Tech Stack
AWSAzureCloudDNSFirewallsGoogle Cloud PlatformNFSPythonSplunkTCP/IP
About the role
- Design, implement, and manage Antivirus and EDR solutions across enterprise-level storage systems and endpoints (file servers, NAS, SAN, object storage, cloud storage).
- Monitor and respond to security alerts generated by Antivirus and EDR platforms.
- Perform regular threat hunting and forensic analysis using EDR tools.
- Ensure AV/EDR coverage, compliance, and reporting across all infrastructure components.
- Manage policy creation and enforcement for Antivirus and EDR tools and maintain up-to-date virus definitions, signatures, and EDR agent versions.
- Work closely with the Security Operations Center (SOC) and Incident Response (IR) teams to triage and remediate security incidents.
- Conduct vulnerability assessments on storage systems and apply mitigation strategies.
- Collaborate with infrastructure, storage, and application teams to ensure security controls do not impact system performance or availability.
- Develop and maintain documentation, SOPs, runbooks, and security guidelines.
- Lead incident response efforts related to malware or virus infections affecting storage systems.
- Analyze infected systems and data to determine the scope and impact of security breaches.
- Develop and implement remediation plans to contain, eradicate, and recover from malware incidents.
- Conduct forensic analysis of malware samples and infected systems to identify root causes and improve security measures.
- Develop and maintain a comprehensive storage security architecture that aligns with industry best practices and regulatory requirements.
- Design and implement secure storage configurations, including access controls, encryption, and data loss prevention (DLP) measures.
- Evaluate and recommend storage security solutions to meet the organization's needs and participate in new storage infrastructure projects.
- Implement and manage security monitoring tools and develop security dashboards and reports to track key security metrics and trends.
- Provide security training and awareness to IT staff and end-users and communicate security risks and mitigation strategies to stakeholders.
- Work with vendors to resolve security issues and implement security updates.
Requirements
- Deep understanding of storage technologies, including file systems (NFS, SMB/CIFS), block storage (SAN), object storage, and cloud storage platforms (AWS, Azure, GCP).
- Hands-on experience with leading AV/EDR platforms, reverse engineering, and incident response.
- Proficiency in using and managing enterprise-level antivirus and anti-malware solutions (e.g., Symantec, McAfee, CrowdStrike, Trend Micro, SentinelOne).
- Deep understanding of storage technologies (NAS, SAN, DAS), data protection, and secure storage practices.
- Strong knowledge of security principles, protocols, and best practices.
- Experience with vulnerability scanning and penetration testing tools.
- Understanding of networking concepts, including TCP/IP, DNS, firewalls, and intrusion detection/prevention systems.
- Experience with scripting languages (e.g., Python, PowerShell) for automation and security tasks along with DevOps skills.
- Familiarity with Cloud (GCP, Azure or AWS) concepts and services.
- Experience with SIEM systems (e.g., Splunk, QRadar, Sentinel) for security monitoring and analysis.
- In-depth knowledge of common malware types, attack vectors, and mitigation techniques.
- Understanding of security frameworks and compliance standards (e.g., NIST, ISO 27001, HIPAA, PCI DSS).
- Knowledge of data encryption technologies and key management practices.
- Familiarity with data loss prevention (DLP) concepts and technologies.
- Excellent analytical and problem-solving skills.
- Strong communication and interpersonal skills.
- Ability to work independently and as part of a team.
- Ability to prioritize tasks and manage time effectively.
- Ability to document security procedures and processes.
- 5-7+ years of experience in information security, with a focus on storage security and malware analysis.
- Experience in designing, implementing, and managing security solutions in complex storage environments.
- Experience in incident response and forensic analysis.
- Bachelor's degree in Computer Science, Information Security, or a related field (Master's preferred).
- Relevant security certifications such as CISSP, CISM, CEH, GIAC (GCIA, GCIH, GREM), Security+.
- Bonus: Experience with specific storage vendor security features (e.g., NetApp, Dell EMC, Pure Storage).
- Bonus: Contributions to the security community (e.g., writing blog posts, presenting at conferences).
- Bonus: Experience with cloud security technologies and best practices.
- Bonus: Knowledge of threat intelligence platforms and feeds.