Job purpose
- Digital Forensics and Incident Response (DFIR) activities including assessment, analysis, categorization, classification, and investigation of cybersecurity incidents
- Manage cybersecurity incidents to ensure timely containment and risk mitigation engaging with operational teams and leadership as required and according to Security Incident Management Processes
- Handle potential high severity incidents autonomously during non-working hours (on rotational on-call basis)
- Collect, document and analyze evidence as part of the digital forensics capability of CyberDefense and AXA CERT
- Follow-up security incidents resolution and track updates in ticketing tool
- Notify and communicate to relevant stakeholders including Group and entity CISO / CSO’s
- Support SOC Security Analysts and an international network of local security incident handlers from AXA entities
- Perform lessons learned activities, e.g. security incident reviews, post mortem documentation
- Contribute to the improvement of the DFIR capability including development and integration of open source and commercial tools in a dedicated forensic lab
- Contribute to threat hunting activity proactively and in the context of high severity incidents
- Participate in use case development and SIEM rules threshold tuning
- Act as a mentor to more junior Security Incident Response Specialists, support and supervise them, ensure knowledge transfer within the team
- Professional communications and reporting to SOC stakeholders and customers
- Participate in exchanges with national and international CERT / CSIRT communities
Qualifications
Education
Bachelor degree in Computer Science or Information Security would be desirable but is not essentialCertification
GIAC GCIH (SANS SEC504), GIAC GCFA (SANS FOR508)Strongly preferred : GIAC GDAT (SANS SEC599), GIAC GNFA (SANS FOR572), GIAC GCFE (SANS FOR408), GIAC GCIA (SANS SEC503), GIAC GREM (SANS FOR610)Preferred : Security infrastructure certificationsPreferred : ITIL foundationPreferred : Offensive security certification (OSCP, SEC560, CEH)Overall work experience in the field
Demonstrated experience in performing Information security incident analysis and response >4 years
Demonstrated experience in SOC / CSIRT >3 years
Demonstrated experience in network / security infrastructure administration >2 years
Demonstrated experience Linux / Windows administration >1 years
Demonstrated experience in large and complex organisation(s) >3 years
Demonstrated experience in usage of ticketing toolsDemonstrated on-the-job experience with any of the standard commercial SIEM toolsTechnical Skills / abilities
Ability to identify risks, threats, vulnerabilities and associated attacks that might involve : malicious code, protocol / design / configuration flaws…Strong troubleshooting and analytical skillsUnderstanding the Internet and detailed knowledge of network protocols (Ethernet, 802.11.X, IP, ICMP, TCP, UDP…)Knowledge of application / services related protocols (DNS, SMTP, HTTP, FTP…)Knowledge of network infrastructure elements and architecture (Firewall, Proxy, IPS, WAF…)Knowledge of current security vulnerabilities and related attack methodologiesDetailed knowledge of packet capture analysis and usage of associated toolsDetailed knowledge of log management (Syslog, CEF, debug levels, parsing…)Knowledge of encryption algorithms, digital signature mechanisms and PKIKnowledge of scripting, character manipulation and regular expressionsPersonal Skills / abilities
Organized with a proven ability to prioritize workload, meet deadlines, and utilize time effectivelyGood interpersonal and communication skills, works effectively as a team playerCommon sense to make efficient and acceptable decisionsWillingness to continue education and to stay up to date, passionate about IT and information securityAbility to work under pressureAbility to lookup for information and to solve unknown problemsDiplomacy when dealing with other partiesAbility to function effectively in a matrix structureCross cultural sensitivity, flexibilityFluent in English