وظيفة استشاري أول - الاستجابة للحوادث لدى فورتينت في المملكة العربية السعودية
تفاصيل الوظيفة
فورتينت تبحث عن مستشار أول - الاستجابة للحوادث (FortiGuard Incident Response) للعمل في السعودية ضمن فريق استجابة حوادث وطب شرعي عالمي المستوى، تحت إشراف مدير عمليات خدمات استشارات الأمن. سيعمل المرشح مباشرة مع خبراء في صيد البرمجيات الخبيثة وتحليلها والهندسة العكسية ولغات البرمجة النصية وجمع الأدلة الرقمية وتكتيكات الجهات الخبيثة. يهدف المستشار إلى قيادة وإدارة مهام الاستجابة للحوادث، وتدريب وإرشاد مستشارين أمنيين آخرين، مع الاستفادة من الفهم العميق لأدوات وتكتيكات الجهات الخبيثة ومنصة FortiEDR لتحقيق الوعي الظرفي وتوجيه الفريق والعملاء. كما سيساهم في إعداد محتوى بحثي مثل المدونات والعروض التقديمية.
المهام والمسؤوليات
- مساعدة قائد الاستجابة للحوادث أثناء المهام وتدريب المحللين المبتدئين وإرشادهم
- التركيز المستمر على تحسين العمليات لخدمات الاستجابة للحوادث الموجهة للعملاء
- إجراء تحليل الطب الشرعي على أنظمة Windows وLinux وMac OS X
- إجراء تحليل شبكات وفحص سجلات الحوادث أثناء مهام الاستجابة للحوادث
- مراجعة سجلات جدران الحماية وقواعد البيانات والويب وغيرها لتحديد أدلة وأنشطة ضارة ومخترقة
- استخدام منصة FortiEDR لإجراء تحقيقات سريعة لكشف التهديدات الأمنية وتحليلها
- إجراء تحليل ذاكرة وفحص ملفات حسب الحاجة
- مراقبة المنتديات السرية ومختبرات تهديدات FortiGuard ومصادر الاستخبارات مفتوحة المصدر للحفاظ على إتقان أحدث تكتيكات الجهات الخبيثة
- إجراء هندسة عكسية أساسية للأدوات الضارة للجهات الخبيثة
- إعداد تقارير وعروض تقديمية شاملة ودقيقة للجمهور التنفيذي والتقني
- التواجد خلال الليالي وعطلات نهاية الأسبوع عند الحاجة لمهام الاستجابة للحوادث
الشروط والمتطلبات
- درجة البكالوريوس في هندسة الحاسب أو علوم الحاسب أو مجال ذي صلة، أو خبرة 5+ سنوات في الاستجابة للحوادث أو الطب الشرعي
- خبرة في التعامل مع العملاء
- خبرة في لغة برمجة نصية واحدة على الأقل: Shell, Ruby, Perl, Python أو ما يعادلها
- القدرة على استخراج البيانات باستخدام YARA أو RegEx أو تقنيات أخرى لكشف تهديدات جديدة
- خبرة في أدوات مثل EnCase وFTK وX-Ways وSIFT وSplunk وRedline وVolatility وWireShark وTCPDump وأدوات الطب الشرعي مفتوحة المصدر (ميزة إضافية)
- خبرة في أدوات تحليل البرمجيات الخبيثة مثل IDA Pro وOllyDbg وImmunity Debugger
- خبرة عملية في حملات التهديدات المتقدمة (APT) وتكتيكات وتقنيات وإجراءات الهجوم (TTPs) وتقنيات حقن الذاكرة والتحليل الثابت والديناميكي للبرمجيات الخبيثة وآليات الثبات
- معرفة قوية بداخل أنظمة التشغيل وخبرة في أمن نقاط النهاية
- القدرة على التحليل الثابت والديناميكي للبرمجيات الخبيثة والسجلات
- تحليل ملفات Linux وMAC الثنائية وفهم داخليات MAC (ميزة إضافية غير إلزامية)
- فهم متين لـ Active Directory وكيفية تأمينه (ميزة إضافية)
- قدرة على العمل تحت الضغط في أوقات حرجة والعمل ليلاً أو في عطلات نهاية الأسبوع حسب الحاجة
- دوافع عالية وذاتية وقدرة على العمل بشكل مستقل وكجزء من فريق
- القدرة على التواصل مع الجمهور التقني والتنفيذي
المهارات المطلوبة
- مهارات ممتازة في الكتابة والتواصل اللفظي باللغة الإنجليزية
- خبرة في التفاعل مع العملاء
- إجادة لغة برمجة نصية واحدة على الأقل: Shell, Ruby, Perl, Python
- القدرة على استخراج البيانات باستخدام YARA أو RegEx أو تقنيات أخرى
- خبرة في أدوات الطب الشرعي وتحليل البرمجيات الخبيثة المذكورة
- خبرة عملية في TTPs والهندسة العكسية والتحليل الثابت والديناميكي
- معرفة قوية بداخل أنظمة التشغيل وأمن نقاط النهاية
- القدرة على التواصل الفعال مع الفرق التقنية والتنفيذية
- تحليل البرمجيات الخبيثة والسجلات بشكل ثابت وديناميكي
- تحليل ملفات Linux وMAC (ميزة إضافية)
- فهم Active Directory (ميزة إضافية)
- القدرة على العمل تحت ضغط في بيئات زمنية حرجة
- التحفيز الذاتي والعمل المستقل والجماعي
عرض النص الأصلي للإعلان
