cyber security engineer
генерация резюме под вакансию
сопроводительное письмо
описание
Greencastle Digital brings together talented people from digital tech, product development, customer experience, and marketing to create cutting-edge solutions in the betting and gaming industry.
задачи
- Design, write, test and tune detections across Cortex XDR / XSIAM, cloud telemetry, identity telemetry, endpoint, network and application logs;
- Treat detections as code by version-controlling rules, peer-reviewing changes, writing tests, measuring coverage against MITRE ATT&CK, and retiring unused detections;
- Own log onboarding and parsing for new sources while collaborating with platform and application engineering teams;
- Run structured threat hunts against hypotheses derived from threat intelligence, recent incidents and attacker tradecraft relevant to online gambling;
- Lead deep-dive investigations on alerts escalated from the Palo Alto MSSP, determine root cause and full scope before hand-back;
- Document findings clearly for future analysts;
- Stand on the bridge during P1 and P2 incidents and personally drive containment and eradication actions with engineering teams;
- Own the technical timeline, indicators of compromise, evidence trail and artefacts needed for regulator notification and post-incident review;
- Deputise for the Head of Cybersecurity as Incident Commander when required;
- Build and maintain SOAR playbooks to automate triage, enrichment, containment and notification;
- Integrate detection and response tooling with the wider stack using clean code;
- Serve as the primary technical interface to the Palo Alto managed SOC, review detections, challenge analysis, and escalate issues;
- Run regular detection and response exercises with the MSSP;
- Work with offensive security partners to run purple-team exercises and translate findings into hardened detections;
- Use breach-and-attack-simulation tooling to continuously validate detection coverage.
требования
- Demonstrable hands-on experience as a SOC analyst, detection engineer, threat hunter or incident responder;
- Strong working knowledge of at least one major SIEM/XDR platform and the query language behind it;
- Practical experience investigating in AWS including CloudTrail, GuardDuty, VPC flow logs, EKS audit logs, and IAM analysis;
- Scripting competence in Python or an equivalent;
- Solid grounding in MITRE ATT&CK, the diamond model and a structured approach to investigation;
- Calm under pressure and comfortable on a bridge call at 03:00;
- Nice to have: Experience in online gambling, payments, financial services or high-volume consumer environments, exposure to retail or distributed-endpoint estates, experience working with or inside an outsourced SOC arrangement, practitioner or vendor certifications such as GCIA, GCIH, GCFA, GNFA, BTL1, relevant degree.
условия
- On-call rotation;
- No conditions specified.
навыки
Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.