Overview

Cybersecurity Incident Responder Jobs in Valletta, Malta at Atos

Title: Cybersecurity Incident Responder

Company: Atos

Location: Valletta, Malta

CONTEXT / INTRODUCTION

The client requires specialised cybersecurity operational and engineering services to support, strengthen and maintain its cybersecurity capabilities.

He operates a hybrid ICT environment comprising on-premises and cloud-based systems, Windows and Linux platforms, enterprise networks, security-monitoring technologies, endpoint-security solutions, cybersecurity automation tools, security data platforms and cloud services.

The client ICT Security Team is responsible in addition to other related issues for the below cybersecurity activities:

  • security monitoring and incident response;
  • endpoint detection and response;
  • security orchestration and automation;
  • security-event ingestion and analysis;
  • threat intelligence and threat hunting;
  • vulnerability management;
  • platforms, infrastructure and system hardening;
  • cybersecurity technical documentation;
  • support to secure development and system implementation;
  • cybersecurity reporting and assurance.

Cybersecurity incident responders shall support the client in:

  • monitoring, analyzing, and responding to cybersecurity events, alerts, cases, and incidents at all severity levels, while coordinating with relevant stakeholders as needed;
  • documenting incidents, maintaining records and preparing incident reports;
  • collecting, preserving and handling digital evidence in support of investigations;
  • operating and improving cybersecurity platforms and controls;
  • supporting cybersecurity integrations and automation;
  • monitoring and analyzing the global threat landscape and vulnerabilities, and supporting remediation measures;
  • improving technical cybersecurity documentation and procedures;
  • transferring knowledge to client personnel.

DESCRIPTION OF THE TASKS

The consultant shall perform principally activities related to the detection, analysis, response and continuous improvement of cybersecurity operations, including:

  • Monitoring security tools (XDR, SIEM), triaging and responding to cybersecurity events, reviewing alerts and incidents across on-premises and cloud environments, ensuring appropriate escalation, prioritization and stakeholder coordination
  • Identify attack patterns, detect anomalies in logs and systems, assign severity levels focusing on high impact assets/systems
  • Conducting in-depth incident analysis to determine root cause, scope and impact, including threat hunting activities
  • Managing and supporting incident response actions (containment, eradication, recovery and restoration) within the Cybersecurity Operations Centre and with internal and external stakeholders
  • Developing and improving detection engineering capabilities, including correlation rules, use cases, SOAR playbooks and response workflows
  • Collecting, preserving and handling digital evidence in accordance with forensic best practices
  • Documenting incidents and preparing clear incident reports for management and stakeholders, ensuring traceability, auditability, and compliance.
  • Developing and maintaining detection capabilities, cybersecurity controls, platforms, automation and integrations, including use cases, correlation rules and monitoring content
  • Improving and contributing to cybersecurity procedures, playbooks, technical documentation and standards
  • Providing cybersecurity awareness training and knowledge transfer to client’ personnel

SPECIFIC KNOWLEDGE, SKILLS AND EXPERTISE

The following specific knowledge, skills and expertise are required for the performance of the above listed tasks:

Security Platforms & Tools

  • Proficiency in the use of Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), and Security Orchestration, Automation and Response (SOAR) systems, in particular Palo Alto Cortex XDR, Splunk, Sentinel and Palo Alto XSOAR.
  • Good ability to develop monitoring content and automation rules for security tools, including the use of SOAR playbooks in Palo Alto XSOAR
  • Very good knowledge of threat-intelligence platforms and sharing mechanisms, including MISP
  • Knowledge of firewall and web application firewall (WAF) technologies, including log analysis
  • Strong experience in querying security platforms and data lakes, including with XQL, KQL, SPL, and scripting languages such as Python
  • Strong experience in malware and suspicious file analysis, including sandbox-based analysis, assessment of impact and implications, and support for remediation measures

Incident Response & Threat Analysis

  • Proficiency in conducting in-depth analysis of complex security incidents across on-premises and cloud environments, including endpoint, network, Windows, Linux and cloud security event analysis, with strong experience in threat hunting and incident response procedures, and provide potential mitigations
  • Ability to coordinate incident response efforts within the Security Operations Centre (SOC) and with other teams
  • Knowledge of integrating threat intelligence into incident analysis, response strategies and incident response planning, informed by the current threat landscape, with the ability to monitor cybersecurity trends and emerging tactics, techniques and procedures (TTPs)
  • Ability to prepare comprehensive incident reports for management and stakeholders

Cloud, Networking & Infrastructure

  • Strong understanding of cloud computing concepts and platforms (e.g. Azure and AWS), including the analysis of related alerts and incidents in hybrid on-premises and cloud environments
  • Strong knowledge of TCP/IP networking
  • Very good knowledge of Windows and Linux operating systems in enterprise environments

Digital Forensics

  • Experience in digital forensic tools, methods, and evidence handling
  • Ability to collect and preserve digital evidence for forensic analysis across various operating systems
  • Understanding of digital forensics techniques

Security Governance & Compliance

  • Very good knowledge of, and adherence to, information security management principles and data security requirements
  • Relevant certification in incident response, cybersecurity tools, or security operations would be considered an advantage

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.