Enconosoft
-
• Experience applying threat and data modeling, advanced data correlation, and statistical analysis to develop alerts, notable events, investigative dashboards, and metrics driven reports.• Assist in the development and execution of cyber threat-hunting tactics, techniques, and procedures (TTPs).• Translate analytical findings into security use cases that can be implemented within available security tool capabilities.• Analyze network and host activity associated with both successful and unsuccessful intrusions by advanced attackers.• Support enterprise incident response efforts• Leverage understanding of tactics, techniques and procedures associated with advanced threats to create and add custom signatures that mitigate highly dynamic threats to the enterprise.• Employ advanced forensic tools and techniques for attack reconstruction and intelligence gathering.• Proactively research emerging cyber threats. Apply analytical understanding of attacker methodologies and tactics, system vulnerabilities, and key indicators of attacks and exploits.Qualifications• Experience with Splunk (preferred) or other security information and event management (SIEM) -type platform.• Familiarity with common languages (PowerShell and Python) to parse logs, automate processes, and integrate systems.• Working knowledge of Computer Network Exploitation (CNE), Computer Network Attack (CNA) and Computer Network Defense (CND) tools and techniques.• NIST• MITRE ATT&CK frameworks (Adversarial Tactics, Techniques, and Common Knowledge)• Understanding of behavioral based threat models, including ATT&CK, Cyber Kill Chain, Diamond Model, etc