Blackpoint Cyber logo
Blackpoint Cyber
Posted 67 days agoVerified live 1d ago

MDR Analyst Skillbridge Intern (Active Duty Military only)

Brief overview

Remote
Security Operations Center (SOC) experienceEndpoint Detection and Response (EDR) triageNext-Generation Antivirus (NGAV)Incident Response (IR) processThreat indicator assessment in Windows environmentWindows operating systemLinux operating systemOSX operating systemELK stack DashboardsELK stack LogstashELK stack SearchingPowerShell scriptingPython programmingGo programmingAWS EC2AWS S3AWS IAM

About the company

Blackpoint Cyber logo
Blackpoint Cyber

A cybersecurity company delivering threat hunting, detection and remediation technology.

Job description

Summary

Blackpoint Cyber is the leading provider of world-class cybersecurity threat hunting, detection and remediation technology. The MDR Analyst Skillbridge Intern will analyze network and system events, collaborate on cybersecurity threats, and help improve SOC efficiency.

Responsibilities

  • Analyze and evaluate anomalous network and system events in a 24x7x365 Security Operation Center (SOC) environment via conducting lead-less threat hunting
  • Collaborate with MDR Analysts to research and investigate emerging cyber security threats; become an escalation point of contact for advanced intrusion analysis
  • Develop Incident analysis reports and work across business units and customers to bring issues to a close
  • Help design and build operational processes and procedures to improve overall SOC efficiency
  • Provide actionable threat and vulnerability analysis based on security events for many independent customer environments
  • Build test lab environments to research emerging techniques and make contributions to the internal and external knowledge development of threat operations
  • Review sandbox technologies for additional IOCs uncovered from artifacts uncovered during analysis

Skills

  • Three (3+) years of experience in an information security role. Progressive relevant training and/or certification may be substituted for one (1) year of the experience requirement
  • Experience working in a Security Operations Center (SOC)
  • One (1+) years of experience with triaging endpoint events from EDR, NGAV, and supporting the Incident Response (IR) process
  • Deep knowledge on assessing threat indicators in a Windows Environment (e.g. Malware/Malicious Anomalies/Abnormal network Activity/Root Level Compromise, Forensic Artifacts, etc.)
  • Robust understanding of at least two of the following: Windows, Linux or OSX
  • Familiarity with ELK stack (Dashboards, Logstash Config, Searching) Scripting / Programming with Powershell, Python, and Go
  • Familiarity with AWS services such as EC2, S3 and IAM and Azure/M365
  • Experience in developing, refining, and performing leadless threat hunting analysis to uncover new or potential incidents and report on results
  • Excellent problem solving, critical thinking, and analytical skills with the ability to deconstruct issues (hunting anomalous pattern detection)
  • Excellent written and verbal communication skills to effectively summarize and present technical findings to both technical and non-technical audiences
  • Bachelor's Degree in Computer Science or related technical discipline
  • Network/System Administration and/or Engineering
  • Deep forensic knowledge of Windows, Mac OS and/or Linux
  • Experience in Digital Forensics and Incident Response a plus
  • Malware Analysis (Behavioral and/or Static analysis- IDA, Cuckoo Sandbox, x86/x64 Debugging) Pentesting/Red/Blue Team
  • Capture The Flag (CTF) Development

Qualifications

Must Haves

  • Three (3+) years of experience in an information security role. Progressive relevant training and/or certification may be substituted for one (1) year of the experience requirement
  • Experience working in a Security Operations Center (SOC)
  • One (1+) years of experience with triaging endpoint events from EDR, NGAV, and supporting the Incident Response (IR) process
  • Deep knowledge on assessing threat indicators in a Windows Environment (e.g. Malware/Malicious Anomalies/Abnormal network Activity/Root Level Compromise, Forensic Artifacts, etc.)
  • Robust understanding of at least two of the following: Windows, Linux or OSX
  • Familiarity with ELK stack (Dashboards, Logstash Config, Searching) Scripting / Programming with Powershell, Python, and Go
  • Familiarity with AWS services such as EC2, S3 and IAM and Azure/M365
  • Experience in developing, refining, and performing leadless threat hunting analysis to uncover new or potential incidents and report on results
  • Excellent problem solving, critical thinking, and analytical skills with the ability to deconstruct issues (hunting anomalous pattern detection)
  • Excellent written and verbal communication skills to effectively summarize and present technical findings to both technical and non-technical audiences

Nice to Haves

  • Bachelor's Degree in Computer Science or related technical discipline
  • Network/System Administration and/or Engineering
  • Deep forensic knowledge of Windows, Mac OS and/or Linux
  • Experience in Digital Forensics and Incident Response a plus
  • Malware Analysis (Behavioral and/or Static analysis- IDA, Cuckoo Sandbox, x86/x64 Debugging) Pentesting/Red/Blue Team
  • Capture The Flag (CTF) Development

Benefits

  • Health, Vision, Dental, and Life Insurance plans
  • A robust 401k plan
  • Discretionary Time Off
  • Other minor perks

More jobs like this