CyberSecurity & Identity Protection Engineer (Tier 3)
BlackCloak
- Location
- United States
- Workplace
- Remote
- Employment
- Full Time
- Salary
- USD 110,000–130,000/yr
Posted 2mo ago
The employer’s full description could not be read from their board. This is a summary of the posting — follow the apply link for the original.
Responsibilities
- Deploy and configure Endpoint Detection and Response (EDR) agents
- Customize detection policies to minimize false positives
- Analyze EDR telemetry to detect attacks
- Monitor client endpoints for malicious indicators
- Isolate compromised devices and communicate incident scope
- Generate monthly executive summaries for clients
- Schedule and run vulnerability scans
- Execute penetration tests
- Review scan results with clients and prioritize patches
- Monitor for threats and vulnerabilities specific to Smart Home and IoT devices
- Alert impacted clients and assist in hardening home networks
- Proactively monitor the Dark Web and criminal forums
- Work with cross-functional teams to alert clients of leaked data
- Manage the credit monitoring platform and alert clients to changes
- Serve as the dedicated case manager for confirmed identity theft incidents
- Handle end-to-end resolution process for identity theft
- Assist in the restoration of compromised accounts
- Hunt for client PII on people-search sites and data broker databases
- Manage the opt-out and removal process for PII
- Identify repetitive manual tasks and build SOAR playbooks or scripts
- Evaluate and implement AI-driven tools to enhance threat detection
- Utilize Machine Learning features to reduce alert fatigue
- Continuously assess toolset architecture
- Optimize API integrations between Identity platforms, EDR, and ticketing systems
- Conduct Post-Mortem reviews after incidents
- Recognize and codify attacker tools, tactics, and procedures
- Develop custom scripts, tools, or methodologies to enhance IR processes
- Develop comprehensive reports of forensic findings and IR activities
- Participate in on-call rotation and escalation team
- Participate in knowledge transfer sessions, product training
- Maintain working knowledge of BlackCloak’s solutions
- Mentor and support Client Success and Security Team Members
- Work closely with engineering and product teams
- Perform research and development on cyber security trends
- Work with the sales team for technical demonstrations
Requirements
- 3-5+ years of experience in Cybersecurity, Fraud Analysis, or Security Engineering
- Experience in deploying, managing, and optimizing EDR tools
- Experience developing detection alerting using automation
- Experience orchestrating detection logic to trigger responses
- Experience developing efficient security workflows
- Experience with client service
- Experience communicating complex technical concepts
- Strong analytical mind required
- Technical knowledge of operating systems such as Windows, macOS, iOS, Android, Linux
- Solid understanding of the US Credit System (Bureaus, FICO, FCRA rights)
- Experience managing identity monitoring platforms (alerts on Credit, SSN, PII)
- Operate independently and efficiently to manage multiple tasks and priorities
- High degree of interpersonal communication skills and discretion for client privacy
- Familiarity in EDR solutions, including CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Carbon Black, and Sophos Intercept X
- Experience with vulnerability assessments
- Experience with identity monitoring platforms
- Experience with SOAR and AI to streamline workflows
- Experience with Python/PowerShell scripting
- Experience with Machine Learning features
- Experience with API integrations
- Experience with Incident Response processes
- Experience developing reports of forensic findings and Incident Response activities
- Experience with client incidents, emergency onboardings and issues
- Experience with technical demonstrations
Preferred
- College degree in an Information Technology (IT/CS/CE) related discipline is a plus, with equivalent experience also considered
- Industry recognized information security certifications a plus: CISSP, CCSP, CFCE, GIAC, OSCP, OSCE, Security+, CEH
- Privacy and identity theft risk management certifications a plus: CIPP, CIPA
- Penetration and vulnerability testing experience
- Windows and macOS forensic investigation and vulnerability management experience
Skills
- CrowdStrike Falcon
- SentinelOne
- Microsoft Defender for Endpoint
- Carbon Black
- Sophos Intercept X
- Python
- PowerShell
- SOAR
- AI
- Machine Learning
- CISSP
- CCSP
- CFCE
- GIAC
- OSCP
- OSCE
- Security+
- CEH
- CIPP
- CIPA
Similar roles
Staff AI Engineering - Enterprise Architecture
American Express · Phoenix, AZ, United States · USD 144,250–256,250/yr · today
Field Service Technician II
Toshiba America Business Solutions · East Syracuse, NY, United States · today
Field Service Technician I
Toshiba America Business Solutions · Rochester, NY, United States · today
Field Service Technician II
Toshiba America Business Solutions · Buffalo, NY, United States · today
Incentives Analyst
MicroStrategy · Tysons Corner, VIRGINIA, United States · USD 66,400–119,600/yr · today
Senior Azure Cloud Engineer
Vaxcyte · San Carlos, California, United States · today