Assistant Vice President / Vice President, Information Security Threat Management Specialist (Application Monitoring & Response), Global Information Security, Sydney, Australia
On-siteSydney, New South Wales, Australia
Job Summary
Analyze application layer alerts, conduct investigations, and respond to malicious actions by leveraging network/packet analysis tools and SIEM solutions to detect targeted attacks. Develop and implement custom alerts and dashboards monitoring controls based on OSI layer 7 indicators, while maintaining and fine-tuning WAF signatures for leading vendors. Provide leadership in assessing new threat vectors, updating existing controls, and designing new security measures through continuous testing and deployment. Mentor less experienced team members and execute risk management strategies to support audit and compliance requirements. Partner with senior business leaders to triage security events and report on impact. On-call and after-hours work are expected with a rotation of approximately one week every two months.
Required Qualifications
- Strong hands-on experience in application security detection and response technologies and processes
- Understanding of common exploits, web application attacks, network protocols and infrastructure/application logs (eg weblogs, AD logs, security logs) for an efficient intrusion analysis
- Advanced log analysis skills leveraging tools such as Splunk or other SIEM solutions to find targeted attacks and hunting exercises
- Experience of maintaining and fine-tuning signatures on WAF of leading vendors such as FE (ASM) and Akamai
- Comfortable with scripting languages and regular expressions
- Working knowledge of common operating systems (Windows/Linux/ OS X)
- Experience in packet captures and analysis (e.g. Wireshark)
- Ability to independently work in a fast-paced environment and drive continuous improvement
- Relevant technical certifications (SANS, CISSP, etc.)
- Excellent verbal and written communication skills, able to adapt a message to various audiences
- On call and after-hours work
- approximately one week every 2 months
Desired Qualifications
- Experience in packet captures and analysis (e.g. Wireshark) is desirable
- Relevant technical certifications (SANS, CISSP, etc.) desirable
- Excellent verbal and written communication skills, able to adapt a message to various audiences
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.