Overview
Provide technical and expert support for the 24/7 Cyber Security Incident Response Team's processes and support the Cyber Security Incident Response/Threat Hunting Team.
Key Responsibilities
- Provide technical and expert support for to the 24/7 Cyber Security Incident Response Team’s processes, during normal working hours and on-call duties, including weekends and holidays;
- Support Cyber Security Incident Response/Threat Hunting Team covering one or multiple physical locations, including NATO Alliance Operations and Missions;
- Perform both static and dynamic code analysis in order to understand malware samples capabilities and capture the results in a report which covers the technical aspects as well as the “so what?” for the decision makers and executives;
- Develop tools, scripting, automation and integrations to automate activities as much as possible, mostly using Python and PowerShell;
- Maintain forensic and malware analysis tools and environments on premises or in the cloud.
Required Experience
- 2 years post-related experience with a Bachelor’s degree in a related discipline, or exceptionally, at least 6 years extensive and progressive expertise in duties related to the function of the post.
- Extensive knowledge of malware analysis techniques and technologies;
- Excellent ability to recognise when an IT network/system has been attacked, be able to take immediate action to limit damage and to escalate the event to higher authority;
- Practical experience with cyber security in cloud-based environments such as Azure and AWS;
- Proficiency in assessing security vulnerabilities of operation systems and software;
- Practical experience and knowledge of malware analysis and malware detection;
- Practical experience in the analysis of digital forensic artefacts in the context of cyber security;
- Good knowledge of the principles of computer and communications security, networking, and vulnerabilities of modern operating systems and applications;
- Good understanding of the MITRE ATT&CK framework and its applicability in Cyber;
- Good practical experience in Windows, Linux and VMware system administration;
- Good knowledge of cyber security incident handling;
- Practical experience in scripting (Python, PowerShell).
Qualifications
A Bachelor’s degree at a nationally recognised/certified University in a related discipline.