Tech Stack
AWSAzureCloudGoogle Cloud PlatformLinuxMacOSSQL
About the role
- Provide security teams with visibility and control over high-value enterprise data to protect from IP theft and insider threats.
- Identify potential insider threats and investigate endpoint forensic incidents.
- Perform technical analysis of data security incidents and analyze events and incidents.
- Find and expose risk in customers' environments and improve detection focus where data loss risk exists.
- Handle documentation and project management aspects of incident response.
- Provide insight into DLP analytics and related issues.
- Analyze Cyberhaven's Data Detection and Response (DDR) platform event data to improve policies, incidents, and alerts.
- Refine datasets and policies as customers' data risk strategy matures.
- Prepare and present summaries and reports to internal team members.
- Eliminate noise and false positives from analytic results to enhance detection accuracy.
- Conduct forensic analysis on people, groups, and non-sanctioned egress destinations as requested.
Requirements
- 2-5 years experience in working with a data protection product, or adjacent security tool experience (EDR, SIEM, SOAR).
- 2+ years' experience with Insider Threat Programs and Information Security.
- Knowledge of endpoint protection best practices and security incident mitigation workflows.
- Excellent problem-solving and analytical abilities with creative and logical thinking.
- Highly motivated, customer centric person, strong customer empathy and focus.
- Ability to work as part of a global team.
- Excellent written and verbal communication skills.
- Familiarity with technologies adjacent to Cyberhaven (SIEM/SOAR) desired.
- Knowledge of security controls for the handling of sensitive data types.
- Understanding of macOS, Linux and Windows environments.
- Experience with DLP, Insider Threat and CASB solutions.
- Familiarity with cloud apps and services (GCP, AWS, Azure).
- Knowledge of SQL for writing queries and performing data analysis.
- Experience designing, developing and maintaining interactive dashboards and data visualizations.
- Knowledge in modifying and developing XML-based content rules to refine DLP datasets.
- Knowledge with general scripting for automation and utilizing APIs.
- Excellent communication and interpersonal skills with a passion for cloud security and emerging technologies.