Incident Commander - Talos IR
-
Lieu :Chicago, Illinois, US
-
Autre EmplacementRemote, USA
-
Centre d'intérêtExpérience client
-
Plage De Rémunération133300 USD - 193500 USD
-
Type de posteExpérimenté
-
Intérêt pour la technologie*Aucune
-
ID de poste1432410
What You’ll Do
The Cisco Talos Incident Commander will work within established methodologies to perform a variety of Incident Response related activities for Cisco customers this will include emergency response to cyber incidents. It will from time to time also include proactively hunting for adversaries in customer networks, crafting and performing Table-Top Exercises, and performing IR Readiness Assessments. The Incident Commander will also be responsible for leading and working on projects that will support tactical and strategic business objectives. Demonstration of leadership abilities, clear and concise communication with a variety of team members, ability to lead during a crisis, personal agility to adapt to changing environments, and a strong comprehension of malware, emerging threats and calculating risk will be critical to success.
Who You’ll Work With
When you work with us, you will be part of a global team of highly empowered Incident Response and Cyber Threat Intelligence professionals who work as a collaborative team passionate about helping our clients be both better prepared to defend against adversaries on their network, as well as responding to active incidents within their network.
Who You Are
Both your clients and your colleagues consider you a personable, eloquent individual, and a born diplomat. You check your ego at the door and learn from others constantly, while also helping to educate those who are not as proficient as you are in technical or procedural topics. As a result, you have a track record of working diligently to help your clients and teammates and have even come up with some novel techniques in your time.
Required Skills
- Respond to cyber incidents caused by internal and external threats to our customers, which may involve nontraditional working hours
- Must be willing to occasionally travel with less than 24-hour notice, up to 20% of the time
- Can clearly communicate the Incident Response Lifecycle and the Kill Chain (Charge) Life Cycle.
- Demonstrate capability to map technical findings to business impacts and communicate those in a manner which is understandable by a non-technical audience.
- Be able to scope an incident, gain consensus on objectives with customers, and lead a team of incident response consultants during an emergency engagement
- Specialize in host centric analysis applying a variety of tools (e.g., F-Response, X-Ways, Volatility, Cisco Secure Endpoint, etc.)
- Design, lead and participate in Table-Top Exercises with customers
- Proactively seek for adversaries on customer networks maximising a variety of tools and techniques
- Lead and perform Incident Response Readiness Assessments for customers
- Draft communications, assessments, and reports that may be both internal and customer facing, to include leadership and executive management
- Understanding of different charges and how best to craft custom detection, containment, and remediation plans for customers
- Serve as a liaison to different businesses and interface with fellow team members and colleagues on other security teams. As needed, manage relationships with business partners, management, vendors, and external parties
- Lead projects as advised
- Be a champion for the process. Develop and document processes to ensure consistent and scalable response operations.
- Demonstrate industry leadership through blog posts and public speaking at conferences and events
- Bachelors' Degree in Computer Science or a related technical degree; or equivalent industry experience.
- Minimum 5 years of experience in information security and 4 years of experience handling incidents
- Must be willing to be on-call and work off-shift hours, to include nights, weekends, and holidays
Desired Characteristics
Detailed understanding of current cyber security threats, charges, and countermeasures. Such as Ransomware, Cyber Crime, Hacktivism, and associated tactics and techniques.
Consistent track record of understanding, and curiosity about, recognized IT Security-related standards and technologies, proven through training, job experience and/or industry activities.
IT Security Certifications
Industry certifications such as the CISSP, CISM, CISA, GCIH, CFCE, GFCA, and/or GCFE
Why Cisco Talos IR
We always strive to do the right thing, for our team, for our customers, and for the world!
Why Cisco?
#WeAreCisco. We are all unique, but collectively we bring our talents to work as a team, to develop innovative technology and power a more inclusive, digital future for everyone. How do we do it? Well, for starters – with people like you!
Nearly every internet connection around the world touches Cisco. We’re the Internet’s optimists. Our technology makes sure the data traveling at light speed across connections does so securely, yet it’s not what we make but what we make happen which marks us out. We’re helping those who work in the health service to connect with patients and each other; schools, colleges, and universities to teach in even the most challenging of times. We’re helping businesses of all shapes and sizes to connect with their employees and customers in new ways, providing people with access to the digital skills they need and connecting the most remote parts of the world – whether through 5G, or otherwise.