We are looking for a Senior Consultant - FortiGuard Incident Response to work in a dynamic and exciting new position reporting to the Director of Operations for FortiGuard Security Consulting Services. The analyst will work directly with members of a world class incident response and forensics team. Our team is comprised of individuals with strong knowledge in malware hunting and analysis, reverse engineering, multiple scripting languages, forensics and threat actors TTPs. In this very hands-on customer facing role the consultant’s main objective is to lead and manage the incident response engagements and train/mentor other security consultants. Leveraging your in-depth understanding of the threat actors’ tactics, techniques, procedures and tools as well as our flagship FortiEDR tooling you will need to quickly glean situational awareness to provide guidance to the team members as well as to the client. In addition, from time to time the candidate will help to create threat research work products such as blogs and presentations. To be successful in this role the candidate must be possess strong consulting skills, deep technical skills and able to work under tight timelines.
Responsibilities:
- Assist the IR Lead during engagements and mentoring/training junior analysis
Continue to focus on process improvement for the customer facing incident response services
Conduct host-based analysis and forensic functions on Windows, Linux, and Mac OS X systems
Conduct network forensics and log analysis during IR engagements
Review firewall, web, database, and other log sources to identify evidence and artifacts of malicious and compromised activity
Leverage our FortiEDR Platform to conduct investigations to rapidly detect and analyze security threats
- Perform memory forensics and file analysis as needed
- Monitor underground forums, our FortiGuard Threat Labs, along with other open-source intelligence outlets to maintain proficiency in latest actor tactics and techniques
Preform basic reverse engineering of threat actor’s malicious tools
Develop complete and informative reports and presentations for both executive and technical audience
Availability during nights/weekends as needed for IR engagements
Required Skills:
- Excellent written and verbal communication skills a must
- Experience interfacing with customers
- Experience with of at least one scripting language: Shell, Ruby, Perl, Python, etc
- Ability to data mine using YARA, RegEx or other techniques to identify new threats
Experienced with EnCase, FTK, X-Ways, SIFT, Splunk, Redline, Volatility, WireShark, TCPDump, and open source forensic tools a plus
- Experience with malware analysis tools such as IDA Pro, OllyDbg, Immunity Debugger
- Hands-on experience dealing with APT campaigns, attack Tactics, Techniques and Procedures (TTPs), memory injection techniques, static and dynamic malware analysis and malware persistence mechanism
- Strong knowledge of operating system internals and endpoint security experience.
- Able to communicate with both technical and executive personnel
- Static and dynamic malware and log analysis
- Analysis of Linux and MAC binary files and the understanding of MAC internals is a plus but not required.
- Highly motivated, self-driven and able to work both independently and within a team
- Able to work under pressure in time critical situations and occasional nights and weekends work
- A solid understanding of Active Directory and how to secure is a plus
Education:
- Bachelor’s Degree in Computer Engineering, Computer Science or related field
- Or 5+ years’ experience with incident response and or Forensics
رقم الإعلان لدى المصدر: 22451