Skip Navigation

McAfee Security Senior Emergency Incident Response Consultant - Remote Based

Primary Location Chandler, Arizona Additional Locations US, Maryland, Rockville; US, Pennsylvania, Pittsburgh; US, Texas, Houston; US, New York, New York City; US, Michigan, Detroit; US, Massachusetts, Boston; US, Florida, Multiple Cities; US, Massachusetts, Multiple Cities; US, New Jersey, Multiple Cities; US, Washington, Multiple Cities; US, California, Los Angeles; US, North Carolina, Raleigh; US, Tennessee, Nashville; US, Texas, Dallas; US, Washington, Bellevue; US, Washington, Seattle; US, Oregon, Portland; US, California, Irvine; US, Nevada, Las Vegas; US, Utah, Salt Lake City; US, Arizona, Phoenix; US, Oklahoma, Oklahoma City; US, Georgia, Atlanta; US, Virginia, Fairfax; US, Kansas, Overland Park; US, Connecticut, Stamford; US, Texas, Austin; US, Colorado, Denver; US, Missouri, St Louis; US, South Carolina, Columbia; US, Pennsylvania, Philadelphia; US, Indiana, Indianapolis; US, California, San Francisco; US, California, San Diego; US, Ohio, Columbus; US, Ohio, Cleveland; US, Florida, Tampa; US, New Mexico, Albuquerque; US, Florida, Orlando; US, Florida, Miami; US, Minnesota, Minneapolis; US, Florida, Jacksonville; US, Illinois, Chicago; US, Virginia, Richmond; US, Maryland, Baltimore Date posted 12/07/2018
Apply Now Job ID: JR0013632

McAfee Security Foundstone Consulting Practice is looking for a technical, passionate pragmatic information security professional with vast IT and Cybersecurity experience to be part of our Emergency Incident Response team.  You must be a strong leader with excellent people and management skills with the ability to take ownership of assignments and execute with speed and accuracy.  You also need to able to work beyond normal business hours and willing to travel locally and/or internationally, if needed.

Location: Remote Based (Anywhere USA)

Travel Requirements: 65% National Travel

About this role:

  • Lead Emergency Incident Response (EIR) engagements and guide clients through a variety of incidents (i.e., breaches, malware/virus outbreaks, security incidents, and forensics investigations).  Provide guidance on tactical and strategic response and remediation recommendations.
  • Excellent verbal and written communication skills
  • Ability to handle stressful situations and think on your feet
  • Ability to learn and apply Containment, Mitigation, and Remediation concepts based on TTP’s.
  • Perform live response, malware analysis, volatile data collection and analysis on hosts and/or network data.
  • Correlate and analyze Windows, Linux to identify Indicators of Compromise (IOCs).
  • Strong in Network Forensics (TCP/IP networking) /Traffic analysis, Digital Forensics
  • Ability to examine firewall, web, database, and other log sources to identify evidence of malicious activity
  • Leveraging various forensics tools including Encase, FTK, X-Ways, SIFT/ open source, Splunk, and other tools to determine source of compromises and/or malicious activity that occurred in client environments.
  • Display an understanding of security best practices, security gap assessments, penetration testing / Cyber Kill Chain, NIST.
  • Perform vulnerability assessments to identify security issues in client environments.
  • Strong working knowledge of security-relevant data, including network protocols, ports and common services, such as TCP/IP network protocols and application layer protocols (e.g. HTTP/S, DNS, FTP, SMTP, Active Directory etc.)
  • Experience or familiarity programming in at least one of the following: Python, Powershell, Bash, Shell Script, Batch, VBscript (Python experience preferable)
  • Deliver professional consulting services across Professional Services portfolio and ability to manage multiple deliverables simultaneously.
  • Able to learn and collaborate from our close-knit group as well as contributing your thoughts, tools, industry news or lessons learned.

