Skip to main content Skip to footer

Cyber Security Threat Hunter

Prague Job No. 12919647 Full-time - Remote

工作描述

Accenture Cyber Fusion Center in Prague is a unique multidisciplined team of around 200 people passionate about Cyber Security.  As part of Accenture Security we support clients globally to prepare for and defend against the rapidly changing capabilities of cyber attackers. We are looking for security professionals to join our international team at our custom-built location.

Role summary

As part of the Accenture Cyber Fusion Center in Prague, you will be part of a specialised team to deliver managed Threat Hunting operations to our clients. Our managed Threat Hunting service enables our clients to uncover threats that would otherwise remain hidden. You will be looking for the evidence of active threats within our clients environments that bypass both preventative and detective controls using our delivery methodology and threat hunting tools and techniques.

职位要求

Requirements

  • Proven Experience with Threat Hunting or Incident investigations (SOC/IR)

  • Experienced in using enterprise security solutions (such as SIEM and EDR) to conduct Investigations or Hunts

  • Strong knowledge of Windows internals and solid networking fundamentals

  • Strong understanding of common attack vectors and offensive tools and tactics

  • Understanding of enterprise architecture and large IT environment operations

  • Understanding of common malware types and behaviors and common infection vectors

  • Ability to identify attacker Tactics, Techniques, and procedures (TTPs)

  • Strong documentation and reporting skills

  • Solid presentation and communication skills

  • 3+ years of information security operations experience

Nice to have

  • Experience with Cloud environments

  • Experience with OT and ICS environments

  • Knowledge of system internals for Unix-based systems

  • Experience with reverse engineering and sandboxing technologies

  • Degree in relevant computer science/IT field

  • Security certifications, for example, but not limited to, GREM, GCFE, GCFA, CEH, GCIH

  • SIEM (Splunk, QRadar, Sentinel, …) and EDR (CrowdStrike, FireEye HX, Endgame, Defender ATP) experience

  • Experience with IoC lifecycle (development, organization, sharing, effective usage)

  • Experience with statistical/quantitative analysis methods and tools

  • Ability to develop small automation scripts and makeshift tools (Python, PowerShell, Bash, …)

What we offer

  • You'll learn, grow and advance in an innovative culture that thrives on shared success, innovative and diverse ways of thinking and enables boundaryless opportunities that can drive your career in new and exciting ways

  • Opportunity to work on various interesting projects delivered to our global TOP 500 clients and with the newest trends in the cyber security area

  • Professional training and acquisition of crucial security certificates – from Offensive Security through CREST to SANS trainings and GIAC certifications

  • Ability to move between different teams with different specializations in either offensive or defensive security

  • Access to the cutting-edge cyber security products and solutions 

  • Remote work

更多了解埃森哲

我们的专长

我们秉承“科技融灵智,匠心承未来”的企业使命,致力于通过引领变革创造价值,为我们的客户、员工、股东、合作伙伴与整个社会创造美好未来。

认识我们的团队

从业务服务部门到各个行业领域, 从职场新人到卓越领袖,我们一直在运用科技创造非凡!

联系我们

加入我们的团队

搜索与你的技能和兴趣匹配的空缺职位。我们希望招聘充满激情、求知若渴、富有创意、专注于解决方案且喜欢团队合作的员工。

埃森哲职位博客

关注埃森哲职业博客,在职场中先人一步,从真正的业内人士处,获取职业建议、内部观点以及可以即学即用的行业真知。