وصف الوظيفة
Role Overview
Expert Engineer/Security Operation Centre at Etisalat E&. This role is responsible for incident response efforts, host-level investigations, comprehensive forensic investigations, proactive threat hunting within the network and systems, and remediation of security incidents.
Role Purpose
Lead incident response and digital forensics operations to detect, investigate, and remediate security incidents across the organization's infrastructure. Proactively hunt for threats using advanced techniques and tools, develop standardized processes for threat detection, and communicate findings to stakeholders to strengthen the security posture.
Key Responsibilities
Incident Response & Remediation
- Lead incident response efforts across the organization's network and systems.
- Develop remediation strategies for compromised environments.
- Ensure timely closure of incidents in compliance with SLA requirements.
- Conduct cloud incident response across Azure and AWS.
Forensic Investigations
- Conduct comprehensive forensic investigations for cybersecurity incidents, including data breaches, advanced persistent threats (APT), ransomware, and insider threats.
- Utilize forensic tools and techniques to collect and analyze evidence, ensuring secure evidence handling and chain of custody for compliance with legal and regulatory standards.
- Conduct host-based forensic analyses across various platforms, including Windows, Linux, macOS, and mobile devices.
- Conduct network-based forensics using platforms such as NDR and Security Onion.
- Conduct initial malware analysis to assess potential risks.
Threat Detection & Analysis
- Conduct in-depth analysis of security events from multiple sources, such as SIEM, IDS/IPS, firewall logs, endpoint detection tools, and network traffic data.
- Monitor and analyze threat intelligence feeds, security blogs, and industry news to stay informed on emerging threats and vulnerabilities.
- Develop and execute advanced threat-hunting queries and custom searches to detect malicious activities that may evade standard detection systems.
- Improve detection rules based on findings.
Threat Hunting
- Proactively hunt for threats in the organization's network by identifying Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs) used by adversaries.
- Build and refine threat-hunting playbooks and runbooks to standardize and enhance threat-hunting operations.
- Utilize the MITRE ATT&CK framework to map detected threats and enhance threat-hunting capabilities.
Reporting & Communication
- Communicate findings through detailed, high-quality reports and presentations to security teams, management, and relevant stakeholders.
Automation & Tooling
- Develop custom scripts to automate security log analysis.
Qualifications & Experience
Education
- Bachelor's degree in Cybersecurity, Computer Science, or related field (or equivalent work experience).
Experience
- Minimum 6 years of experience in digital forensics, incident response, or threat hunting.
- Strong hands-on experience with Incident Response and Digital Forensics.
- Practical investigation experience (end-to-end case handling or evidence processing exposure).
- Investigation background must include exposure to host-level investigations; cannot be focused solely on EDR and SIEM tools.
- Hands-on experience with Windows and Linux environments; ability to read and explain Windows or Linux logs effectively.
Certifications
- DFIR related certifications required.
- SANS certifications required, specifically SANS GCFA, GCFE, and GCIH.
Skills & Competencies
Technical Expertise
- Expertise in Digital Forensics, Incident Response, and Threat Hunting.
- Strong knowledge of forensic tools such as EnCase, FTK, Oxygen, Cellebrite, Volatility, and other forensics analysis tools.
- Experience with SIEM platforms such as Microsoft Sentinel and Splunk.
- Ability to write and execute complex queries using KQL (Kusto Query Language).
- Docker or Kubernetes.
- Skilled in scripting (e.g., Python, PowerShell) for automation of forensics and incident response tasks.
- Experience with cloud forensics for platforms such as AWS and Microsoft Azure.
Professional Competencies
- Knowledge of the MITRE ATT&CK framework for categorizing and responding to adversarial techniques.
- Ability to communicate complex technical findings effectively to both technical and non-technical audiences.
- Strong analytical and problem-solving skills, with attention to detail and accuracy.
- Self-driven and able to work effectively in high-stress situations, handling multiple incidents simultaneously.
- Demonstrated ability to work both independently and collaboratively within a team.