Senior Cyber Threat Hunter

Posted:
8/28/2024, 2:36:14 AM

Location(s):
Escazú, San Jose Province, Costa Rica ⋅ San Jose Province, Costa Rica

Experience Level(s):
Senior

Field(s):
IT & Security

ROLE SUMMARY

The Pfizer Global Information Security (GIS) organization safeguards critical information assets by employing world-class talent to proactively defend company interests. Fostering a culture of colleague empowerment, we support Pfizer’s mission of delivering breakthroughs that change patients’ lives. GIS teams continuously work to detect threats faster, respond decisively, and make Pfizer harder to hack. GIS leadership cultivates a positive, fun, welcoming, collaborative, flexible, and supportive work environment that lifts people up and helps them realize their full potential. We achieve this through our company values of Courage, Excellence, Equity, and Joy, and a strong culture of enablement. This is a great place to work where colleagues are provided with opportunities to grow, receive acknowledgement of their achievements, and are rewarded for hard work.

The Cyber Threat Hunting (CTH) team is accountable for identifying unrealized threats that may have evaded security controls and actively improving our security posture. We use vast collections of data, a comprehensive toolset, and creative investigative techniques to identify & analyse potential threats. In collaboration with other GIS teams, we also contribute to the development and implementation new security controls and detections.

The incumbent will be a senior member of the Pfizer GIS Cyber Threat Hunting team, an individual contributor (technical) reporting to the Manager of Cyber Threat Hunting in the GIS Cyber Threat Analysis & Response organization.

The role engages with cross-functional colleagues and external business partners. You will leverage an advanced level of knowledge & experience to perform threat hunts using a dynamic collection of tools, data, and processes. Other aspects include assisting the development of new threat hunting exercises, managing the team backlog, and contributing to new detections development. You also contribute to – and may lead – team projects and other work related to the CTH mission. This unique and exciting opportunity is ideal for individuals who are motivated, curious, creative, team-oriented, organized, intelligent, and embrace a culture of life-long learning. It offers a chance to take ones work to the next level, explore new technologies, apply experience, grow one’s skillset, and regularly exercise critical thinking skills. You’ll enjoy the freedom to explore, ample amounts of support, best-of-breed tools, and opportunities for great team collaboration.

ROLE RESPONSIBILITIES

  • Maintain awareness of threats targeting pharmaceutical companies and related industries, such as manufacturing and healthcare.
  • Contribute to the identification of new, relevant threat hunting opportunities.
  • Apply advanced technical knowledge and experience to design & execute cyber threat hunting exercises in an efficient, accurate, and complete manner.
  • Contribute to the management of the team backlog.
  • Perform all work in accordance with documented policies & procedures.
  • Maintain current, accurate, and complete documentation for all phases of threat hunting exercises.
  • Independently perform accurate & complete analysis of cyber threat hunt findings using defensible & creative investigative techniques.
  • Leverage cyber threat hunt outcomes to develop detections & other security controls that proactively mitigate risk.
  • Conceptualize and develop solutions for moderately complex challenges encountered by the team.
  • Contribute to the identification, design, and/or development of new automation capabilities and process improvements that help mature the CTH program.
  • Develop the knowledge and experience of the Pfizer environment to serve as a subject matter expert on the available logs and analysis techniques.
  • Provide training & support to junior members of the team.
  • Contribute to the ongoing development & improvement of the CTH program.
  • Exercise sound judgement and decision-making by applying expert-level knowledge and experience.
  • Perform all work in alignment with the Agile operating model established by the organization and adopted by the team.
  • Maintain awareness of team procedures, emerging threats, organization announcements, technical solution operating practices, and team communication by regularly reviewing information from various forms of documentation, threat intelligence, & business communication.

BASIC QUALIFICATIONS

  • BS in Information Security, Computer Sciences, Information Systems, Engineering, Sciences, or related field
  • Level of experience consistent with several years of work in a Threat Hunting, Incident Response, or Security Operations functions using a variety of security tools for monitoring a large-scale enterprise environment
  • Experience querying, correlating, & analyzing large-scale datasets using tools such as Splunk, SQL, Python, and/or Microsoft Excel
  • Experience analyzing data from network solutions (firewall, proxy, IPS/IDS, network security appliances, VPN, etc.), web applications, business information systems, endpoint security solutions, and other related technologies
  • Extensive experience performing analysis of activity on Microsoft Windows endpoints, including process, network, registry, and file system events, along with related forms of activity
  • Strong understanding of TCP/IP, common network protocols, OSI model, traffic flow analysis, and common network services (DHCP, DNS, web services, email, database, etc.)
  • Ability to analyze and disposition various forms of endpoint, network, application, and / or service-related collections of activity in a largely independent manner
  • Ability to clearly communicate potentially complex information in a concise, accurate, and complete manner in both written and verbal form
  • Commitment to training, self-paced study, and maintaining proficiency in the cybersecurity domain

PREFERRED QUALIFICATIONS

  • Knowledge of information security principles and standards

EEO (Equal Employment Opportunity) & Employment Eligibility 

Pfizer is committed to equal opportunity in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, or disability.

Information & Business Tech