Allianz is seeking a Cyber Security Specialist to join the Security Operations team. The specialist will serve on the front lines of Allianz s Security team and will lead and support security investigations across the company s global infrastructure as we'll as respond to escalations from different entities. The specialist will leverage an armory of tools to investigate and respond to both external and internal security threats. Utilizing Allianz tooling, you will monitor security events in real-time, assess external and internal threats, and provide accurate and timely response. You will collaborate closely with multiple product team within the Tribe, with a diverse set of skills to tackle the array of security challenges that we encounter.
Responsibilities includes
- Lead security incident response in a cross-functional environment and drive incident resolution.
- Lead and develop Incident Response initiatives that improve Allianz capabilities to effectively respond and remediate security incidents.
- Perform digital forensic investigations and analysis of a wide variety of assets including endpoints.
- Perform log analysis from a variety of sources to identify potential threats.
- Build automation for response and remediation of malicious activity.
- Write complex search queries in the EDR as we'll as SIEM tools for hunting the adversaries.
- Works on SOAR cases, automation, workflow & Playbooks.
- Integrating and working on Identity solutions.
- Developing SIEM use cases for new detections specifically on identity use cases.
Minimum Qualifications:
- 5-10 years of experience in Security Incident Response, Investigations
- Working experience in Microsoft On-prem and Entra ID solutions
- Good knowledge in Active Directories and Tier 0 concepts
- Very good knowledge of operating systems, processes, registries, file systems, and memory structures and experience in host and memory forensics (including live response) on Windows, macOS and Linux.
- Experience investigating and responding to both external and insider threats.
- Experience with attacker tactics, techniques, and procedures (MITRE ATT&CK)
- Experience analyzing network and host-based security events
Your benefits:
We believe in rewarding performance and our compensation and benefits package includes a company bonus scheme, pension, employee shares program and multiple employee discounts (details vary by location)
From career development and digital learning programs to international career mobility, we offer lifelong learning for our employees worldwide and an environment where innovation, delivery and empowerment are fostered
Flexible working, health and we'llbeing offers (including healthcare and parental leave benefits) support to balance family and career and help our people return from career breaks with experience that nothing else can teach