Develops and delivers detailed IT solutions through consulting project activities
Responsibilities include client identification through final invoicing for engagements requiring varied interpersonal and technical skills
Technical responsibilities include problem identification, system architecture definition, hardware/software specification and/or design, implementation, testing, client training, and solution deployment
Performance is typically evaluated based on utilization (i.e., billable hours)
Project management activities include interaction with company and client managers and cost/schedule monitoring
May have some financial responsibilities, including project cost estimating, proposal generation, and invoicing
May participate in sales and proposal presentations in addition to completing ongoing team account activities
Identifies additional product/service opportunities in the customer organization
Performance is typically measured by the capture of the consulting engagement and/or delivery of agreed solutions within budgeted hours
Requirements
Understanding of cyber threats, attack vectors, detection capabilities, and associated countermeasures
Experience working in a Security Operations Center to monitor security alerts, respond to, and remediate detected issues is preferred
Clear understanding of organizational Incident Management processes in relation to threats and vulnerabilities
Maintain a deep knowledge of Trellix (formerly McAfee) Endpoint Security, Application Control/Change Control, ENS, TIE, DXL, DLP
Experience in Windows, Mac, Linux OS and application hardening, including understanding artifacts and behaviors
Experience with one or more scripting languages: Python, PowerShell, Go, C#, other command line scripting or similar is preferred
You may have experience scripting API integrations with response and orchestration tools like SIEM, SOARs and/or XDR platforms
Experience with a SIEM tool and working with SIEM Analyst
Experience with event correlation and analysis
Demonstrated technical proficiency in cybersecurity operations, cybersecurity engineering, systems engineering
Experience with Virtualization (VMWare, Nutanix, etc.) and Cloud Services [i.e., AWS, Azure]) and enterprise networks