Csirt Engineer (hybrid)

GEICO GEICO · Insurance · Bethesda, MD +3

GEICO is seeking an experienced Incident Response Engineer to join their Cybersecurity Incident Response Team (CSIRT). The role involves identifying, detecting, responding to, and mitigating sophisticated cybersecurity threats against GEICO and its customers. Responsibilities include handling security events, conducting incident response activities, complex investigations (cloud response, malware analysis, threat actor analysis, root cause analysis), and remediation. The engineer will work with various tools and data sources, analyze events in cloud environments (AWS, Azure, GCP), perform host-based analysis on Windows, Linux, and Mac, and examine network traffic logs to identify Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs).

What you'd actually do

  1. Identify, detect, respond, and mitigate sophisticated threats to GEICO
  2. Responding to cloud-based incidents in AWS, Azure, and GCP
  3. Host-based analysis of Windows, Linux and Mac operating systems
  4. Examine data collected from a variety of tools and sources (e.g., IDS alerts, firewall logs, web logs, network traffic logs) to identify IOCs and/or malicious TTPs
  5. Analyze events that occur within their environments for the purposes of mitigating threats

Skills

Required

  • Incident Response
  • digital forensics
  • cloud-based incidents
  • root cause analysis
  • MITRE ATT&CK framework
  • Windows, Linux, Mac operating systems security
  • computer networking concepts and protocols
  • network security methodologies
  • threat actor TTPs
  • Bash
  • Python
  • Perl
  • PowerShell
  • critical thinking
  • logic
  • decision making
  • troubleshooting
  • problem-solving
  • technical documentation
  • network packet captures
  • cloud computing technologies
  • cyber defense systems

Nice to have

  • GIAC Cloud Security Essentials Certification (GCLD)
  • GIAC Cloud Forensics Responder (GCFR)
  • GIAC Certified Web Application Defender (GWEB)
  • GIAC Cloud Security Automation (GCSA)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Examiner (GCFE)
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Reverse Engineering Malware (GREM)
  • GIAC Defending Advanced Threats (GDAT)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Certified Information Systems Security Professional (CISSP)

What the JD emphasized

  • 4+ years of Incident Response experience
  • Experience with responding to cloud-based incidents
  • Demonstrated experience performing root cause analysis of security events and incidents