CSIRT Level 3 Incident Handler & Digital Forensic Investigator M/W

icon briefcase Job Type : Full Time

Number of Applicants

 : 

000+

Click to reveal the number of candidates who applied for this job.

Job Description - CSIRT Level 3 Incident Handler & Digital Forensic Investigator M/W

You are curious, motivated, and passionate!

Integrated within dynamic and passionate teams, you will have the opportunity to fully invest yourself, innovate and create from the latest technologies. You will quickly find your place at Excellium. In order to understand our business, the challenges of our customers and to accompany them we regularly organize meetings, workshops, and training. We will thus help you to develop your skills and position you on stimulating projects, adapted to your profile and enabling you to surpass yourself.

Your team :

Let’s meet CERT-XLM, Excellium Services’ CSIRT. We are an incident response team strong of 9years’ experience, made of a dozen of highly motived people.

Our goal is to help organizations contain, neutralize, and eradicate cybersecurity threats. We ensure organizations are prepared to face incidents, and we conduct post-mortem investigations when needed.

We address around 70 incident response engagements yearly, from generic forensic investigations to human operated ransomware breach analysis.

To avoid psychological fatigue within the team, we are careful to keep a balance between incident handling and research and development projects.

Your job :

The main duty is to assist organizations face various security incidents. In this task, you will conduct host forensics, and log analysis in support of incident response engagements. You also ensure our customers receive adequate incident response preparation.

Based on the knowledge of TTPs gained from your engagements in incident response, you will develop new detection use cases for Excellium CSOC. Occasionally, you will validate their relevance and implementation in purple team engagement.

A part of your time will also be dedicated to the development and maintenance of our in-house CSIRT tools and applications.

Regular training or workshops with customer or your peers will allow you to share knowledge about incident handling, and you will have opportunities to present your work at security conventions.

PROFILE

  • Highly motivated, interested in the fields of cyber defense and research.
  • First experience in a similar job or in Cyber-security field (Soc/Pentest)
  • Understanding of windows & *Nix operating systems
  • Windows events and forensic artifacts understanding.
  • Requires analytical thinking and problem-solving skills.
  • Love in parsing and analysis “dirty and always incomplete” logs.
  • Experience with high level tools (volatility, Log2Timeline) and more advanced ones (grep).
  • Comfortable with command line (we work with Linux)
  • Development: Fluent in reading and writing Python 3
  • English B2 or >

Nice to have but not mandatory:

  • Dutch B2 or >
  • Highly motivated, interested in the fields of cyber defense and research.
  • Significant experience in Incident response
  • Deep understanding of windows and *Nix operating systems internals
  • Requires analytical thinking and problem-solving skills.
  • Love in parsing and analysis “dirty and always incomplete” logs.
  • Experience with Volatility, Log2Timeline, Misp, IntelMQ, Wireshark, Tshark, Snort
  • Enjoy debugging Python 3. (Sometimes 2, you know forensic tool code base quality)
  • Knows threat Intel promises, understand its limitations.
  • Work calmly and well under pressure
  • Maintain composure while dealing with under stress people.
  • Support the team, help less experienced members, share knowledge
  • Good writing and reporting skills.
  • English B2 or >

Nice to have but not mandatory:

  • Hands on experience with Cloud, OT/SCADA or Apple environments.
  • Could read X86/64 assembly, C, C++, .NET
  • Dutch B2 or >

You are a big enthusiast of IT security, you are curious and on the lookout for the latest news, security holes and technological advances, then apply !!

OFFER DETAILS

Contract: F ull time

Location :

OR

“Your personal data will be kept for a period not exceeding 3 months. If you agree, your personal data will be kept for up to 12 months for potential future job offers. “

WHO WE ARE?

Joining Excellium means having the opportunity to fully commit yourself to innovate and create from the latest technologies.

Excellium benefits from a good dynamic, with accessible managing partners and involved teams.
It is all about joining a family of more than 100 passionate cyber employees.

It is also the chance to expand your area of expertise in:
– Cybersecurity,
– Hybrid Cloud,
– Managed Security Services,
– Application Security.

We will help you grow and develop your cyber skills.
Then don’t wait any longer to apply!!

#J-18808-Ljbffr
Original job CSIRT Level 3 Incident Handler & Digital Forensic Investigator M/W posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
icon no cv required No CV Required icon fast interview Fast Interview via Chat

Share this job with your friends

icon get direction How to get there?

icon geo-alt 1930 Zaventem, Zaventem (Commune); Hal-Vilvorde (Arrondissement); Province Du Brabant Flamand; Région Flamande

icon get direction How to get there?
View similar Others jobs below

Similar Jobs in Belgium

Share this job with your friends

💰

Browse the Top Paying Jobs Others Salaries

GrabJobs is the no1 job portal in Belgium, connecting you to thousands of jobs fast! Find the best jobs in Belgium, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2024 Grabjobs Pte.Ltd. All Rights Reserved.