Senior Threat Hunter/Analyst - SOC

Bucharest

ExpressVPN

Protect your privacy, stream worldwide, and enjoy fast speeds with ExpressVPN. Servers in 105 countries, 24/7 support, and a 30-day risk-free trial—start now!

View all jobs at ExpressVPN

Apply now Apply later

Responsibilities

As an individual contributor in our Security Operations Center, you’ll have a broad list of responsibilities including: (the mix will depend on your interests and skill-level)

  • Threat Hunting, to proactively detect, isolate, and neutralize threats:
    • Research traffic on our networks, create baselines for expected norms and identify and investigate outliers. Provide your analysis and document your research.
    • With your understanding of normal operations and your baseline for logging and events, hunt for anomalous events and pull the thread to determine if our systems were compromised or a compromise was attempted.
    • Manage research related to threat hunting adversaries in our environments
    • Participate in investigations related to threat hunting adversaries in our environments
  • Monitoring:
    • Monitor and analyze the output from many log sources including cloud services, on-premise network equipment, productions platforms, and employee provided devices and recommend security actions per procedures where required
    • Perform Real-Time monitoring and triaging of security alerts
  • Incident Response:
    • Act as the first point of contact (POC) for security incidents and anomalies
    • Coordinate with other security and operations teams during incidents or investigations
    • Conduct preliminary incident triage according to the Security Incident Management Triage Matrix and set the priority accordingly
    • React and respond to all real or perceived security and cyber-related incidents, threat and attacks within agreed times
    • Determine and classify the severity of alerts and assess potential impacts as classification defined in the knowledge base
  • Stay on the bleeding edge by conducting research, consulting with colleagues and attending training to maintain awareness of trends in new security threats, technologies, and regulations
  • Assist in IT security investigations, red team exercises and penetration tests as needed
  • Understand and operates an effective Security Orchestration, Automation and Response (SOAR) platform
  • Work closely with other teams to provide mitigation recommendations to reduce the overall security risk within the organization
  • Provide ideas and feedback to improve the overall SOC capabilities and maturity
  • Find and analyze various threat intelligence feeds
  • The position is on-call through an on-call schedule and PagerDuty.

Required Skills

Advanced understanding of:

  • Concepts such as MITRE ATT&CK and the Cyber Kill Chain
  • Monitoring non-traditional IT services such as SaaS and cloud services
  • Advanced knowledge of:
    • SIEM solutions such as Sumo Logic, Splunk or Elastic SIEM
    • Endpoint Detection and Response (EDR) solutions such as Carbon Black or Endgame
    • Advanced analysis and triaging of security logs from Windows, Linux, ChromeOS, and macOS
    • Malware analysis and investigation
    • Implants, shells, Command and Control (C2) infrastructures
    • TCP/IP Networking, packet capturing and analysis
    • Network equipment such as Cisco, Palo Alto, and Juniper

Benefits

Health and happiness go hand in hand, and we make every effort to support our team members in all facets of their lives—both inside and outside the office. Learn more about our employee benefits by visiting our careers page.

Before you apply

  • At the moment, we do not sponsor visas in the EU. For Hong Kong, we require at least two years of working experience and a university degree in a related field. For Singapore and the UK, we can only sponsor visas for mid-career or above.
  • Please upload your resume as a PDF and do not include any salary or compensation information in it.

ExpressVPN is one of the world’s leading providers of online privacy and security services for consumers. Started in 2009, we’ve grown to have millions of active paying customers, a team of more than 700 people worldwide, and a brand recognized by hundreds of millions of people in 18 languages and more than a hundred countries. We see huge growth in our industry, and are gaining market share through strong execution.

Please note that all offers are subject to reference checks from one or more of your former managers/colleagues. For your current manager, we understand that every company has distinct HR practices, and will only speak with them at a mutually agreed-upon time that works for you.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: Automation Carbon Black Cloud Cyber Kill Chain EDR Incident response Linux MacOS Malware MITRE ATT&CK Monitoring Privacy Red team SaaS SIEM SOAR SOC Splunk TCP/IP Threat intelligence Windows

Perks/benefits: Health care Team events

Region: Europe
Country: Romania

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.