hero

Portfolio Company Careers

Discover career opportunities across PFG's network of portfolio companies

Threat Hunter

Trustwave

Trustwave

United States
Posted on Oct 4, 2024
About Trustwave Government Solutions

Trustwave Government Solutions is a leading provider of data security and compliance services to the U.S. Federal government. Our team of security experts, ethical hackers and researchers, enables our government partners to transform the way they manage their information security and compliance programs results to ensure each customer receives valuable outcomes at the best value. The agencies we work with benefit from our collaborative, innovative approach to meeting their unique needs. We listen carefully and respond nimbly. Our solutions combine industry best practices with customized technology to ensure quality and integrity.

The Threat Architect position is part of the SpiderLabs Threat Fusion team. This is a global team of threat hunting and threat intelligence experts committed to identifying malicious or risky behavior within our client networks and to tracking cybercrime/APT threat actor activity from across the globe. The threat architect is a key position to work closely with clients, conduct threat hunts, and interface with other teams within the company.

While technical expertise is a primary qualification, this position also requires excellent communication skills and business acumen. The selected candidate will frequently meet with top level executives from Fortune 500 global companies, to explain value proposition, and to deliver threat hunting findings, as well as creating formal technical reports.

Where active breaches are discovered, this team member will also be a primary member of the breach response team, working closely with forensic investigators, malware reverse engineers, and cyber threat intel analysts, to ensure malicious actors are rapidly removed and networks are properly remediated.

Specific Focus For This Role Will Include

  • Threat Hunting

Perform Proactive and Continual Threat Hunts for Trustwave clients. Conduct hunting, investigation, containment, reporting, and client engagement related to hunting activities utilizing Trustwave’s proprietary threat hunting platform. Contribute use-case development and detection strategies to further improve Trustwave’s proprietary threat hunting platform. Work closely with the engineering team to lead the integration of Trustwave SpiderLabs Threat Hunt platform with the GTDB (Global Threat Database), and the Trustwave Fusion portal. Incumbent must have a vision for “making intel actionable” for all Trustwave security analysts. Adding proper intelligence feeds / sources, scripting extraction of intel from various potential sources. Bring a vision to the team to improve our approach and utilization of threat intel and drive that vision to reality.

  • Threat Intelligence Partnerships

Interface with security researchers from Trustwave partners, such as Palo Alto Unit 42, Carbon Black, and Cybereason. Determine joint projects and publications that can be prepared surrounding new and emerging threats that our team discovers, be a point person discussing threats with potential partners.

  • Building Hunting Business

Support sales team to close major deals by clearly and concisely explaining the value and expected outcomes of a Trustwave threat hunt.

Requirements

  • Experience conducting incident response and computer forensic investigations.
  • Malware analysis experience is also a major advantage.
  • Experience conducting endpoint-based threat hunting.
  • In-depth knowledge of Windows system administration and good network hygiene.
  • Knowledge/experience with Windows/Linux/OSX security and investigations.
  • Knowledge of various threat actor groups and TTPs they are known to utilize. Experience developing endpoint-based rules to detect such TTPs.
  • Knowledge and experience implementing MITRE ATT&CK framework into hunting and detection mechanisms.
  • Skilled speaker and able to communicate comfortably with senior security executives.
  • Skilled writer, able to communicate both our service and emerging threat activity through written communication.

Education

  • A high school diploma or equivalent is required; a college or university degree is a plus.

This is a remote opportunity open to anyone legally authorized to work in the United States. Guided by our flexible workplace philosophy, Moments That Matter, people gather in the office when in-person interaction is most impactful; full-time remote employees may be asked to travel occasionally based on the needs of the team and the business.

Trustwave is an Equal Opportunity Employer of Minorities, Females, Protected Veterans, and Individuals with Disabilities.

Per Federal government contracting requirements, candidate must be a US citizen, as well as potentially pass and maintain a National Agency Check with Local Agency and Credit Checks (NACLC).

To All Agencies

Please, no phone calls or emails to any employee of Trustwave outside of the Talent Acquisition team. Trustwave’s policy is to only accept resumes from agencies via the Trustwave Agency Portal. Agencies must have a valid fee agreement in place and they must have been assigned the specific requisition to which they submit resumes, by the Talent Acquisition team. Any resume submitted outside of this process will be deemed the sole property of Trustwave and in the event a candidate is submitted outside of this policy is hired, no fee or payment of any kind will be paid.