
Principal Consultant, Dfir, Incident Response
3 days ago
Company Description
At Palo Alto Networks® everything starts and ends with our mission:
Being the cybersecurity partner of choice, protecting our digital way of life.
We have the vision of a world where each day is safer and more secure than the one before. These aren’t easy goals to accomplish - but we’re not here for easy. We’re here for better. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.
We’re changing the nature of work. Palo Alto Networks is evolving to meet the needs of our employees now and in the future through FLEXWORK, our approach to how we work. From benefits to learning, location to leadership, we’ve rethought and recreated every aspect of the employee experience at Palo Alto Networks. And because it FLEXes around each individual employee based on their individual choices, employees are empowered to push boundaries and help us all evolve, together.
Disruption is at the core of our technology and on our way of work to meet the needs of our employees now and in the future through FLEXWORK, our approach to how we work. We’re changing the nature of work from benefits to learning, location to leadership, we’ve rethought and recreated every aspect of the employee experience at Palo Alto Networks. And because it FLEXes around each individual employee based on their individual choices, employees are empowered to push boundaries and help us all evolve, together.
**Job Description**:
- Perform reactive incident response functions including but not limited to: host-based analysis functions through investigating Windows, Linux, and Mac OS X systems to identify Indicators of Compromise (IOCs)
- Examine firewall, web, database, and other log sources to identify evidence of malicious activity
- Investigate data breaches leveraging forensics tools including Encase, FTK, X-Ways, SIFT, Splunk, and custom Crypsis investigation tools to determine source of compromises and malicious activity that occurred in client environments
- Manage incident response engagements to scope work, guide clients through forensic investigations, contain security incidents, and provide guidance on longer term remediation recommendations
- Ability to perform travel requirements as needed to meet business demands (on average 20%)
- Not mandatory: Mentorship of team members in incident response and forensics best practices. If the potential is there and this is your ambition you can grow into this mentorship position
**Qualifications**:
- Professional and relevant experience in incident response or digital forensics consulting with a passion for cyber security
- Experience with leading complicated engagements including scoping, interfacing with the client, and have executed on a technical front
- Proficient with host-based forensics and data breach response
- Experienced with EnCase, FTK, X-Ways, SIFT, Splunk, Redline, Volatility, WireShark, TCPDump, and open source forensic tools
- Incident response consulting experience required
- Bachelor’s Degree in Information Security, Computer Science, Digital Forensics, Cyber Security or related field
- Not mandatory but possible: Potential leadership skills including experience managing a team or individuals or the potential skills to growth to such a role
Additional Information
We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.
Palo Alto Networks is evolving and changing the nature of work to meet the needs of our employees now and in the future through FLEXWORK, our approach to how we work. From benefits to learning, location to leadership, we’ve rethought and recreated every aspect of the employee experience at Palo Alto Networks. And because it FLEXes around each individual employee based on their individual choices, employees are empowered to push boundaries and help us all evolve, together.
All your information will be kept confidential according to EEO guidelines.
**Covid-19 Vaccination Information for Palo Alto Networks Jobs**
- Vaccine requirements and disclosure obligations vary by country.
- Unless applicable law requires otherwise, you must be vaccinated for COVID or qualify for a reasonable accommodation if:
- The job requires accessing a company worksite
- The job requires in-person customer contact and the customer has implemented such requirements
- You choose to access a Palo Alto Networks worksite
- If you have questions about the vaccine requirements of this particular position based on your location or job requirements, please inquire with the recruiter.
**Covid-19 Vaccination Information for Palo Alto Networks Jobs**
- Vaccine requirements and disclosure obligations vary by country.
- Unless applicable law requires otherwise, you must be vaccinated for C
-
Principal Consultant
24 hours ago
Sydney, Australia Palo Alto Networks Full timeCompany Description **Our Mission** At Palo Alto Networks® everything starts and ends with our mission: Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are...
-
Information Security Principal Consultant
2 weeks ago
Sydney, New South Wales, Australia Westpac Group Full timeJob DescriptionCreate your best future and join Westpac as an Information Security Principal Consultant.The Principal Information Security Consultant is responsible for providing expert technical support to the SOC, with a focus on threat hunting.A technical specialist and escalation point for the SOC, the Principal Information Security Consultant mentors...
-
Sydney, Australia NTT Full time**Is innovation part of your DNA? Do you want to enable a connected future for people, organizations, and society?** Join our growing global NTT team and you’ll be part of the world’s largest ICT company (by revenue). We’ve combined the capabilities of 28 remarkable companies to become one, leading technology services provider. Together, we help our...
-
Information Security Principal Consultant
1 week ago
Sydney, Australia Westpac Group Full timeCreate your best future and join Westpac as an Information Security Principal Consultant. The Principal Information Security Consultant is responsible for providing expert technical support to the SOC, with a focus on threat hunting. A technical specialist and escalation point for the SOC, the Principal Information Security Consultant mentors junior staff,...
-
Information Security Principal Consultant
3 days ago
Sydney, Australia Westpac Group Full timeCreate your best future and join Westpac as an Information Security Principal Consultant. The Principal Information Security Consultant is responsible for providing expert technical support to the SOC, with a focus on threat hunting. A technical specialist and escalation point for the SOC, the Principal Information Security Consultant mentors junior staff,...
-
Information Security Principal Consultant
3 days ago
Sydney, New South Wales, Australia Westpac Group Full time $120,000 - $180,000 per yearCreate your best future and join Westpac as an Information Security Principal Consultant.The Principal Information Security Consultant is responsible for providing expert technical support to the SOC, with a focus on threat hunting. A technical specialist and escalation point for the SOC, the Principal Information Security Consultant mentors junior staff,...
-
Senior Investigator, DFIR
4 weeks ago
Sydney, New South Wales, Australia Gridware Full timeGridware Sydney, New South Wales, AustraliaBecome a part of Gridware's DFIR team and help investigate and respond to cybersecurity incidents impacting Australian organisations.About the role:Your role will be communicating with clients during and after a cybersecurity incident. You'll be required to assess the extent of the incident, provide expert advice,...
-
Principal Incident Response Analyst
3 days ago
Sydney, New South Wales, Australia Atlassian Full time $125,000 - $175,000 per yearOverviewAt Atlassian, the Principal Incident Response Analyst plays a vital role in maintaining the security and integrity of our data and networks. This role, based in the US, is key to the team's planning and execution of work that advances our ability to handle incidents from start to finish. This role involves developing and implementing incident...
-
Senior Threat Detection
4 days ago
Sydney, New South Wales, Australia Ethos BeathChapman Full time $120,000 - $180,000 per yearPrincipal Consultant – Threat Hunting | Principal Incident Response Consultant | SOC Principal Consultant | Senior Threat HunterLocation:Sydney, NSWJob Type:Permanent | Full-TimeCategory:Information & Cyber SecurityAbout the RoleWe're currently recruiting for a Principal Consultant, Threat Hunting to join a leading financial services organisation. This is...
-
Principal Cyber Hunt and Incident Response
1 week ago
Sydney, Australia Reserve Bank of Australia Full timePlay an important part shaping the future of our iconic Australian institution- Hybrid work environment- Permanent position- Join a team focused on remaining at the forefront of technology About the Role As the principal, you’ll be responsible for the following: - Mature the Reserve Bank of Australia’s Cyber Hunt and Incident Response program in a...