Product area
Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.
Additional job description
As an Incident Response Consultant, you will provide industry-leading incident response, assessment, transformation, managed detection and response, and training services with in-depth tactical support. You will help organizations effectively detect and respond to threats and reduce the overall impact of business risk before, during, and after an incident. You will be able to resolve security incidents quickly, effectively and at scale with complete incident response including investigation, containment, remediation, and crisis management. In this role, you will work on engagements including assisting clients in navigating technically complex and high-profile incidents, performing forensic analysis, threat hunting, and malware triage.
Qualifications
Job responsibilities
- Collaborate with internal and customer teams to investigate and contain incidents.
- Recognize and codify attacker Tools, Tactics, and Procedures (TTP) and Indicators of Compromise (IOC) that can be applied to current and future investigations.
- Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations.
- Support specific workstreams for a variety of client-facing investigations including the examination of cloud, endpoint, and network-based sources of evidence.
- Develop comprehensive and accurate reports and presentations for technical and non-technical audiences.
Minimum qualifications
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, related technical field, or equivalent practical experience.
- Experience in information security domain, with 1 year of experience leading Incident Response investigations, analysis, or containment actions and any three of the following: network or log forensic analysis, malware triage analysis, disk, or memory forensics.
- Experience in cybersecurity in one of the following areas: network security, wireless security, web application assessments, social engineering, scripting, cloud security, reverse engineering, or incident response.
Preferred qualifications
- Experience with enterprise security architecture and security controls.
- Experience with cloud incidents or forensic responses.
- Experience with malware triage analysis and disk or memory forensics in one or more of the following: Windows, macOS, or Linux.
- Excellent time and project management skills.