Cybersecurity Engineer - Incident Response

GM Financial

4

(3)

Multiple Locations

Why you should apply for a job to GM Financial:

  • 4/5 in overall job satisfaction
  • 5/5 in supportive management
  • Ratings are based on anonymous reviews by Fairygodboss members.
  • We offer 12 weeks of paid parental leave for our team members to care for and bond with their new family member.
  • Our Women's Inspiration Network (WIN) supports the recruitment, retention and professional development of women across our organization.
  • Our programs provide the support, flexibility and resources for women returning to their careers after a break.
  • #1010

    Position summary

    s to join our growing Cybersecurity team.

    RESPONSIBILITIES

    About the role:

    • The Cybersecurity Engineer is responsible for maintaining and building detection, investigation, and incident response activities to identify and mitigate threats to the corporate network, assets, and users. This team member will collaborate with stakeholders to perform on-going alerting and tuning on various technologies. Security technologies may include but are not limited to: Data Loss Prevention (DLP), Security Incident Event Management (SIEM), User and Entity Behavior Analytics (UEBA), Intrusion Detections System (IDS)/Intrusion Prevention System (IPS), Endpoint Detection and Response (EDR), Network Detection and Response (NDR), Security Orchestration, Automation and Response (SOAR), and Web/Email Security Products.

    In this role you will:

    • Triage, investigate, escalate alerts and incidents from multiple sources of varying technical levels

    • Investigate security incidents from detection to resolution, engaging in any containment, eradication and recovery actions as needed

    • Write and execute search commands within a SIEM to find relevant information

    • Navigate various security products and solutions for pertinent data and insights

    • Develop custom rules and detections using Regular Expression (Regex) and YARA

    • Remain up to date on the latest Cybersecurity trends and tactics, techniques, and procedures (TTP)

    • Attention to detail and ability to formulate decisions based on evidence gathering

    • Perform other duties as assigned

    • Conform with all company policies and procedures

    What makes you a dream candidate?

    • Strong technical skills and hands on experience in Cybersecurity as it relates to alert triage, on-going monitoring, detection, investigation, and incident response activities

    • Understanding of Cybersecurity concepts such as Endpoint security, Network security, Cloud security, Data Loss Prevention/Data Privacy, and Web/Email security

    • Practical knowledge of the NIST Incident Response Life Cycle and the MITRE ATT&CK Framework

    • Strong knowledge of the OSI model and security that is associated with each layer

    • Strong knowledge of core Information Technology concepts such as TCP/IP networking, Windows & Active Directory, Unix/Linux/Mac, web/email traffic fundamentals, and using a command line interface (CLI)

    • Practical knowledge of cloud providers, technologies, and concepts

    • Understanding of Agile and DevOps environments

    • Experience with scripting languages such as Python, Go, Ruby, PowerShell, etc

    • Demonstrated ability to communicate across multiple levels of stakeholders

    • Ability to document and summarize technical evidence and findings

    • Good interpersonal, verbal, and written communication skills across various mediums

    • Detail oriented with good time and analytical skills

    • Ability to exercise prudent judgment and offer knowledgeable recommendations

    • Ability to work both independently and in a team environment

    • Ability to manage multiple projects, tasks, and investigations

    • Ability to work in sensitive situations

    • Be a reputable representative of the department

    QUALIFICATIONS

    Experience

    • Bachelor's Degree or equivalent experience preferred

    • Working knowledge in one or more of the following domains: Cybersecurity, Cloud Computing, Network Engineering, Network Operations, Information Technology Support, System Administrator, Data Science, Software Development preferred

    • 2+ years of experience in large, complex, and global business environment preferred

    Licenses

    • Cybersecurity related Certifications strongly preferred (GCIH, GCFA, GCFE, Security+)

    Licenses

    • Information Security Certifications strongly preferred

    What We Offer: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.

    Our Culture: Our team members define and shape our culture - an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work - we thrive.

    Compensation: Competitive pay and bonus eligibility.

    Work Life Balance: Flexible hybrid work environment, 4 days a week in the office.

    Why you should apply for a job to GM Financial:

  • 4/5 in overall job satisfaction
  • 5/5 in supportive management
  • Ratings are based on anonymous reviews by Fairygodboss members.
  • We offer 12 weeks of paid parental leave for our team members to care for and bond with their new family member.
  • Our Women's Inspiration Network (WIN) supports the recruitment, retention and professional development of women across our organization.
  • Our programs provide the support, flexibility and resources for women returning to their careers after a break.