C

Senior Security Incident Commander - (Threat Management) (Remote)

Cisco Meraki
Remote
Canada, Canada

Applications are accepted until further notice

At Cisco Meraki, we know that technology can connect, empower, and drive us. Our mission is to simplify technology so our customers can focus on what's most meaningful to them: their students, patients, customers, and businesses. We’re making networking easier, faster, and intelligent with technology that simply works.

The modern world runs on the internet, and the internet cannot exist without its underlying infrastructure. Meraki makes setting up, leading, and maintaining that infrastructure easier than it has ever been before. Meraki enables connectivity everywhere from neighborhood cafes to education institutions to global hospitality groups operating thousands of sites!

The Threat Management Response team is responsible for 24x7x365 monitoring and rapid incident response for all Cisco Meraki environments. We are the last line of defense to protect the company and our customer's data from our threat actors and adversaries. You will have a significant impact on the security of millions of Cisco Meraki users all around the world!

Incidents can happen at any time, as such this position requires on-call work (including overnight and weekends) on an as-needed basis. The core hours for this position are 9:30 AM PST - 6:30 PM (in the time zone you are hired for), Monday through Friday.

Key responsibilities:

  • Serve on a rotation of security incident commanders, work with heads of every major product team to ensure a quick mobilization for high-severity incidents
  • Experience responding to high severity incidents and handling the remediation process. (e.g. Malware analysis, large scale phishing attacks, production intrusion, etc.)
  • Familiarity with the following tools:
  • File Integrity Monitoring (FIM)
  • Vulnerability Scanners
  • Network and Host Intrusion Detection (IDS) such as SNORT/Sourcefire, Palo Alto, etc.
  • Incident Response Case Management Tools
  • Network sniffers and packet tracing tools such as DSS, Ethereral, tcpdump, Wireshark, etc.
  • Investigate security events for the following platforms and technologies:
  • Cloud (AWS, Azure, GCP)
  • Windows/Mac/Linux OS
  • Cisco physical and virtual network devices and platforms
  • Perform basic forensics when security incidents occur
  • Develop, document, and lead initiatives to improve Incident Response strategies, runbooks, capabilities, and technologies

You are an ideal candidate if you:

  • Understand common threat actor tactics, techniques, and procedures (TTPs) and how they are chained together
  • Have experience leading threat hunts, using available logs and threat intelligence to proactively identify and investigate potential risks and suspicious behavior
  • Successful candidates typically have 6+ years in Cybersecurity Incident Response roles, primarily passionate about leading sophisticated incidents involving multi-functional teams.
  • Understand major security compliance frameworks such as PCI, SOC 2, and FedRAMP as they relate to incident monitoring and response

Bonus points for:

  • Relevant industry security certifications such as CISSP, SANS GIAC (e.g. GCIH, GNFA, GCFE, GCFA, GREM), AWS certifications (SAA, SAP, or SCS), etc.
  • Familiarity with other security verticals such as: Digital Forensics, Threat Intelligence, Threat Detection, Application Security, Cloud Security, Offensive Security
  • Networking experience with LAN/WAN routing and high availability (OSPF, BGP4/iBGP, EIGRP, and NSRP) routing protocols and technologies
  • Experience with IoT platforms, large-scale distributed systems, and/or client-server architectures

At Cisco .Meraki, we’re challenging the status quo with the power of diversity, inclusion, and collaboration. When we connect different perspectives, we can imagine new possibilities, encourage innovation, and release the full potential of our people. We’re building an employee experience that includes appreciation, belonging, growth, and purpose for everyone.

Cisco is an Affirmative Action and Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, national origin, genetic information, age, disability, veteran status, or any other legally protected basis. Cisco will consider for employment, on a case by case basis, qualified applicants with arrest and conviction records.

 

 

 

 

 

 

 

#LI-Remote

Apply now