Empresa: DXC Technology
Job Description: DXC Technology helps global enterprises run mission-critical systems and operations while modernizing IT, optimizing data architectures, and ensuring security and scalability across public, private and hybrid clouds. With decades of driving innovation, the world's largest companies trust DXC to deliver new levels of performance, competitiveness and customer experiences. Learn more about the history of DXC and our focus on people, customers and operational execution at www.dxc.technology . Responsibilities: Utilize advanced technical background and experience to scrutinize and provide corrective analysis to escalated cyber security events from Tier 1 & 2 analysts distinguishing these events from benign activities and escalating confirmed incidents to the Incident Response Lead. Provide in-depth cyber security analysis, and trending/correlation of large datasets such as logs, event data, and alerts from diverse network devices and applications within the enterprise to identify and troubleshoot specific cyber security incidents and make informed technical recommendations that enable remediation efficiently. Proactively search through log, network, and system data to find and identify undetected threats. Identify and ingest indicators of compromise (IOC’s) (e.g., malicious IPs/URLs, etc.) into network security tools/applications to protect the clients network. Quality-proof technical advisories and assessments prior to release from SOC. Coordinate with and provide expert technical support to enterprise-wide technicians and staff to resolve confirmed incidents. Report common and repeat problems, observed via trend analysis, to SOC management and propose process and technical improvements to improve the effectiveness and efficiency of alert notification and incident handling. Formulate technical best-practice SOPs and Runbooks for SOC Analysts. Respond to inbound requests via phone and other electronic means for technical assistance and resolve problems independently. Coordinate escalations with Service Delivery Lead and collaborate with internal technology teams to ensure timely resolution of issues. Identifies, reports, and resolves security violations. Required Skills In-depth understanding of: current cyber security threats, attacks and countermeasures for adversarial activities such as network probing and scanning, distributed denial of service (DDoS), phishing, ransomware, botnets, command and control (C2) activity, etc. In-depth hands-on experience analyzing and responding to security events and incidents with most of the following technologies and/or techniques: security information and event management, (SIEM) technologies, intrusion detection/prevention systems (IDS/IPS), network and host-based firewalls, network access control (NAC), data leak protection (DLP), database activity monitoring (DAM), web and email content filtering, vulnerability scanning tools, endpoint protection, secure coding, etc. Strong communication, interpersonal, organizational, oral, and customer service skills. Strong knowledge of TCP/IP protocols, services, and networking. Knowledge of forensic analysis techniques for common operating systems. Adept at proactive search, solicitation, and detailed analysis of threat intelligence (e.g., exploits, IOCs, hacking tools, vulnerabilities, threat actor TTPs) derived from open-source resources and external entities, to identify cyber security threats and derive countermeasures, not previously ingested into network security tools/applications (external & internal threat hunting) Strong understanding of command line scripting and implementation (i.e., Python, PowerShell, Bash Shell) Ability to write new content/searches/scripts (e.g., CrowdStrike Falcon Next-Gen + AI & ONUM, Palo Alto Cortex XSIAM + AI, Microsoft Azure Sentinel, Splunk Enterprise Security, IBM QRadar, ManageEngine Log360, etc.) Strong knowledge of Operational Technology (OT) environments, including SCADA systems, Industrial Control Systems (ICS), industrial network security, asset visibility, threat detection, and OT security solutions such as Nozomi Networks. Experience with tools such as Active Directory, Cisco IOS, MS Server, AMP, CrowdStrike, Splunk ES, SNORT, Yara, IronPort, and Firepower. Desired Skills Certification desired - SANS GCIA, GCED, GPEN, GCIH or similar industry Experience working with or in any of the following: Computer Incident Response Team CIRT/CSIRT. Computer Emergency Response Team CERT. Computer Security Incident Response Center CSIRC. Degree in Computer Science, Information Security or similar discipline. What are we offering? This position is also available to people with disabilities; Various benefits, competitive salary and our values make DXC one of the most important and attractive companies to work for in the world. At DXC, our objective is to provide equal opportunities, respecting individualities and diversities, in order to build a balance between professional / personal life and constant opportunity for career development. If you are looking for challenges in a pleasant, multinational work environment, then we definitely want to know more about you. Apply now using the links below, or directly into a position through our career portalhttps://jobs.dxc.technology. You can also find us at: https://www.facebook.com/DXCTechnology/ https://www.linkedin.com/company/dxctechnology At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We’re committed to fostering an inclusive environment where everyone can thrive. Recruitment fraud is a scheme in which fictitious job opportunities are offered to job seekers typically through online services, such as false websites, or through unsolicited emails claiming to be from the company. These emails may request recipients to provide personal information or to make payments as part of their illegitimate recruiting process. DXC does not make offers of employment via social media networks and DXC never asks for any money or payments from applicants at any point in the recruitment process, nor ask a job seeker to purchase IT or other equipment on our behalf. More information on employment scams is available here .