use an alternative email address when communicating with us. If you do not have alternative address please contact the Recruiter (number above) for an alternative way to submit your application.
Our apologies for the inconvenience caused
