|Published||September 9, 2023|
The typical starting salary range for this role is determined by a number of factors including skills, experience, education, certifications and location. The full salary range for this role reflects the competitive labor market value for all employees in these positions across the national market and provides an opportunity to progress as employees grow and develop within the role. Some roles at Liberty Mutual have a corresponding compensation plan which may include commission and/or bonus earnings at rates that vary based on multiple factors set forth in the compensation plan for the role.
Advanced Cyber Threat Team – Threat Hunter - Threat Intelligence
We deliver our customers peace of mind every day by helping them protect what they value most. Our passion for placing the customer at the center of everything we do is driving a transformational shift at Liberty Mutual. Operating as a tech startup within a Fortune 100 company, we are leading a digital disruption that will redefine how people experience insurance.
The Senior Cybersecurity Engineer is an experienced role within the Liberty Mutual Advanced Cyber Threat Team reporting to the Cyber Security Operations Center. This technical role is responsible for proactively and iteratively hunting for cyber threats. The successful candidate will work at the intersection of Cyber Threat Hunting, Cyber Threat Intelligence, Malware Analysis & Reverse Engineering, and Digital Forensics & Incident Response. Responsibilities include mentoring junior engineers and maturing the team’s capabilities and processes.
About the job:
- Identify and track threat actor Tactics, Techniques, and Procedures (TTPs).
- Create Cyber Threat Hunt hypotheses based on TTPs.
- Operate and mature an iterative agile Cyber Threat Hunting cycle.
- Leverage internal and external data sets and threat intelligence feeds to drive cyber threat hunting initiatives.
- Conduct Digital Forensics investigations and Malware Analysis to identify malicious activity and derive Indicators of Compromise (IOCs) and associated detection rules.
- Investigate and report on cyber threat hunt findings, including recommendations to improve security posture across detective and preventive controls.
- Conduct Incident Response activities as required based on hunt findings.
- Contribute to engineering initiatives to operationalize Cyber Threat Intelligence feeds and API integrations.
- Validate security control coverage against identified IOCs based on emerging cyber threat intelligence.
- Collaborate with the Offensive Security team to analyze and evaluate the effectiveness of existing security controls against identified TTPs.
- Contribute to the creation and dissemination of finished cyber threat intelligence products and briefings.
- Participate in and contribute to select Cyber Threat Intelligence sharing communities.
- Coach and mentor junior team members to enhance and mature capabilities and team processes.
- Contribute to reporting on the team’s operational metrics and KPIs.
- Serve as a Lead Responder on a global cybersecurity incident response team with a periodic on-call requirement.
- Bachelors degree in Computer Science, Computer Engineering, Information Security, or other related discipline.
- Minimum 5+ years of recent experience working as a cybersecurity professional.
- Subject matter expertise in at least one of the following areas: Cyber Threat Hunting, Malware Analysis & Reverse Engineering, Cyber Threat Intelligence, Digital Forensics & Incident Response.
- Active Cybersecurity certifications are desirable (but not required) such as GCIH, GREM, GCFA, GCTI, OSCP etc. (see list below).
- Previous experience working in a Cyber Security Operations Center or similar function is desirable.
- Knowledge of relevant frameworks, standards, and best practices such as NIST CSF, PCI-DSS, CIS CSCs, MITRE ATT&CK, Cyber Kill Chain etc.
- Experience with using a Security Information Event Management (SIEM) platform.
- Experience with using a scripting language such as Python or PowerShell for task automation or tool creation is desirable.
- Demonstrable knowledge of several of the following areas: cybersecurity concepts, network protocols, firewalls, IDS/IPS systems, email security, endpoint security, network security, Windows/Linux/macOS systems, cyber threat hunting, malware analysis tools and techniques, cyber threat intelligence, common threat actor TTPs, application security concepts, cloud security fundamentals, Incident Response methodologies.
- Excellent oral and written communication skills.
- SANS/GIAC GCIH, GREM, GCFA, GCTI
- CompTIA Security+, CySA+
- Microsoft Azure or AWS Certifications
- Security Solutions/Tools Certifications
At Liberty Mutual, our purpose is to help people embrace today and confidently pursue tomorrow. Thats why we provide an environment focused on openness, inclusion, trust and respect. Here, youll discover our expansive range of roles, and a workplace where we aim to help turn your passion into a rewarding profession.
Liberty Mutual has proudly been recognized as a "Great Place to Work" by Great Place to Work US for the past several years. We were also selected as one of the "100 Best Places to Work in IT" on IDGs Insider Pro and Computerworlds 2020 list. For many years running, we have been named by Forbes as one of Americas Best Employers for Women and one of Americas Best Employers for New Graduates as well as one of Americas Best Employers for Diversity. To learn more about our commitment to diversity and inclusion please visit: https://jobs.libertymutualgroup.com/diversity-inclusion
We value your hard work, integrity and commitment to make things better, and we put people first by offering you benefits that support your life and well-being. To learn more about our benefit offerings please visit: https://LMI.co/Benefits
Liberty Mutual is an equal opportunity employer. We will not tolerate discrimination on the basis of race, color, national origin, sex, sexual orientation, gender identity, religion, age, disability, veterans status, pregnancy, genetic information or on any basis prohibited by federal, state or local law.