knowledge of IPv4/IPv6, TCP networking protocols, and the OSI model. Expertise in security tools: SIEM (ArcSight, Sentinel, QRadar, Splunk), EDR (Microsoft Defender, FireEye), IDS/IPS, firewalls, proxies, web application firewalls, and anti-virus technologies. Strong knowledge of Linux and Windows operating systems. Familiarity with SOAR technologies (e.g. More ❯
and network analysis tools (Splunk, Wireshark, SOF-ELK). Exhibit skills using common Incident Response and Security Monitoring applications such as SIEM (Splunk), EDR (FireEye HX, CrowdStrike Falcon, McAfee mVision EDR), WAF, IPS. Demonstrated knowledge of common intrusion methods and cyber-attack tactics, techniques, and procedures (TTPs). Have at More ❯
to detail In-depth understanding of modern attack vectors , especially those surfaced via EDR platforms Proficiency with SIEM (e.g., Splunk, ArcSight), EDR (e.g., Defender, FireEye) , and supporting security tools Strong technical knowledge of TCP/IP, OSI model, Windows/Linux , and cloud environments (Azure, AWS, O365) Familiarity with SOAR More ❯
to detail In-depth understanding of modern attack vectors , especially those surfaced via EDR platforms Proficiency with SIEM (e.g., Splunk, ArcSight), EDR (e.g., Defender, FireEye) , and supporting security tools Strong technical knowledge of TCP/IP, OSI model, Windows/Linux , and cloud environments (Azure, AWS, O365) Familiarity with SOAR More ❯
to detail In-depth understanding of modern attack vectors , especially those surfaced via EDR platforms Proficiency with SIEM (e.g., Splunk, ArcSight), EDR (e.g., Defender, FireEye) , and supporting security tools Strong technical knowledge of TCP/IP, OSI model, Windows/Linux , and cloud environments (Azure, AWS, O365) Familiarity with SOAR More ❯
to detail In-depth understanding of modern attack vectors , especially those surfaced via EDR platforms Proficiency with SIEM (e.g., Splunk, ArcSight), EDR (e.g., Defender, FireEye) , and supporting security tools Strong technical knowledge of TCP/IP, OSI model, Windows/Linux , and cloud environments (Azure, AWS, O365) Familiarity with SOAR More ❯
to stakeholders Preferred Qualifications: Direct experience with current advanced persistent threats (APT) Undergraduate degree or equivalent experience Deep expertise with EnCase Experience with NetWitness, FireEye, Splunk, and/or RSA Security Analytics Knowledge of Volatility, Rekall and/or Mandiant Redline Knowledge of Chain of Custody process and procedures Network More ❯