JobHabor

CyberSecurity & Identity Protection Engineer (Tier 3)

BlackCloak

Location
United States
Workplace
Remote
Employment
Full Time
Salary
USD 110,000–130,000/yr
Apply on the employer’s site

Posted 2mo ago

The employer’s full description could not be read from their board. This is a summary of the posting — follow the apply link for the original.

Responsibilities

  • Deploy and configure Endpoint Detection and Response (EDR) agents
  • Customize detection policies to minimize false positives
  • Analyze EDR telemetry to detect attacks
  • Monitor client endpoints for malicious indicators
  • Isolate compromised devices and communicate incident scope
  • Generate monthly executive summaries for clients
  • Schedule and run vulnerability scans
  • Execute penetration tests
  • Review scan results with clients and prioritize patches
  • Monitor for threats and vulnerabilities specific to Smart Home and IoT devices
  • Alert impacted clients and assist in hardening home networks
  • Proactively monitor the Dark Web and criminal forums
  • Work with cross-functional teams to alert clients of leaked data
  • Manage the credit monitoring platform and alert clients to changes
  • Serve as the dedicated case manager for confirmed identity theft incidents
  • Handle end-to-end resolution process for identity theft
  • Assist in the restoration of compromised accounts
  • Hunt for client PII on people-search sites and data broker databases
  • Manage the opt-out and removal process for PII
  • Identify repetitive manual tasks and build SOAR playbooks or scripts
  • Evaluate and implement AI-driven tools to enhance threat detection
  • Utilize Machine Learning features to reduce alert fatigue
  • Continuously assess toolset architecture
  • Optimize API integrations between Identity platforms, EDR, and ticketing systems
  • Conduct Post-Mortem reviews after incidents
  • Recognize and codify attacker tools, tactics, and procedures
  • Develop custom scripts, tools, or methodologies to enhance IR processes
  • Develop comprehensive reports of forensic findings and IR activities
  • Participate in on-call rotation and escalation team
  • Participate in knowledge transfer sessions, product training
  • Maintain working knowledge of BlackCloak’s solutions
  • Mentor and support Client Success and Security Team Members
  • Work closely with engineering and product teams
  • Perform research and development on cyber security trends
  • Work with the sales team for technical demonstrations

Requirements

  • 3-5+ years of experience in Cybersecurity, Fraud Analysis, or Security Engineering
  • Experience in deploying, managing, and optimizing EDR tools
  • Experience developing detection alerting using automation
  • Experience orchestrating detection logic to trigger responses
  • Experience developing efficient security workflows
  • Experience with client service
  • Experience communicating complex technical concepts
  • Strong analytical mind required
  • Technical knowledge of operating systems such as Windows, macOS, iOS, Android, Linux
  • Solid understanding of the US Credit System (Bureaus, FICO, FCRA rights)
  • Experience managing identity monitoring platforms (alerts on Credit, SSN, PII)
  • Operate independently and efficiently to manage multiple tasks and priorities
  • High degree of interpersonal communication skills and discretion for client privacy
  • Familiarity in EDR solutions, including CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Carbon Black, and Sophos Intercept X
  • Experience with vulnerability assessments
  • Experience with identity monitoring platforms
  • Experience with SOAR and AI to streamline workflows
  • Experience with Python/PowerShell scripting
  • Experience with Machine Learning features
  • Experience with API integrations
  • Experience with Incident Response processes
  • Experience developing reports of forensic findings and Incident Response activities
  • Experience with client incidents, emergency onboardings and issues
  • Experience with technical demonstrations

Preferred

  • College degree in an Information Technology (IT/CS/CE) related discipline is a plus, with equivalent experience also considered
  • Industry recognized information security certifications a plus: CISSP, CCSP, CFCE, GIAC, OSCP, OSCE, Security+, CEH
  • Privacy and identity theft risk management certifications a plus: CIPP, CIPA
  • Penetration and vulnerability testing experience
  • Windows and macOS forensic investigation and vulnerability management experience

Skills

  • CrowdStrike Falcon
  • SentinelOne
  • Microsoft Defender for Endpoint
  • Carbon Black
  • Sophos Intercept X
  • Python
  • PowerShell
  • SOAR
  • AI
  • Machine Learning
  • CISSP
  • CCSP
  • CFCE
  • GIAC
  • OSCP
  • OSCE
  • Security+
  • CEH
  • CIPP
  • CIPA

Similar roles