This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Citi's Cloud Incident Response (Cloud IR) team seeks a Cloud Incident Responder to own the assigned security incidents that occur within Citi's public cloud environments. You will work closely with stakeholders to ensure effective security incident response with an aim to safeguard the integrity of services and data within Citi's public cloud platforms. Your role is critical in ensuring a proactive and coordinated approach in responding to cloud security incidents and managing security risks in a timely and effective manner.
Job Responsibility:
Lead and/or support in-depth triage and investigations of assigned cyber incidents in cloud
Perform incident response functions including cloud-focused investigations by analyzing logs
Execution of automation to gather forensic artifacts for in-depth analysis
Execution of cloud-native automation to run resource containment actions
Conduct host-based analytical functions to uncover Indicators of Compromise
Documentation of investigation analysis
Develop, document and maintain operationally effective playbooks to deal with cloud-based incidents
Take ownership for and drive the development of new automation capabilities
Work with application and infrastructure stakeholders to identify key components and information sources
Collaborate with global multidisciplinary groups for triaging and investigating large-scale security incidents
Build and nurture key stakeholder relationships
Actively participate in Threat modeling of new services/capabilities, readiness exercises
Requirements:
Strong technical expertise in relevant Cloud security tools and technologies (e.g. EDR, SIEM, Container security, SSPM, CNAPP, etc.)
Solid team player with the ability to work in multi-disciplinary team of teams with DevSecOps practitioners
Exceptional communication and presentation skills to convey complex technical matters to senior security stakeholders and leadership
Strong understanding of security incident response processes, excellent technical documentation skills and proven analytical skills
Deep knowledge of public cloud services used in modern cloud-native containerized applications
Advanced proficiency with cloud security focused services such as Guard Duty, SCC, IAM, etc.
Hands-on experience with CI/CD methodologies and tools that support modern deployment practices into public cloud
Proficient with public cloud services focused on automation such as SSM, Lambda, Cloud Functions, etc.
Experience with various log aggregation/data analytics tools, such as Splunk, Sentinel, etc.
Familiarity with security constructs of SaaS and PaaS offerings such as Snowflake, MongoDB
Windows Operating Systems / UNIX specifically in command line use and basic file system knowledge
Welcome to CrawlJobs.com – Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.
We use cookies to enhance your experience, analyze traffic, and serve personalized content. By clicking “Accept”, you agree to the use of cookies.