Proactively hunts for and investigates advanced cyber threats and suspicious activity across the enterprise by analyzing network, log, and threat intelligence data to identify potential compromises and emerging adversary behaviors. Develops threat hunting strategies, tools, and automation to enhance detection capabilities, identifies mitigations for vulnerabilities, and supports incident response for critical security incidents.
Proactively searches for cyber threats that exist undetected within the network. Initiates investigations to identify unusual behavior indicative of malicious activity with the assumption that a threat actor already resides within the network. Analyzes raw log and network data as well as working with Threat Detection and Incident Response analysts to generate hunting leads. Cross-reference trends and activity within the enterprise environment with current threat intelligence regarding external trends. Identifies mitigations for key vulnerabilities identified during threat as well as taking the lead on analysis if an APT or other compromise is identified while performing hunting. Develops threat hunting strategies to increase capabilities for finding new threats. Builds hunting tools and automation capabilities to identify sophisticated adversaries. Performs incident response for critical security incidents.
Required Qualifications:
REQ: CSSP