A career in IBM Consulting is built on long-term client relationships and close collaboration worldwide. You’ll work with leading companies across industries, helping them shape their hybrid cloud and AI journeys. With support from our strategic partners, robust IBM technology, and Red Hat, you’ll have the tools to drive meaningful change and accelerate client impact. At IBM Consulting, curiosity fuels success. You’ll be encouraged to challenge the norm, explore new ideas, and create innovative solutions that deliver real results. Our culture of growth and empathy focuses on your long-term career development while valuing your unique skills and experiences.
As a Expert Cyber Defender you play a vital role in defending an organization's digital infrastructure by identifying, analyzing, and mitigating cyber threats. This position involves leveraging industry frameworks and a range of cybersecurity tools to monitor, prioritize, investigate, and respond to security incidents. In this role you will analyze data collected from various cybersecurity defense tools and act to mitigate risks, supporting threat hunting and incident remediation.
Your primary responsibilities will include:
• Conduct Event Investigations: Investigate security incidents using various cybersecurity tools, including SIEM, SOAR, EDR, and XDR platforms, to identify and analyze potential threats. Apply industry frameworks like MITRE ATT&CK and the Cyber Kill Chain to understand and counter adversary tactics effectively.
• Manage Incident Reports: Develop and manage incident reports, providing actionable recommendations and response strategies to strengthen clients' security posture.
• Analyze Network and Endpoint Events: Interpret security tools and logs from Windows, MAC, and Linux systems to identify potential security threats and vulnerabilities.
• Engage in Vulnerability Management: Participate in vulnerability management and cyber threat intelligence activities to identify and anticipate potential threats, staying ahead of emerging threats and evolving technologies.
• Provide Actionable Recommendations: Offer expert guidance and support to clients, providing actionable recommendations to enhance their security posture and mitigate potential threats.
Onsite - Fort Meade, MD 5 days a week
• Deep Expertise in Threat Analysis: Experience with industry frameworks like MITRE ATT&CK and the Cyber Kill Chain, with the ability to apply them to understand and counter adversary tactics effectively.
• Proficiency in Cybersecurity Tools: Experience with a range of cybersecurity tools, including SIEM, SOAR, EDR, and XDR platforms, to monitor, prioritize, investigate, and respond to security incidents.
• Advanced Understanding of Network and Endpoint Events: Ability to interpret security tools and logs from Windows, MAC, and Linux systems to identify potential security threats and vulnerabilities.
• Experience in Vulnerability Management: Participation in vulnerability management and cyber threat intelligence activities to identify and anticipate potential threats, staying ahead of emerging threats and evolving technologies.
• Certification in Cybersecurity: Possession of relevant certifications in cybersecurity, such as CISSP, demonstrating expertise in threat detection, response, and intelligence.
• Prior Government Cyber Operational Experience- Experience working in a high OPTEMO environment within the government with demonstrated expertise in threat detection, response and intelligence.
• Deep Understanding of Emerging Threats: Experience with identifying and analyzing emerging threats and technologies, staying ahead of the evolving threat landscape. Ability to adapt and apply this knowledge to improve threat detection and response strategies.
• Familiarity with Multiple Operating Systems: Exposure to various operating systems, including Windows, MAC, and Linux, with the ability to interpret security tools and logs to identify potential security threats and vulnerabilities.
• Knowledge of Cyber Threat Intelligence: Experience with cyber threat intelligence activities, including identifying and anticipating potential threats, and providing actionable recommendations to enhance security posture.