HOW YOU'LL HELP US KEEP CLIMBING (OVERVIEW & KEY RESPONSIBILITIES)
OVERVIEW:
Do you enjoy solving advanced technical problems, and working with best of breed security tools? Yearn for the opportunity to identify and respond to incidents and threats for a global enterprise? Enjoy building and maintaining successful relationships through direct interaction with peers, managers, and other technical teams? Partnering with management to build a collaborative working environment while promoting high standards, exercising good judgment and professionalism? If you do, then its sounds like you are just the person we are looking for to join our Information Security Team at Delta Airlines.
Responsibilities:
This person will support the Information Security department's goals and objectives by addressing escalations, and the evaluation of technology controls providing key insight and research in new threats, vulnerabilities, and mitigation techniques. In this role they will take the lead in proposing solutions to improve or reduce risk exposure from the overall threat landscape and improve the resilience and readiness of security technologies and processes which ensure the confidentiality, integrity, and availability of the organization's assets, information, data, and IT services in an efficient manner.
Develop and execute security incident response plans and cyber forensic investigations for investigating all reported security incidents.
Develop comprehensive incident reports and investigation summaries.
Develop and collect intelligence to proactively detect and identify high-confidence threats to the brand, service infrastructure and enterprise users and systems.
Responsible for analyzing/validating security control requirements and tuning, defining the mitigation rules, scripting and performing changes or mitigating attacks, and assisting with troubleshooting support related to any issues which may arise from security detection or protection technologies.
Assist with reviewing existing tools, applications, and processes to help strengthen and optimize current security capabilities, as well as identifying any gaps or technical solutions to further enhance the team's effectiveness.
Communicate problems and solutions verbally and in written form to peers and management.
Compliance and governance: help achieve compliance, identify compliance initiatives, and promote appropriate security policies.
Lead analysis and review security events for anomalous activity, collaborate with respective peer groups to take appropriate action to safeguard company information assets against current and foreseen threats.
Lead the exploration of practical security solutions to address emerging threats and compliance requirements, including design and implementation of recommended solutions.
WHAT YOU NEED TO SUCCEED (MINIMUM QUALIFICATIONS)
8+ years' experience with Incident Response
Experience in a 24x7 global enterprise, preferably in the Financial industry
SANS GIAC certifications
Experience with cloud platforms
Experience managing or maintaining malware analysis sandboxes
Knowledge of malware analysis tools
Python and/or PowerShell scripting
Knowledge of Exabeam suite of products or other SIEM tools
Excellent communication and interpersonal skills
Understanding of the business and the ability to assess and address risk without negatively impacting the business
Ability to identify and analyze malicious code
In depth understanding of Windows operating systems
Ability to evaluate exploit code in relationship to existing security controls
Where permitted by applicable law, must have received or be willing to receive the COVID-19 vaccine by date of hire to be considered for U.S.-based job, if not currently employed by Delta Air Lines, Inc.
WHAT WILL GIVE YOU A COMPETITIVE EDGE (PREFERRED QUALIFICATIONS)
Strong knowledge of networking technologies (TCP/IP, HTTP, SMTP, etc.)
Strong knowledge of web application vulnerabilities and solutions
Strong knowledge of Unix & Linux operating systems
Strong knowledge of the functions of various security infrastructure, including firewalls,
Intrusion Prevention Systems, Proxy Servers, Security Event Managers, VPNs
Strong knowledge of web application technologies (HTML, JavaScript, etc.)
Ability to identify vulnerabilities in networks, systems and applications using COTS tools and manual processes
General knowledge of network and systems forensics
In depth knowledge of incident response processes and procedures
General knowledge of threat intelligence
Ability to provide 24-hour on-call support on a rotating basis
CISSP Certified
Atlanta, GA
Delta Air Lines, Inc. provides scheduled air transportation for passengers and cargo in the United States and internationally. The company operates through two segments, Airline and Refinery. Its route network is centered on a system of hubs and markets at airports in Amsterdam, Atlanta, Boston, Detroit, London-Heathrow, Los Angeles, Mexico City, Minneapolis-St. Paul, New York-LaGuardia, New York-JFK, Paris-Charles de Gaulle, Salt Lake City, São Paulo, Seattle, Seoul-Incheon, and Tokyo-Narita.
The company sells its tickets through various distribution channels, including delta.com and mobile applications/Web, telephone reservations, online travel agencies, traditional brick and mortar, and other agencies. It also provides aircraft maintenance, repair, and overhaul services; and vacation packages to third-party consumers, as well as aircraft charters, and management and programs. The company operates through a fleet of approximately 800 aircraft. Delta Air Lines, Inc. was founded in 1924 and is headquartered in Atlanta, Georgia.