- Security architecture (network topology, firewalls, proxies, web content filtering, wireless, EDR, IDS, IPS, SIEM, SOAR, etc.)• Network data sources (full packet analysis, flow data, dns logs, proxy logs, NIDS, etc.)
Competencies: Digital : Python, Digital : Threat Hunting
Essential Skills:
- Deep understanding of cyber threat actor attacker techniques and tools (such as malware, common attack types) including evasion techniques, reconnaissance, scanning, exploitation, evasion, lateral movement, persistence, and exploits), proficient with MITRE ATT&CK
Desirable Skills:
- Deep understanding of security operations center processes, tools, and data for analysis & control mitigations, security event timeline analysis and baselining with experience in the analysis of logs and data for the development and implementation of custom
detections to counter attacker techniques, known vulnerabilities and evasion methods
Keywords: Threat Detection Engineer