Overview
Job Purpose The ICE Cybersecurity Digital Forensics and Incident Response (DFIR) team is responsible for defending critical financial infrastructure from Global Cyber threats. We leverage an evolving arsenal of controls that require technical proficiency as well as tenacity, professionalism, and strong communication skills. Responsibilities
- Security Analytics - Efficiently distill actionable information from large data sets for reporting, hunting, and anomaly detection
- Incident Management - Detect, document, investigate, and resolve security incidents in an efficient manner
- Endpoint Forensics - Construct meaningful incident timelines from forensic artifact analysis
- Counter Measures - Ability to design and implement preventative and corrective controls to counteract emerging threats
- Proactive Threat Hunting - Develop and execute focused plans to discover advanced threats that evade traditional security controls
- Behavioral Analysis - Develop and implement criteria to identify anomalous user behavior leading indicating insider threat activity
- Intrusion Detection - Develop and tune network anomaly control capability to produce reliable actionable data
- Threat Hunting - Proactively search for unknown threats within the environment.
Knowledge and Experience
- 3+ years of relevant experience
- Deep understanding of networking and its application
- University degree in related discipline
- Hands on experience with Windows and Linux
Core Competencies - ICE
- Teamwork: works well with teammates locally and at remote offices; shares knowledge and is seen as someone to go to for help; contributes in weekly peer meetings
- Problem solving and decision making: demonstrates a sense of urgency; takes ownership of problems and follows temporary fixes with permanent solution; finds creative solutions
- Communication: is clear and accurate in verbal and written communication; listens to peers and supported employees; follows directions and provides useful feedback
- Professionalism: makes a positive impression in person, via phone, and electronically; models a 'can-do' attitude; embraces additional responsibility; refrains from office gossip or conflict; works extra hours as needed to ensure work is complete; adheres to corporate policy and encourages others to do the same
Specific Technologies: Splunk, OpenDNS, Exabeam, Tanium, SentinelOne, Checkpoint, Palo Alto, WAF, Vectra, X-Ways, Python, PowerShell, RegEx Intercontinental Exchange, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to legally protected characteristics.
|