- Identify gaps in our infrastructure, and work with business partners to gain visibility through logging and detection.
- Use your coding, data analytics and investigation skills to hunt, detect and respond to insider threats.
- Write detection to detect data abuse and data exfiltration at scale.
- Build automation and detection models to support identification of anomalous activity and response activities to mitigate insider threats at scale.
- Hunt for insider threats in our corporate and production environments to proactively identify anomalous activity.
- Work side by side with our engineering teams to build advanced detection solutions to help keep systems and information safe, and partner closely with our Human Resources and Legal teams to carry out complex investigations.
- Identify and consult on the design of countermeasures to mitigate insider threats in our environment.
- Partner with stakeholders to contribute to Security Awareness messaging and Training.
-
JOB TYPE: Freelance, Contract Position / W2 (no agencies/C2C - see notes below) -
Location: United States only - Remote - (Time Zone: PST/CIST | Partial overlap) -
HOURLY RANGE: Our client is looking to pay $140 – $150/hr -
ESTIMATED DURATION: 40hr/week
THE OPPORTUNITY
Requirements
What you’ll be working on
- 5+ years of hands-on in-depth knowledge and technical experience in security operations including detection engineering, threat hunting, incident response, digital forensics, and/or threat intelligence.
- Bachelor's degree in a related technical field or equivalent practical experience.
- Exposure to data science and analytics solutions applicable to the insider threat detection space.
- Experience with Insider Threat technologies (SIEMs, Data Loss Prevention solutions, host forensic solutions).
- Knowledge and familiarity of the Cyber Kill Chain Framework and MITRE ATT&CK Framework and how these apply to the insider threat landscape.
- Experience automating security detection and response.
- Experience in AWS services (EC2, S3, Lambda, RDS) preferred
- We are not focused on specific tools but we often use Python, AWS, SQL, and more.
- Self-motivated and creative problem-solver able to work independently with minimal guidance.
- Ability to work calmly and collaboratively in critical high-stress situations with expediency.
- Outstanding organizational, prioritization, and multitasking skills.
Apply Now!
#PL-BT #LI-BT
Tags & focus areas
Used for matching and alerts on DevFound Remote Dev