الصفحة الرئيسية قطر Principal Consultant, Dfir, Reactive Services

الصفحة الرئيسية قطر Principal Consultant, Dfir, Reactive Services

Principal Consultant, Dfir, Reactive Services

دوام كامل في a Laimoon Verified Company في Qatar
نُشرت يوم May 4, 2024

تفاصيل الوظيفة

Company Description

At Palo Alto Networks®, everything starts and ends with our mission: Being the cybersecurity partner of choice, protecting our digital way of life. We have the vision of a world where each day is safer and more secure than the one before. These aren't easy goals to accomplish - but we're not here for easy. We're here for better. We are a company built on the foundation of challenging and disrupting the way things are done, and we're looking for innovators who are as committed to shaping the future of cybersecurity as we are.

We're changing the nature of work. Palo Alto Networks is evolving to meet the needs of our employees now and in the future through FLEXWORK, our approach to how we work. From benefits to learning, location to leadership, we've rethought and recreated every aspect of the employee experience at Palo Alto Networks. And because it FLEXes around each individual employee based on their individual choices, employees are empowered to push boundaries and help us all evolve, together.

**Job Description**:

**Your career**

This role is client-facing and requires the Principal Consultant to lead and produce deliverables based on reactive services client engagements. The Principal Consultant will work directly with multiple customers and key stakeholders (Admins, C-Suite, etc) to manage incident response engagements and provide guidance on longer term remediation. Furthermore the Principal Consultant will act as a mentor and goto person to build up and strengthen our DFIR Service. Speaking at a conference, taking part in a Panel or representing Unit42 in any other ways are also part of the role.

**Your Impact as a Principal Consultant**:

- Perform and lead reactive incident response functions including but not limited to: host-based analysis functions through investigating Windows, Linux, and Mac OS X systems to identify Indicators of Compromise (IOCs).

- Examine log sources such as cloud provider platform native logs such as Microsoft M365, Microsoft Azure, Google Cloud, Google Workspaces and AWS.

- Investigate cloud security incidents using one of the following: Palo Alto Networks Prisma Cloud, Microsoft Defender, AWS Guard Duty, AWS CloudTrail, AWS CloudWatch.

- Investigate data breaches leveraging forensics tools including Encase, FTK, X-Ways, SIFT, Splunk, and custom Palo Alto Networks investigation tools to determine source of compromises and malicious activity that occurred in client environments.

- Manage incident response engagements to scope work, guide clients through forensic investigations, contain security incidents, and provide guidance on longer term remediation recommendations.

- Ability to perform travel requirements as needed to meet business demands (on average 20%).

- Mentorship of team members in incident response and forensics best practices.

**Qualifications**:

**Your experience**

- 6+ years of incident response or digital forensics consulting experience with a passion for cyber security

- Strong leadership skills including experience managing a team or individuals

- Experience with leading complicated engagements including scoping, interfacing with the client, and have executed on a technical front

- Proficient with host-based forensics, cloud-based forensics and data breach response.

- Proficient with querying data sources such as logging platforms and databases (e.g. SQL, Splunk, Log Analytics Workspaces, XSIAM/XDR)

- Experienced with EnCase, FTK, X-Ways, SIFT, Splunk, Redline, Volatility, WireShark, TCPDump, and open source forensic tools.

- ** Cloud consulting and/or cloud incident response experience required.**:

- Incident response consulting experience required Bachelor's Degree in Information Security, Computer Science, Digital Forensics, Cyber Security or related field

Additional Information

**The Team**

**Our Commitment**

All your information will be kept confidential according to EEO guidelines.

Apply safely

To stay safe in your job search, information on common scams and to get free expert advice, we recommend that you visit SAFERjobs, a non-profit, joint industry and law enforcement organization working to combat job scams.

Share this job
See All Principal Jobs
تعليقات وملاحظات تعليقات وملاحظات