
Senior Cybersecurity Incident Responder (f/m/d)
- Amadora, Lisboa
- Permanente
- Horário completo
- Investigate and follow through on IT security incidents in a geographically distributed environment, considering all relevant technical and non-technical stakeholders during all phases of the incident.
- Analyze reports about potential / suspected incidents, collect and analyze technical incident information and log data, generate reports, and ensure progress on incident tickets.
- Help improving CERT's internal toolset by contributing with new ideas on functionality and features.
- Report to and advise management and other stakeholders to improve and drive Siemens' Cybersecurity posture. Doing so, you will balance level of detail and strategic insight presented on a case-by-case basis.
- University degree (BA) in Information Technology, Engineering or similar
- Significant work experience in Incident Response including in complex cloud environments; experience in IT Forensics or Vulnerability Management is a plus
- Significant technical knowledge with relevant exposure and expertise in IT Security, in several of the following technologies: Linux and Windows operating systems, web-technologies (encryption, HTTP, REST), networking, cloud environments.
- Solid understanding of technical and organizational aspects of information security, e.g., through prior defensive or offensive work experience.
- Experienced in fundamental attack concepts (terminology, tools, processes, etc.).
- Knowledge of cyber threats and vulnerabilities: how to properly identify, triage, and remediate threats based on threat intelligence as well as on analysis of security events, log data and network traffic.
- Strong analytical skills with the ability to collect, organize, analyze, and disseminate significant amounts of information with attention to detail and accuracy
- Advanced interpersonal skills: clear and concise communication; able to address collaborators of different backgrounds and technical levels and expertise and work proactively
- Fluent in spoken and written English, including security terminology.
- Experience in conducting forensics investigations on Windows, Mac or Linux operating systems
- Vulnerability Handling / Management
- Creation, analysis, and management of threat intelligence
- Development of internal tooling (Python, Django, Shell scripting)
- Relevant Industry Certifications such as SANS/GIAC (e.g., GCIA, GCIH, GNFA, GCFA), CompTIA Security+ CISSP, CISA, CISM are desirable.