Principal Consultant, Dfir, Incident Response

3 days ago


Sydney, Australia Palo Alto Networks Full time

Company Description
**Our Mission**

At Palo Alto Networks® everything starts and ends with our mission:
Being the cybersecurity partner of choice, protecting our digital way of life.

We have the vision of a world where each day is safer and more secure than the one before. These aren’t easy goals to accomplish - but we’re not here for easy. We’re here for better. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.

We’re changing the nature of work. Palo Alto Networks is evolving to meet the needs of our employees now and in the future through FLEXWORK, our approach to how we work. From benefits to learning, location to leadership, we’ve rethought and recreated every aspect of the employee experience at Palo Alto Networks. And because it FLEXes around each individual employee based on their individual choices, employees are empowered to push boundaries and help us all evolve, together.

**Job Description**:
**Your Career**

**Your Impact**
- Perform reactive incident response functions including but not limited to - host-based analysis functions through investigating Windows, Linux, and Mac OS X systems to identify Indicators of Compromise (IOCs)
- Examine firewall, web, database, and other log sources to identify evidence of malicious activity
- Investigate data breaches leveraging forensics tools including Encase, FTK, X-Ways, SIFT, Splunk, and custom Crypsis investigation tools to determine source of compromises and malicious activity that occurred in client environments
- Manage incident response engagements to scope work, guide clients through forensic investigations, contain security incidents, and provide guidance on longer term remediation recommendations
- Ability to perform travel requirements as needed to meet business demands (on average 20%)
- Not mandatory - Mentorship of team members in incident response and forensics best practices - If the potential is there and this is your ambition you can grow into this mentorship position

**Qualifications**:
**Your Experience**
- Professional and relevant experience in incident response or digital forensics consulting with a passion for cyber security
- Experience with leading complicated engagements including scoping, interfacing with the client, and have executed on a technical front
- Proficient with host-based forensics and data breach response
- Experienced with EnCase, FTK, X-Ways, SIFT, Splunk, Redline, Volatility, WireShark, TCPDump, and open source forensic tools
- Incident response consulting experience required
- Bachelor’s Degree in Information Security, Computer Science, Digital Forensics, Cyber Security or related field or equivalent military experience
- Not mandatory but possible - Potential leadership skills including experience managing a team or individuals or the potential skills to growth to such a role

Additional Information
**The Team**

**Our Commitment**

We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

All your information will be kept confidential according to EEO guidelines.

**Covid-19 Vaccination Information for Palo Alto Networks Jobs**
- Vaccine requirements and disclosure obligations vary by country.
- Unless applicable law requires otherwise, you must be vaccinated for COVID or qualify for a reasonable accommodation if:

- The job requires accessing a company worksite
- The job requires in-person customer contact and the customer has implemented such requirements
- You choose to access a Palo Alto Networks worksite
- If you have questions about the vaccine requirements of this particular position based on your location or job requirements, please inquire with the recruiter.



  • Sydney, Australia Palo Alto Networks Full time

    Company Description **Our Mission** At Palo Alto Networks® everything starts and ends with our mission: Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are...


  • Sydney, Australia Palo Alto Networks Full time

    Company Description At Palo Alto Networks® everything starts and ends with our mission: Being the cybersecurity partner of choice, protecting our digital way of life. We have the vision of a world where each day is safer and more secure than the one before. These aren’t easy goals to accomplish - but we’re not here for easy. We’re here for better....


  • Sydney, Australia Palo Alto Networks Full time

    **Company Description** Our Mission** At Palo Alto Networks® everything starts and ends with our mission: Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are...


  • Sydney, New South Wales, Australia Westpac Group Full time

    Overview Join to apply for the Information Security Principal Consultant - Threat Hunting role at Westpac Group .Create your best future and join Westpac as an Information Security Principal Consultant.Responsibilities The Principal Information Security Consultant is responsible for providing expert technical support to the SOC, with a focus on threat...


  • Sydney, New South Wales, Australia beBeeSecurity Full time $180,000 - $250,000

    Job Overview:We are seeking a skilled Security Engineer to join our Incident Response Team. This individual will be responsible for responding to security events, conducting analysis of threats and intrusion attempts, and providing security services to safeguard sensitive data.The ideal candidate will work closely with detection systems and vulnerability...


  • Sydney, New South Wales, Australia Westpac Group Full time

    OverviewJoin to apply for the Information Security Principal Consultant - Threat Hunting role at Westpac Group.Create your best future and join Westpac as an Information Security Principal Consultant.ResponsibilitiesThe Principal Information Security Consultant is responsible for providing expert technical support to the SOC, with a focus on threat hunting.A...


  • Sydney, Australia Westpac Group Full time

    Create your best future and join Westpac as an Information Security Principal Consultant. The Principal Information Security Consultant is responsible for providing expert technical support to the SOC, with a focus on threat hunting. A technical specialist and escalation point for the SOC, the Principal Information Security Consultant mentors junior staff,...


  • Sydney, Australia Westpac Group Full time

    Create your best future and join Westpac as an Information Security Principal Consultant. The Principal Information Security Consultant is responsible for providing expert technical support to the SOC, with a focus on threat hunting. A technical specialist and escalation point for the SOC, the Principal Information Security Consultant mentors junior staff,...


  • Sydney, Australia NTT Full time

    **Is innovation part of your DNA? Do you want to enable a connected future for people, organizations, and society?** Join our growing global NTT team and you’ll be part of the world’s largest ICT company (by revenue). We’ve combined the capabilities of 28 remarkable companies to become one, leading technology services provider. Together, we help our...


  • Sydney, New South Wales, Australia beBeeIncident Full time $120,000 - $180,000

    Security Incident Response ProfessionalJob Description:We are seeking a seasoned Security Incident Response professional to join our team. The ideal candidate will possess in-depth knowledge of security incident response, threat analysis, and mitigation strategies.The selected individual will be responsible for responding to security incidents, coordinating...