We tackle whatever challenges come our way. We have each other’s backs, we recognize our accomplishments, and we grow together. We celebrate and support one another – from big and small things in life to big career moments. And giving back is in our DNA (we get 10 days off each year to do just that).
We know that powering an inclusive future starts with us. Because without diversity and a dedication to equality, there is no moving forward. Our 30 Inclusive Communities, that bring people together around commonalities or passions, are leading the way. Together we’re committed to learning, listening, caring for our communities, whilst supporting the most vulnerable with a collective effort to make this world a better place either with technology, or through our actions.
So, you have colorful hair? Don’t care. Tattoos? Show off your ink. Like polka dots? That’s cool. Pop culture geek? Many of us are. Passion for technology and world changing? Be you, with us! #WeAreCisco
Lorsqu’elle est disponible, la fourchette salariale affichée pour ce poste reflète l’échelle d’embauche prévue pour les salaires des nouveaux embauchés aux États-Unis et au Canada. Pour les postes non liés à la vente, les fourchettes d’embauche reflètent uniquement le salaire de base; les employés sont également admissibles à des primes annuelles. Les fourchettes d’embauche pour les postes de vente comprennent la rémunération de base et la rémunération incitative. La rémunération individuelle est déterminée par le lieu d’embauche du candidat et par d’autres facteurs, incluant, sans s’y limiter, les compétences, l’expérience et les études, certifications ou formations pertinentes. Les candidats pourraient ne pas être admissibles à la fourchette salariale complète selon leur lieu d’embauche aux États-Unis ou au Canada. Le recruteur peut fournir plus d’informations sur la rémunération du poste dans votre lieu au cours du processus de recrutement.
Les employés américains ont accès à une assurance médicale, dentaire et visuelle de qualité, à un régime 401(k) avec une contribution équivalente de Cisco, à une couverture d’invalidité à court et à long terme, à une assurance vie de base et à de nombreuses prestations de bien-être.
Les employés reçoivent jusqu’à douze jours fériés payés par année civile, ce qui comprend un jour férié flottant (pour les employés non exemptés), plus un jour de congé pour leur anniversaire. Les nouveaux employés non exemptés accumulent jusqu’à 16 jours de congés annuels, à raison de 4,92 heures par période de paie. Les nouveaux employés exemptés participent à la politique de congés annuels flexibles de Cisco qui ne fixe pas de limite précise quant au nombre de jours de congé pouvant être pris par les employés admissibles. Cependant, cette flexibilité dépend de la disponibilité et de certaines contraintes opérationnelles. Tous les nouveaux employés sont admissibles aux congés de maladie, sous réserve de la Politique relative aux congés de maladie de Cisco. Ils auront droit à quatre-vingts (80) heures de congés de maladie à leur date d’embauche et le 1er janvier de chaque année par la suite. Jusqu’à 80 heures de congés de maladie non utilisées seront reportées d’une année civile à l’autre, de sorte que le nombre maximal d’heures de congé de maladie dont un employé peut disposer est de 160 heures. Les employés de l’Illinois bénéficient d’un programme spécifique de congés spécialement conçu pour répondre aux exigences locales. Tous les employés disposent également de congés payés pour faire face à des situations critiques ou d'urgence. Nous offrons des heures supplémentaires rémunérées pour faire du bénévolat et rendre service à la communauté.
Les employés participant à des plans de vente reçoivent, en plus de leur salaire de base, une rémunération incitative fondée sur les performances, qui est répartie entre les composantes sur quota et non. Pour la rémunération incitative basée sur des quotas, Cisco paie généralement comme suit :
0,75 % de l'incitatif cible pour chaque tranche de 1 % du chiffre d’affaires atteint jusqu’à concurrence de 50 % du quota;
1,5 % de l'incitatif cible pour chaque tranche de 1 % du chiffre d'affaires atteint entre 50 % et 75 %;
1 % de l'incitatif cible pour chaque tranche de 1 % du chiffre d'affaires atteint entre 75 % et 100 %; et lorsque le rendement dépasse 100 % d’atteinte, les taux incitatifs sont égaux ou supérieurs à 1 % pour chaque tranche de 1 % du chiffre d'affaires atteint, sans limites de rémunération incitative.
Pour les éléments de performance de vente non basés sur les quotas, tels que les objectifs de vente stratégiques, Cisco peut payer jusqu’à 125 % de l’objectif. Les plans de vente de Cisco ne prévoient pas de seuil minimum de performance pour le versement de la rémunération incitative pour les ventes.
Renseignements confidentiels de Cisco