Details
Posted: 22-Jun-22
Location: Pittsburgh, Pennsylvania
Type: Full Time
Required Education: 4 Year Degree
Categories:
Information Technology
Preferred Education:
4 Year Degree
Additional Information:
Telecommuting is allowed.
Employer will assist with relocation costs.
The Cyber Security Incident Response Team (CSIRT) Member conducts essential cyber security incident handling activities for Covestro. This is accomplished by conducting event and incident analysis, and coordinating incident containment and remediation actions. In addition, the CISRT team member is instrumental in cyber threat and vulnerability analysis and response coordination. The jobholder will be responsible for interfacing with the Covestro Security Operations Center to receive alerts and determine appropriate action. Further, the CSIRT members shape detection criteria and consult on SOC operational guidelines. This role includes cybersecurity incident response across the Covestro enterprise. The jobholder has the authority to initiate the IT Security Incident Management Process, and to brief all levels of executive management on security topics and to execute emergency responses during cybersecurity breaches.
Major tasks and responsibilities
- Serve as a technical resource for cyber security incident handling
- Provide qualified guidance on and coordinate execution of identification, analysis, response and monitoring of cyber threat and vulnerabilities
- Monitor and consult on technical vulnerability remediation
Incident Management and Monitoring
- Manage Security incidents.
- Assist in developing concepts for efficient and effective security response activities.
- Be a trusted point of contact and expertise for incidents, and manage all the incident response activities including escalation to upper management..
- Provide qualified guidance on SOC alerting conditions and necessary data sources
Note: this role requires some on-call duty, with expected weekend responsibilities (once per 9 weeks)
Vulnerability Management
- Analyze and interpret results of vulnerability management activities using standard frameworks (CVSS)
- Research and investigate new and emerging vulnerabilities, to include 0Day events
- Identify and resolve false positive findings in assessment results
- Assess compensating controls and validate their effectiveness
- Partner with stakeholders to streamline, standardize and document vulnerability remediation procedures
- Monitor vulnerability remediation activities
- Integrate information from disparate sources and create tactical intelligence that is relevant to protecting the business.
Threat Management
- Research and investigate new and emerging cyber threats and vulnerabilities through participation in external security communities.
- Manage relationships with global stakeholders to identify business needs and design appropriate security controls.
- Analyze and interpret threat information using standard frameworks (Cyber Kill Chain, MITRE ATT&CK framework)
Other Areas of Effort
- Support the achievement of the Global IT Strategy
Additional Job Description