Lone Tree, Colorado, USA
25 days ago
Cyber Threat Hunter

Company Description

ClientSolv Technologies is an IT solution firm with over a decade of experience serving Fortune 1000 companies, public sector and small to medium sized companies. ClientSolv Technologies is a woman-owned and operated company that is certified as a WMBE, 8a firm by the Federal government's Small Business Administration.

 

Job Description

We are seeking a Cyber Security Threat Hunter for a contract-to-hire opportunity in Englewood, CO. 

 

The focus of the Cyber Security Threat Hunter is to distinguish, interrupt and suppress threat actors on enterprise networks. To execute this mission, the Threat Hunter will use data analysis, threat intelligence, and cutting-edge security technologies. Working within the Security Analysis and Operations Team, the Cyber Security Threat Hunter is responsible for detecting and assessing cyber security events and incidents across the enterprise environment. Threat Analysts will also participate in developing processes, procedures, training, etc. for new technologies. The candidate must have a curious investigative mind, an interest in information security, and the ability to communicate complex ideas to varied audiences.

 

Job Duties and Responsibilities:

Examine alerts from various security monitoring tools, perform triage & determine scope of threats; escalate as necessary.Develop and analyze dashboards and reports to identify potential threats, suspicious/anomalous activity, malware, etc.Coordinate with End user computing groups that are exhibiting unusual behavior (i.e. excessive firewall denials, Okta logins from unusual geo-locations) to have them assist in troubleshooting/remedying the issues.Assist with tickets relating to whitelisting & user internet access by researching the domains being requested for security/reputation, liaising with users for additional details, and passing the tickets along for implementation in the proxiesManage various Proof-of-Concept implementations for threat hunting platforms/tools to evaluate if they would be beneficial for the organization by providing additional visibility into the enterprise environment and increasing incident response time.Provide Tier 2 & Tier 3 support as neededKeep up-to-date with information security news, techniques, and trendsBecome proficient with Ticketing system and workflow managementBecome proficient with third-party threat intelligence tools as required

Qualifications

 

3+ years’ experience in Information SecurityExperience with traditional security tools found in enterprise network environments:Anti-VirusIPS/IDSFirewallsProxiesActive DirectoryVulnerability assessment toolsCyber Threat Hunting ExperienceExperience with data analysisExperience with SIEMExperience with cyber threat intelligenceExperience with software vulnerabilities & exploitation

Nice to have:

Experience with EDR (Desired)Prior experience working with in the following areas:Computer Incident Response Team (CIRT)Computer Security Incident Response Center (CSIRC)Security Operations Center (SOC)Experience with malware analysisExperience with APT/crimeware ecosystemsDegree in Information Security or Information TechnologyThe following certifications are strongly desired:Security+GIAC Certified Incident Handler (GCIH)GIAC Certified Intrusion Analyst (GCIA)SANS Institute/GIAC ISC2

 

Additional Information

This contract to hire role is located onsite in Englewood, CO.

Confirm your E-mail: Send Email