Summary
Avertium is a cyber fusion and managed extended detection and response (MXDR) services provider. The Cyber Security Engineer will support managed service customers by researching, diagnosing, troubleshooting, and resolving security tool issues across Microsoft security products, SentinelOne, and Azure and AWS cloud environments.
Responsibilities
- Provide technical guidance / recommendations to clients to enhance their overall security posture within the managed products. Handles daily proactive maintenance and reactive troubleshooting/repair functions
- Proactively monitor technical issues pertaining to the services provided for the client and make recommendations to reduce the risk/impact of similar future problems. Monitors health of security systems
- Utilize SIEM and other tools to assist in network investigations, including firewalls, IDS/IPS and network and system monitoring toolsets
- Perform post mortem analysis on logs, traffic flows, and other activities to identify malicious activity
- Research, develop, and stay current on testing tools, techniques, and process improvements in support of security tools and incident response
- Proactively work with clients in the management of technical issues as well as planning, implementation, skills and knowledge transfer on services provided
Skills
- 3+ years experience in an Engineering or similar role in Cyber Security
- Experience with security tool application, server, and networking support
- Experience troubleshooting performance and application-based issues on Windows and Linux environments
- Some automation or scripting experience with Regex and PowerShell
- Experience with Kusto Query Language (KQL)
- Experience with Prometheus and Grafana
- Exposure to MITRE and familiar with TTPs(Tactics Techniques and Procedures)
- Ability to create internal documentation including architectural diagrams
- Familiarity with cloud administration best practices and principles in AWS and(or) Azure
- In-depth understanding of networking concepts and technologies
- Experience using enterprise ticketing systems such as ServiceNow
- Excellent problem solving and communication skills
- Ability to provide step by step technical help via phone, remote session, and email
- Microsoft Certifications (AZ500,MS500, SC200, SC100) preferred
Qualifications
Must Haves
- 3+ years experience in an Engineering or similar role in Cyber Security
- Experience with security tool application, server, and networking support
- Experience troubleshooting performance and application-based issues on Windows and Linux environments
- Some automation or scripting experience with Regex and PowerShell
- Experience with Kusto Query Language (KQL)
- Experience with Prometheus and Grafana
- Exposure to MITRE and familiar with TTPs(Tactics Techniques and Procedures)
- Ability to create internal documentation including architectural diagrams
- Familiarity with cloud administration best practices and principles in AWS and(or) Azure
- In-depth understanding of networking concepts and technologies
- Experience using enterprise ticketing systems such as ServiceNow
- Excellent problem solving and communication skills
- Ability to provide step by step technical help via phone, remote session, and email
Nice to Haves
- Microsoft Certifications (AZ500,MS500, SC200, SC100) preferred
Benefits
- Full benefits
- Unlimited paid time off
- Participation in 401(k)
- Opportunities for professional growth and development
- Opportunity to work with cutting-edge security technologies in a stimulating work environment