Summary
ReliaQuest is a forward-thinking company that emphasizes professional growth and diverse roles. As a GreyMatter Specialist, you will engage in threat detection, engineering, and incident response while developing a comprehensive skill set in cybersecurity. This role offers mentorship and hands-on experience to solve real-world challenges for enterprise customers.
Responsibilities
- Be a trusted technical advisor, resolving customer challenges from start to finish
- Provide analysis and recommendations to customers based on alert activity, response playbook availability, and investigations
- Triage and fine-tune security alerts, Digital Risk Protection (DRP) alerts, and engineering health alerts to ensure optimal performance
- Integrate and configure log sources for existing customers
- Troubleshoot and resolve issues related to data parsing and ingestion to ensure smooth operations and data accuracy
- Independently integrate and configure log sources, handling both administrative tasks and ad hoc requests to complete work efficiently
- Deploy and fine-tune detection rules using GreyMatter Detect
- Employ the Cyber Analysis Methodology to conduct investigations
- Conduct advanced investigations, including Tier 3 incidents, ad-hoc threat hunts, and customer-requested analyses
- Communicate effectively with customers regarding engineering and Incident Response (IR) escalations
- Spend 75% of your day in front of the customer
Skills
- Bachelor's degree in a related field
- Understanding of cybersecurity and IT disciplines including networking, operating systems, authentication protocols, general enterprise network, architecture, and security incident response
- Knowledge of TCP/IP Protocols, network analysis, and network/security applications
- Basic knowledge of Linux/Unix operating systems
- Ability to blend your technical and communication skills to advise the customer
- Must demonstrate great attitude, energy, and effort
- Must be adaptable, focused, accountable, and helpful
- Must demonstrate excellent verbal and written communication skills (English language)
- Certifications such as Network+, Security+, CySA+
- 1-3 years' experience as a Security/Network Administrator or equivalent knowledge
- Prior SIEM experience and/or administration
- Hands-on experience with parsing data, log formats, regular expressions
- Scripting experience (bash, PowerShell, python)
- Multiple OS experience (mac, windows)
- Knowledge of various security methodologies and processes, and technical security solutions (SIEM, IDS/IPS, Firewall Solutions, Offensive Security tools)
Qualifications
Must Haves
- Bachelor's degree in a related field
- Understanding of cybersecurity and IT disciplines including networking, operating systems, authentication protocols, general enterprise network, architecture, and security incident response
- Knowledge of TCP/IP Protocols, network analysis, and network/security applications
- Basic knowledge of Linux/Unix operating systems
- Ability to blend your technical and communication skills to advise the customer
- Must demonstrate great attitude, energy, and effort
- Must be adaptable, focused, accountable, and helpful
- Must demonstrate excellent verbal and written communication skills (English language)
Nice to Haves
- Certifications such as Network+, Security+, CySA+
- 1-3 years' experience as a Security/Network Administrator or equivalent knowledge
- Prior SIEM experience and/or administration
- Hands-on experience with parsing data, log formats, regular expressions
- Scripting experience (bash, PowerShell, python)
- Multiple OS experience (mac, windows)
- Knowledge of various security methodologies and processes, and technical security solutions (SIEM, IDS/IPS, Firewall Solutions, Offensive Security tools)