Additional Experience Desired:

  • Experienced in managing large and complex client environments and meet their business requirements by evaluating their security controls, architecture and operations against industry best practices
  • Assess and develop risk management/mitigation controls and strategies via technical testing and conducting risk assessments and develop actionable remediation guidance.
  • Have performed IR/SOC Gap Assessments and Development
  • Basic understanding of the McAfee product suites to be able to intelligently discuss with clients how the Foundstone Services can support and be supported by McAfee technology and solutions at a highly level.
  • Understanding in development of engagement scoping and proposals and making customer presentations

Typical Minimums:

  • Bachelor/Master’s degree from an accredited college in a related discipline, or equivalent experience/combined education, min 9 years of IR/forensic, security experience, and as above.

  • One or more of the following technical certifications or equivalents: GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Reverse Engineering Malware (GREM), EnCE or similar 

#LI-EB1

Shift:

Shift 1 (United States of America)

Primary Location:

Virtual US and Canada

Posting Statement:

McAfee prohibits discrimination based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status.

Apply Now

Sign Up for McAfee Job Alerts

Form

Get the latest job openings delivered to your inbox.

Interested InSelect a job category from the list of options. Select a location from the list of options. Finally, click “Add” to create your job alert.

  • Sales, United StatesRemove
  • Sales, New Jersey, United StatesRemove
  • Sales, Massachusetts, United StatesRemove
  • Sales, Florida, United StatesRemove
  • Sales, Baltimore, Maryland, United StatesRemove
  • Sales, Chicago, Illinois, United StatesRemove
  • Sales, Richmond, Virginia, United StatesRemove
  • Sales, Minneapolis, Minnesota, United StatesRemove
  • Sales, Jacksonville, Florida, United StatesRemove
  • Sales, Miami, Florida, United StatesRemove
  • Sales, Albuquerque, New Mexico, United StatesRemove
  • Sales, Orlando, Florida, United StatesRemove
  • Sales, Tampa, Florida, United StatesRemove
  • Sales, Cleveland, Ohio, United StatesRemove
  • Sales, San Diego, California, United StatesRemove
  • Sales, Columbus, Ohio, United StatesRemove
  • Sales, San Francisco, California, United StatesRemove
  • Sales, Philadelphia, Pennsylvania, United StatesRemove
  • Sales, Indianapolis, Indiana, United StatesRemove
  • Sales, Columbia, South Carolina, United StatesRemove
  • Sales, Austin, Texas, United StatesRemove
  • Sales, Denver, Colorado, United StatesRemove
  • Sales, St Louis, Missouri, United StatesRemove
  • Sales, Overland Park, Kansas, United StatesRemove
  • Sales, Stamford, Connecticut, United StatesRemove
  • Sales, Atlanta, Georgia, United StatesRemove
  • Sales, Fairfax, Virginia, United StatesRemove
  • Sales, Oklahoma City, Oklahoma, United StatesRemove
  • Sales, Phoenix, Arizona, United StatesRemove
  • Sales, Salt Lake City, Utah, United StatesRemove
  • Sales, Las Vegas, Nevada, United StatesRemove
  • Sales, Irvine, California, United StatesRemove
  • Sales, Portland, Oregon, United StatesRemove
  • Sales, Seattle, Washington, United StatesRemove
  • Sales, Bellevue, Washington, United StatesRemove
  • Sales, Dallas, Texas, United StatesRemove
  • Sales, Nashville, Tennessee, United StatesRemove
  • Sales, Raleigh, North Carolina, United StatesRemove
  • Sales, Los Angeles, California, United StatesRemove
  • Sales, Boston, Massachusetts, United StatesRemove
  • Sales, Detroit, Michigan, United StatesRemove
  • Sales, New York, New York, United StatesRemove
  • Sales, Houston, Texas, United StatesRemove
  • Sales, Pittsburgh, Pennsylvania, United StatesRemove
  • Sales, Rockville, Maryland, United StatesRemove
  • Sales, Chandler, Arizona, United StatesRemove

What's Happening
at
McAfee?

Check out #LifeAtMcAfee

Explore our Blog