Cybersecurity Investigator
hace 4 semanas
Experian is a global information services company that empowers consumers and clients to manage their data with confidence. We help individuals take financial control, businesses make smarter decisions, and organizations prevent identity fraud and crime.
The Cyber Fusion Center (CFC) is a critical component of Experian's cybersecurity efforts, and the Insider Threat Investigator plays a key role in leading proactive, predictive, and reactive data analysis and investigation of threats to Experian's environment.
Responsibilities include:
- Utilizing next-generation tools and technology to conduct behavioral analytics assessments and root cause analysis for insider and data loss threats.
- Authoring concise and written reports and executive summaries for leadership on cases and incidents.
- Managing high-risk information security incidents by working in conjunction with response partners and other risk teams.
- Conducting root cause analysis of alerts and associated tools and data to identify false positives, drive precision rate improvement, and streamline investigations effectiveness and impact.
- Conducting proactive data analysis and research on emerging trends to determine prevalence of threats in Experian's environment.
- Working with partner teams on internal threat detection and response projects.
- Authoring playbooks for new/changed investigative processes.
- Collaborating with CFC teams to improve and automate processes.
Required skills include:
- Understanding of core current cybersecurity technologies as well as emerging capabilities.
- Analyzing data and evaluating relevance to a specific incident under investigation.
- Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings.
- Effectively communicating investigative findings to non-technical audiences.
- Ability to interact with and lead discussions with senior Experian executives across different functions and lines of business.
- Ability to manage high-risk regional information security incidents by working in conjunction with response partners and other risk teams.
- Maintaining an awareness of industry challenges and advancements in order to add value to existing technologies and processes used within the team.
- Creating and implementing countermeasures to specific weaknesses against known adversarial TTPs.
Qualifications include:
- 5-7 years of insider threat and insider investigation experience, and experience working in a Cyber Fusion Center environment.
- Proficiency with running queries in Splunk and building dashboards to create proactive tracking of threats.
- Experience with User and Entity Behavior Analytics (UEBA) and Data Loss Prevention (DLP) principles.
- Knowledge of computer forensics, incident response, threat-informed defense approaches, the MITRE Att&ck framework, and cybersecurity principles.
- Experience with security monitoring technologies, such as DLP, CASB, UEBA, SIEM, IPS/IDS.
- Investigative data analysis expertise and ability to detect threat patterns and risks.
- Experience with corporate investigations, security operations, incident analysis, incident handling, incident or vulnerability management or testing, system patching, log analysis, intrusion detection, or security device administration.
-
Digital Forensics and Malware Investigator
hace 4 semanas
San José, San José, Costa Rica Crg Solutions A tiempo completoCrg Solutions is seeking a skilled Digital Forensics and Malware Investigator to join our team.The ideal candidate will have a deep understanding of operating systems artifacts, filesystems artifacts, and network protocols.Responsibilities:Conducting digital forensics investigations to identify attack vectors, understand attack methods, and scope...
-
Cybersecurity Threat Investigator
hace 1 semana
San José, San José, Costa Rica Sentinelone A tiempo completoSecurity ExpertiseSentinelOne is pioneering the future of cybersecurity through our XDR platform, ensuring real-time threat prevention, detection, and response. Our patented AI models deliver autonomous protection, providing unparalleled transparency into network activities at machine speed.We're a values-driven team where names are known, results are...
-
Dfir and Malware Analyst
hace 6 meses
San Pedro, Costa Rica CRG Solutions A tiempo completoDFIR and Malware analyst Short description: The Digital Forensics & Incident Response investigator will handle cyber-attacks and data breaches investigations involving internal or external threat. The investigator will conduct an end-to-end investigation including Malware Analysis to reveal the big picture and protect any of the company's worldwide clients...
-
Financial Crime Investigator
hace 1 mes
San José Province, Costa Rica Now Digital Talent A tiempo completoFraud and Security AgentWe are seeking a detail-oriented and analytical Fraud and Security Agent to join our team.Job Overview:The Fraud and Security Agent will be responsible for monitoring, detecting, and preventing fraudulent activities in customer transactions while ensuring a secure environment for our clients.Key Responsibilities:Monitor transactions...
-
UX Researcher
hace 4 semanas
San José, San José, Costa Rica Sentinelone A tiempo completoAbout UsSentinelOne is a cybersecurity leader that's revolutionizing the way organizations protect themselves from threats. Our XDR platform uses AI to prevent, detect, and respond to threats in real-time, giving our customers unparalleled visibility and control over their networks.We're a values-driven team that's passionate about innovation and...