Cyber Threat Specialist
Date: Jun 1, 2023
Location: Savannah, GA, US
Company: Gulfstream Aerospace Corporation
Cyber Threat Specialist in GAC Savannah
Unique Skills:
The following attributes are all important and experience and/or working knowledge will be a plus.
Experience in other fields will be considered if skills are transferable.
Looking for a seasoned cyber security professional who remains current on the evolving cyber security environment and technologies.
Experience with UEBA, EDR, XDR, DLP, SIEM and SOAR concepts/technologies
Deep understanding of the life cycle of cybersecurity threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs)
Experience in Intelligence Driven Defense, Cyber Kill Chain methodology, and/or MITRE ATT&CK framework. Threat Hunting
Strong analytical and troubleshooting skills
Experience with vulnerability management tools and /or programs
Experience with reverse engineering malware
Experience in the area of Cloud Security - CCSP or CCSK a plus
Experience securing MS AD/Azure environments
Experience in the digital forensics field
Experience in Networking and/or Firewalls a plus
Willing and capable of training team members
Python programming
(These positions include shift work required to cover 24x7 Security Operations, Position is on site with possibility of some hybrid remote work, but primary location is on site)
Education and Experience Requirements
Job Description
- Conducting forensic collections of electronic evidence including information system and network devices for legal, human resources, ethics, and information security.
- Applying forensic software/hardware applications to analyze digital media, images; determining solutions for recovery of potentially relevant information.
- Examining and analyzing network traffic, related applications and operating systems to identify potential threats, anomalous or malicious activities to network resources; validating Intrusion Detection System (IDS) alerts.
- Analyze security data to effectively detect intrusions & attempted intrusions and to initiate and engage the proper resources to mitigate the risk.
- Providing reports and documents regarding network security incidents details and outcome; leads efforts in troubleshooting problems and recommending vulnerability corrections.
- Monitoring and improving documentation and reporting processes for cyber incident status and results.
- Driving the design and implementation of the organizational information security solutions, and continuously enhancing information security approaches and methodologies.
- Lead incident response team in addressing and managing the aftermath of a security breach or attack. Must be trained and have experience in incident response procedures and practices .
- Defining process issues and resolutions; facilitating and overseeing computer forensics processes.
- Conducting security assessments, penetration testing, and ethical hacking.
- Identifying, analyzing, and reporting threats or hidden events within the enterprise network by using defensive measures and information collected from a variety of sources to protect data, information systems, and networks.
- Provides technical and administrative support and performs a range of investigations of information security systems.
- Perform analysis and investigations using data from firewalls, IPS, VPN, web filtering, SIEM, IDS, email filtering and forensic tools.
- Able to be on call for incidents and problems; also able to work different shifts. .
- Able to travel as needed. .
- Proficient in the use of incident response and forensics tools such as FTK, Encase, and Cellebrite. .
- Must have an understanding of cyber forensics, networking, and information security technologies and be able to demonstrate outside-the-box thinking and continuous learning.
- Experience with the following operating systems: Windows, OSX, IOS, Linux or UNIX.
- Security Certification such as CISSP, CEH, ACE, EnCE, CCE, Security+ etc. required.
Additional Information
Requisition Number: 208577
Category: Information Systems
Percentage of Travel: Up to 25%
Shift: Third
Employment Type: Full-time
Posting End Date: 01/30/2023
Equal Opportunity Employer/Veterans/Disabled.
Gulfstream does not provide work visa sponsorship for this position, unless the applicant is a currently sponsored Gulfstream employee.
Legal Information | Site Utilities | Contacts | Sitemap
Copyright © 2020 Gulfstream Aerospace Corporation. All Rights Reserved. A General Dynamics Company.
Gulfstream Aerospace Corporation, a wholly-owned subsidiary of General Dynamics (NYSE: GD), designs, develops, manufactures, markets, services and supports the world's most technologically-advanced business jet aircraft
Nearest Major Market: Savannah
Job Segment:
Cyber Security, Computer Forensics, Information Security, Cloud, Network Security, Security, Technology