Security Incident Commander, Threat Management Response

1 month ago


Sydney, Australia Cisco Full time
At Cisco Meraki, we know that technology can connect, empower, and drive us. Our mission is to simplify technology so our customers can focus on what's most significant to them: their students, patients, customers, and businesses. We’re making networking easier, faster, and sophisticated with technology that simply works.At Meraki, you will be a part of a tight-knit engineering organization working with hardworking, effective engineers. A significant influence over the tools that we use to supervise and audit our system and where we choose to deploy them. Responsible for coordinating the response to security incidents. You will support other security teams in driving business-friendly security and process improvements. Finally, by developing our capabilities to promptly detect threats, you will have a direct, immediate, and positive impact on our customers and the hundreds of millions of users that rely on Meraki access points, switches, security appliances, and cameras every single dayWe are passionate about building real products that our customers love. We believe in fostering a positive culture by hiring, mentoring, and empowering thoughtful, conducive, humble people. With the support of management, we constantly look within for ways to improve organizationally. Finally, we maintain a positive relationship with Cisco that gives us the stability and resources of a larger company without sacrificing our startup culture. We are confident you will love it hereThe Threat Management Response team is responsible for 24x7x365 monitoring and rapid incident response for all Cisco Meraki environments. We are the last line of defense to protect the company and our customer's data from threat actors and adversaries.Incidents can happen at any time, as such this position requires on-call work (including overnight and weekends) on an as-needed basis. The core hours for this position are 9:30 AM PST - 6:30 PM PST, Monday through Friday. Key responsibilities: Serve on a rotation of security incident commanders, working with heads of every major product and engineering team to ensure a quick mobilization for high-severity incidents Serve as incident commander when escalations from security analysts require immediate response Write SQL to search data warehouses and large datasets for signs of compromise Respond to high severity incidents and handle the remediation process. (e.g. Malware analysis, large scale phishing attacks, production intrusion, etc.) Familiarity with the following tools: Security Incident and Event Monitoring (SIEM) File Integrity Monitoring (FIM) Vulnerability Scanners, Endpoint Detection & Response (EDR), Security Orchestration, Automation & Response (SOAR) Network and Host Intrusion Detection (IDS) such as SNORT/Sourcefire, Palo Alto, etc. Investigate security events for the following platforms and technologies: Cloud (AWS, Azure, GCP) Cisco physical and virtual network devices and platforms Assist with and perform digital forensics on host OS or cloud system infrastructure to identify IOCs and other signs of imminent security risk and threat Write response runbooks and author documentation on organizational response processes You are an ideal candidate if you: Understand common threat actor tactics, techniques, and procedures (TTPs) and how they are chained together Have experience leading threat hunts, using available logs and threat intelligence to proactively identify and investigate potential risks and suspicious behavior Have a calm methodical approach to investigating potential threats Have minimum of 5 years worked in cybersecurity roles professionally Have the ability to build and/or re-architect new and existing solutions within AWS to help tackle problems outstanding to Meraki’s security logging or security investigation infrastructure Expertise with observability and security tools like Splunk, ELK, Snowflake or other searchable big data solutions Understand core cybersecurity concepts such as encryption, hashing, non-repudiation, vulnerability management, and least privilege Understand major security compliance frameworks such as PCI, SOC 2, and FedRAMP as they relate to incident monitoring and response Bonus points for: Relevant industry security certifications such as CISSP, SANS GIAC (e.g. GCIH, GNFA, GCFE, GCFA, GREM), AWS certifications (SAA, SAP, or SCS), etc. Familiarity with other security verticals such as: Digital Forensics, Threat Intelligence, Threat Detection, Application Security, Cloud Security, Offensive Security Valuable knowledge of detection tools, for example: Nessus, Qualys, OSSEC, Osquery, Suricata, Threatstack, AWS Guard Duty Experience with IoT platforms, large-scale distributed systems, and/or client-server architectures

  • Sydney, New South Wales, Australia Cisco Full time

    Cisco is seeking a skilled Incident Commander to join our Threat Management Response team. As an Incident Commander, you will play a critical role in ensuring the security and integrity of our systems and data.Job SummaryWe are looking for a highly motivated and experienced Incident Commander to lead our response efforts in the event of a security incident....


  • Sydney, New South Wales, Australia Cisco Full time

    Protecting Our Customers and DataCisco Meraki is committed to simplifying technology and providing innovative solutions to our customers. As a Threat Management Response Security Incident Commander, you will play a critical role in safeguarding our company and customers' data against evolving threats. This is a challenging and rewarding position that...


  • Sydney, New South Wales, Australia Cisco Full time

    Protecting Our Customers and Our CompanyCisco Meraki is committed to providing the highest level of security for our customers and our company. As a key member of our Threat Management Response team, you will play a critical role in safeguarding our data and systems from evolving threats.Key Responsibilities:Serve on a rotation of security incident...


  • Sydney, New South Wales, Australia Cisco Full time

    Protecting Our Customers and DataCisco Meraki is committed to safeguarding our customers' data and protecting our company from evolving threats. As a key member of our Threat Management Response team, you will play a critical role in our incident response efforts. Your expertise will help us stay ahead of potential risks and ensure the security of our...


