Cyber Security Detection Solution Engineer
Cyber Security Detection Solution Engineer
Division
Euroclear is a global critical financial infrastructure company. Security is at the core of the company’s services, firmly embedded in their management systems and processes.
The Chief Information Security Office (CISO) division’s main responsibility is to reduce the risk of Euroclear cyber threat surface by monitoring for malicious intent targeted at Euroclear’s services, it’s supporting assets and people. This includes security monitoring, pentesting, security architecture, cyber threat intelligence, brand and digital footprint monitoring, cyber analytics, risk assessments, IAM, security incident handling and forensic analysis.
The Cyber Defence Centre (CDC) department, being part of CISO, focusses on detection and response capabilities within the cyber security domain. It acts as subject matter expert across all divisions in the company as well as interacts with external stake holders, including customers, oversight bodies, threat intelligence providers and third parties.
The SOC, CIRT and TI teams are part of the CDC, together with the CoE team which drives the architectural and technological evolution for the CDC.
Role
The Centre of Excellence Expert architectures and develops solutions for CDC supporting its cyber security detection and response capabilities. It advices, researches, reviews, assesses and supervises the implementation of the technical and procedural needs in new initiatives/projects and existing implementations within the CDC. This is performed with strong focus on ROI, (operational) security requirements and security best practices.
You are expected to:
- Develop technically funded detection and response strategies
- Drive the detection and response capabilities of the CDC, providing best in class solutions to make CIRT, TI and SOC teams efficient
- Support a solid CDC architecture and create detailed designs, giving the CDC teams the appropriate detection and response capabilities
- Design by focussing on existing tooling and its capabilities. Identify and develop integrations, seek for enrichments and pin-point available data sources
- Liaise with various teams and stakeholders for requirements and check-off proposed solutions
- Manage the change requests towards the teams that are responsible for the equipment/tools on which the detection capability depends on
- Be responsible for security detection and response capabilities end-to-end (look further than just the detection rule on e.g SIEM)
- Design playbooks on a SOAR platform for optimal detection and response
- Know and analyse the strengths and weaknesses of the detection tool/technology that the CDC relies on. Even for tools managed outside the CDC. Allowing the CoE to highlight potential workarounds or coverage by other tools/technology.
- Facilitate and support any improvements that benefit the CDC, in the context of security operations across the company. Work in a continuous improvement mode on technology deployments, configurations and usage.
- Support teams within and outside the CDC, with technical expertise (based on experience and best-practice research) in the context of detection and response configurations/features/functions
- This can be ad-hoc or as part of a project by means of e.g. a document reviewPresent the CoE security projects/initiatives/solutions to various audiences. This as a design walk-thru, a product training or transfer of information on a specific subject supporting detection and response
- Known the market and interact with the technology vendors that CDC relies on. This to anticipate changes, identify potential beneficial enhancements and ensure product support
- Perform limited engineering activities on some of the security platforms
Qualifications, Skills and experience
A combination of several of the below should be covered:
- A security focused ICT engineer, with a broad view and good understanding the working principles of many corporate ICT tools
- 10 years of experience in security operations engineering and design; A lead engineer in Security Operations (with admin role) on multiple security products. A security solution architect that has dealt with designing and introducing new corporate security detection/prevention tools
- Mastering security technologies as well as its high-level concepts
- In-depth understanding of relevant preventive and detective security technologies (knowing the pros and cons of various techniques used in the area of SIEM / SOAR / firewall / proxies / VPN / EDR / NDR / NBA / CASB / ZTN / nIDS / IPS / End-point logging /etc, cryptography and PKI)
- Security technology and security market aware
- Familiar with Cloud environments and concepts
- Experienced with corporate network infrastructure architectures
- Good understanding of orchestration, management and operational monitoring technologies, while familiarized with some
- Some pen-test experience (purple teaming experience, or former red team member)
- Python coding and/or PowerShell skills are a plus
- Good understanding of security standards and the various (security) frameworks
- Mastering best practice security concepts (coming from e.g. CIS, MS, Cisco, NIST, Mitre, etc)
- Well-developed troubleshooting skill-set
- Experience in building relationships and partnering effectively cross functionally and at all levels across a global organization
- Demonstrates history of driving change and managing for results
- Bachelor’s degree or equivalent work experience
Interpersonal Skills
- An enabler, with a heighted sense of accountability
- Strong analytical skills and attention to detail
- Customer-oriented, resourceful and enthusiastic
- Excellent written and verbal communication skills
- Influence – have the ability to inspire, be persuasive and be a leader. Act with a real sense of urgency to move others to action
- Curious and courageous – Demonstrate an appetite to learn new things. Takes initiative and is not afraid to go against popular opinion
- Adaptable – remains calm and optimistic under pressure and adapts well to unexpected situations. Comfortable dealing with ambiguity and uncertainty
Euroclear recruits people from all walks of life. Our 3,500 employees represent 89 nationalities, of which over 50% are women. We are deeply convinced that diversity of talents, backgrounds and opinions is a key to success, by fostering engagement, energy and innovation. We are committed to promoting diversity within the organization, as well as an inclusive environment where everyone can be themselves, feels valued and respected, regardless of their background.