IBM is a technology and consulting company seeking an entry-level Threat Hunter to support its CISO Threat Hunt team. The role focuses on proactively detecting, investigating, and disrupting threats through threat hunting, data analysis, security technologies, detection methodology development, and collaboration with incident response and monitoring teams.
Developing hunts, translating them into an iterative process, and deploy them in various toolsets including but not limited to EDRs and SIEMs
Modeling attacks and threats to improve threat detection & mitigation
Conducting deep analysis of threats across the enterprise by taking into consideration threat actor tactics, techniques, and procedures (TTPs)
Developing attack detection & response playbooks, defining counter-measures and strategies to mitigate emerging threats
Documenting and communicating findings to an array of audiences which includes both technical and executive teams
Collaborating in a virtual team and interface with a multitude of stakeholders within or outside the IBM CISO
Qualification
Required
High School Diploma/GED
**Your Abilities & Skills:**
• Modeling threats and mapping them to industry leading frameworks
• Developing threat hunts based on various intelligence inputs
• Actively developing hypotheses for hunting
• Performing both host and network-based investigations using various toolsets
• Pivot off indicators within networks to identify the scope and breadth of attacks
• Reviewing logs to identify evidence of past intrusions
• Performing attack simulation testing where necessary
• Communicate and coordinate with other security focals during an active incident
**Your Knowledge:**
• Computer networking concepts and protocols, and network security methodologies
• Cyber security threats, threat actors and their associated TTPs
• Security controls, how they can be monitored, and thwarted
• Laws, regulations, policies, and ethics as they relate to cybersecurity and Privacy
We believe you are a good fit for this role if you are someone that can analyze alerts, proactively hunt for malicious activity, and develop new detection methods
From a technical expertise perspective, you will succeed in this position if you have several years of experience in:
• Understanding granular details about network flow, operating systems internals, and threat actor intentions
• Correlating anomalous behaviour, intelligence, and statistical outliers in the environment to hypothesis driven hunts
• Applying basic automation or scripting to new or existing processes
IBM will not be providing visa sponsorship for this position now or in the future. Therefore, in order to be considered for this position, you must have the ability to work without a need for current or future visa sponsorship
Preferred
Bachelor's Degree
• Strong understanding of TTP's
• Experience with Endpoint Detection and Response (EDR) tools with a focus in incident investigation and/or threat hunting
Benefits
Hybrid work arrangement
Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being
401(k)
Cash balance pension plan
IBM Employee Stock Purchase Plan
Financial counseling
Life insurance
Short- and long-term disability coverage
Opportunities for performance based salary incentive programs
12 paid holidays
Minimum 56 hours sick time
120 hours vacation
12 weeks parental bonding leave in accordance with IBM Policy
Other Paid Care Leave programs
Paid family leave benefits to eligible employees where required by applicable law
Training and educational resources on IBM's personalized, AI-driven learning platform
Industry-recognized certifications to achieve career goals
Diverse and inclusive employee resource groups
Giving and volunteer opportunities
Discounts on retail products, services & experiences
IBM provides technology and consulting, including software, infrastructure systems, and cloud-based solutions.
Glassdoor
3.9
Founded in 1911
Armonk, New York, USA
10001+ employees
http://www.ibm.com
IBM provides technology and consulting, including software, infrastructure systems, and cloud-based solutions.