Principal Cybersecurity Engineer - Cybersecurity Detection & Response Engineer
Job Description Principal Cybersecurity Engineer
(Cybersecurity Detection & Response Engineer)
The Principal Cybersecurity Engineer role (Cybersecurity Detection and Response Engineer) is an experienced role within the Liberty Mutual's Cybersecurity Operations Center and will work within an agile team to develop proactive methods to detect, protect, and respond to cyber threats. This role will work cross functionally across many security teams within the Cybersecurity Operations Center and will report directly to the Director of the Cybersecurity Operations Center.
- Acts as a senior member of an agile team
- Performs coaching and mentoring for junior engineers
- Performs research on new methods for detecting malicious or suspicious cyber behavior
- Develops new methods for detecting cyber threats through monitoring security controls and technology.
- Manages, develops, and deploys event correlation and risk-based methods for building detections
- Manages, develops, and deploys detections in behavioral analytics platforms
- Works within Agile software development environment supporting a SIEM & Security Orchestration and Automation platform (SOAR)
- Develops automation response and remediation playbooks within a SOAR technology
- Performs analysis to ensure quality, integrity, and fidelity of use cases, rules, and analytics for effectiveness
- Supports Incident Response teams as needed to collect artifacts for audit and internal investigations.
- Manages, develops, and deploys to popular cloud platforms
- Leverages APIs to perform integration of systems where possible
- Utilizes industry standards and frameworks such as NIST Standards, MITRE ATT&CK & Defend Framework, and the Cyber threat Kill Chain.
- Collaborates with various teams to understand cyber detection requirements
- Uses a customer centric approach to building detections and response
Preparation, Training, and Experience
- Subject matter expertise in the following areas: Cyber Detection Engineering
- Subject matter expertise in at least one of the following areas:
- Software Development, Cyber Threat Hunting, Malware Analysis & Reverse Engineering, Cyber Threat Intelligence, Digital Forensics & Incident Response, SOAR Development
- College-level degree in Computer Science, Computer Engineering, Information Security, or other related discipline
- Active Cybersecurity certifications are desirable (but not required) such as GCIH, GREM, GCFA, GCTI, OSCP etc.
- 7 years of recent experience working as a cybersecurity professional
- Previous experience working in a Cyber Security Operations Center or similar function is desirable
- Knowledge of relevant frameworks, standards, and best practices such as NIST CSF, PCI-DSS, CIS CSCs, MITRE ATT&CK, Cyber Kill Chain etc.
- Experience with using a Security Information Event Management (SIEM) platform
- Experience with using a scripting language such as Python or PowerShell for task automation or tool creation is desirable
- Demonstrable knowledge of several of the following areas: cybersecurity concepts, network protocols, firewalls, IDS/IPS systems, email security, endpoint security, network security, Windows/Linux/macOS systems, cyber threat hunting, malware analysis tools and techniques, cyber threat intelligence, common threat actor TTPs, application security concepts, cloud security fundamentals, Incident Response methodologies.
- Excellent oral and written communication skills.
- Industry Security Certifications
- Cloud based security certifications
- Offensive security certifications
- Security Solutions/Tools Certifications
At Liberty Mutual, our purpose is to help people embrace today and confidently pursue tomorrow. That's why we provide an environment focused on openness, inclusion, trust and respect. Here, you'll discover our expansive range of roles, and a workplace where we aim to help turn your passion into a rewarding profession.
Liberty Mutual has proudly been recognized as a Great Place to Work by Great Place to Work US for the past several years. We were also selected as one of the 100 Best Places to Work in IT on IDG's Insider Pro and Computerworld's 2020 list. For many years running, we have been named by Forbes as one of America's Best Employers for Women and one of America's Best Employers for New Graduatesas well as one of America's Best Employers for Diversity. To learn more about our commitment to diversity and inclusion please visit: https://jobs.libertymutualgroup.com/diversity-inclusion
We value your hard work, integrity and commitment to make things better, and we put people first by offering you benefits that support your life and well-being. To learn more about our benefit offerings please visit: https://LMI.co/Benefits
Liberty Mutual is an equal opportunity employer. We will not tolerate discrimination on the basis of race, color, national origin, sex, sexual orientation, gender identity, religion, age, disability, veteran's status, pregnancy, genetic information or on any basis prohibited by federal, state or local law.