
Principal Forensic & Incident Response Architect | Full Time
- Detroit, MI
- Permanent
- Full-time
- Bachelor's Degree (Security, Technology, or Forensics) or equivalent of five (5) years of relevant experience in lieu of degree is required.
- Minimum of two (2) years leading hands-on enterprise security incident response investigations, required.
- Minimum of two (2) years executing threat hunting in both on-premise and cloud environments using both automated tools and manual techniques, required.
- Solid understanding of network and system intrusion and detection methods, examples of related technologies include SIEM, End Point Detection and Response, firewalls, hacking tools, techniques, and procedures.
- Deep understanding of Windows and Unix\Linux operating systems including logging facilities.
- Understanding of network protocol analysis, public key infrastructure, SSL, Active Directory. Understanding of basic malware analysis, endpoint lateral movement detection methodologies and host forensic tools.
- Understanding of Indicators of Compromise (IOCs) and attacker TTPs.
- Familiarity with MITRE ATT&CK.
- Expert understanding of information systems security; network architecture; general database concepts; document management; hardware and software troubleshooting; electronic mail systems; Microsoft Office applications; intrusion tools; and computer forensic tools such as Axiom, EnCase, Access Data, and/or FTK.
- GCIH - GIAC Certified Incident Handler, preferred. GNFA - GIAC Network Forensic Analyst,
- Preferred. GCFA - GIAC Certified Forensic Analyst
- Preferred. GCFE -GIAC Certified Forensic Examiner
- preferred. CFCE - Certified Forensic Computer Examiner, preferred.
- Organization: Corporate Services
- Department: Ascension Cybersecurity IR
- Shift: Day Job
- Union Code: Not Applicable