  • Sydney, New South Wales, Australia Cisco Full time

    Job SummaryWe are seeking a highly skilled Cybersecurity Incident Commander to join our Threat Management Response team at Cisco Meraki. This is a challenging role that requires strong incident response and leadership skills, as well as expertise in threat hunting and security monitoring.About the RoleThis position involves serving as a key member of our...


  • Sydney, New South Wales, Australia Cisco Full time

    Bulletproof Your Company's DataCisco Meraki is a leader in cloud-managed networking, and we're looking for a skilled Threat Response Lead to join our team. As an Incident Commander, you'll be responsible for safeguarding our company and customers' data against evolving threats. Your calm and methodical approach to investigating potential threats will be...


  • Sydney, Australia Cisco Full time

    At Cisco Meraki, we are known for simplifying technology through our products and services - and for the people behind them. As the fastest growing cloud-managed networking team in the world, our technology architecture is changing the face of networking and making cloud-managed IT a reality. Our employees' groundbreaking ideas impact everything we do. Here,...


  • Sydney, Australia Cisco Full time

    At Cisco Meraki, we know that technology can connect, empower, and drive us. Our mission is to simplify technology so our customers can focus on what's most significant to them: their students, patients, customers, and businesses. We’re making networking easier, faster, and sophisticated with technology that simply works.At Meraki, you will be a part of a...


  • Sydney, New South Wales, Australia Cisco Full time

    Defend Against Evolving ThreatsCisco Meraki is seeking a skilled Security Incident Commander to join our Threat Management Response team. As a key member of our security incident response team, you will play a critical role in safeguarding our company and customers' data against emerging threats. Your responsibilities will include serving as an incident...


  • Sydney, New South Wales, Australia Cisco Full time

    Cybersecurity Threat Manager Job DescriptionAt Cisco, we are dedicated to simplifying technology and providing innovative solutions. As a Cybersecurity Threat Manager, you will be part of our team that stands at the forefront of protecting our company and customers' data from evolving threats.This role requires expertise in incident response, threat...

  • SOC Analyst

    6 months ago


    Sydney, Australia Talent International Full time

    australia sydney permanent package + benefitsWe have a newly created opportunity for a Security Operations Centre Analyst to step up into an Incident Commander role as part of a growing Global Cyber Information Security team. Working for a leading, global insurance firm this person will have the proud responsibility of protecting all company divisions...


  • Sydney, New South Wales, Australia Amazon Full time

    About the RoleAmazon is seeking a highly skilled Security Engineer to join our innovative Information Security team and work within the Security Incident Response Team (SIRT) in Sydney.SIRT Security Engineers respond to security events, conduct analysis of threats, and provide security services to safeguard highly sensitive data.They work hands-on with...


  • Sydney, Australia Deloitte Full time

    Job Requisition ID:  36349  Learn from the best in the business Mentoring, growth and training – receive support and coaching to progress your career Preventive and supportive mental health initiatives About the Role The Manager – Incident Response and Cyber Defence will play a key operational role in supporting the Head of...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time

    About the RoleWe are seeking a highly skilled and experienced Incident Response Manager to join our Cyber Detection and Response team. As a key member of our team, you will be responsible for leading and managing major and critical incidents, as well as guiding and mentoring Incident Responders across your crew.Key ResponsibilitiesAnalyse data and logs to...


  • Sydney, Australia Commonwealth Bank Full time

    **_You are _**_a problem solver with a strong technical background in Incident Responds (IR) and or Security Operations Centre (SOC). _ - **_We are _**_one of the largest Cyber Security Practices in the Southern Hemisphere. _ - **_Together we can _**_contribute to protecting the Group, Customers and Community. _ **Do work that matters**: We're building...


  • Sydney, New South Wales, Australia Amazon Full time

    About the RoleWe are seeking a highly skilled Security Engineer to join our Incident Response Team at Amazon. As a Security Engineer, you will play a critical role in responding to security incidents, conducting analysis, and providing security services to safeguard our systems and data.Key ResponsibilitiesRespond to security incidents and coordinate a...


  • Sydney, Australia Amazon Full time

    DESCRIPTIONAmazon is seeking for a qualified Security Engineer to join our innovative, high energy Information Security team and work within the Security Incident Response Team (SIRT) in Sydney. SIRT Security Engineers respond to security events, conduct analysis of threats such as malware and intrusion attempts, and provide security services to safeguard...

  • Security Engineer

    2 weeks ago


    Sydney, New South Wales, Australia Amazon Full time

    Job DescriptionWe are seeking a highly skilled Security Engineer to join our team and contribute to our incident response efforts. As a key member of our team, you will work closely with our security engineers to identify, contain, and remediate security incidents that may impact our business.Key Responsibilities:Respond to security incidents and coordinate...


  • North Sydney, Australia Gallagher Full time

    About Us: Welcome to Gallagher - a global leader in insurance, risk management, and consulting services. With a growing team of more than 45,000 professionals worldwide, we empower businesses, communities, and individuals to thrive. At Gallagher, you can build a career whether it’s with our brokerage division, our benefits and HR consulting division, or...


  • Sydney, Australia Amazon Full time

    DESCRIPTIONAmazon is seeking for a qualified Security Engineer to join our innovative, high energy Information Security team and work within the Security Incident Response Team (SIRT) in Sydney. SIRT Security Engineers respond to security events, conduct analysis of threats such as malware and intrusion attempts, and provide security services to safeguard...