Threat Intelligence Analyst
Job Role: Endpoint Detection and Threat Hunting AnalystLocation: Downey, CA (Remote)Duration: 12 Months ContractAdditional Skills Required:Possess knowledge with Endpoint and Data Protection products such as CrowdStrike Falcon Endpoint Security, Falcon SaaS Security, Falcon Exposure Management, Falcon Data Protection, Falcon Recon, Fusion SOAR Ability to generate reports using APIs. Demonstrate mastery in operating and optimizing the Falcon platform. Possess knowledge of parent and child CIDs in the CrowdStrike environment. Ability to generate reports using APIs as a CrowdStrike Falcon administrator. Demonstrate mastery in operating and optimizing the Falcon platform. Demonstrate ability to use Endpoint and Data Protection products for threat hunting in the environment. Possess knowledge with Axonius Possess knowledge in XDR platforms (Secureworks) Possess knowledge in Cisco SecureWorkload Possess knowledge in SIEM tools for reporting and reviewing of logs (Elastic) Possess knowledge in API integrations and configuration Possess knowledge in creating data pipelines using Cribl.Additional Experience Required:Minimum one (1) year of working experience within the last 2 years in building data pipelines using Cribl.Minimum three (3) years of working experience within the last 4 years in performing workflow analysis using Cisco SecureWorkload/Tetration.Minimum three (3) years of working experience within the last 4 years in Incident response in an enterprise environmentMinimum three (3) years of experience within the last 4 years configuring telemetry API integrations to various SIEM and XDR toolsMinimum six (6) years of working experience within the last 8 years serving as an organization’s subject matter expert responsible for the management of CrowdStrike Falcon and SecureWorksMinimum six (6) years of working experience within the last 8 years administering Endpoint Detection and Response platform for Prevention Policies, creating IOA exclusions, USB Device Control, Firewall, and creating Fusion SOAR workflows.Minimum six (6) years of working experience within the last 8 years with malware, threat intelligence and/or sandbox analysisMinimum four (4) years of working experience with programming or scripting languages such as PowerShell, Python and Bash.Minimum five (5) years of working experience with virtualization/VDI technologies and cloud SaaS solutions.Minimum two (2) years of experience in API integrations for automation.