Listing Description
As a Senior Cybersecurity Analyst, team members work for NextEra’s Threat Defense Services (TDS) team. Team members are expected to provide daily support related to the collection and analysis of prioritized and commodity threats that may pose a risk to NextEra Energy. The Senior CTI position is primarily responsible for the daily scoping of threats to the Energy and Critical Infrastructure sector, including, but not limited to, performing tasks such as malware review and classification, daily reporting to the company’s senior leaders and executives, infrastructure enumeration, and creating rulesets to identify new activity.
Team members work closely with fellow threat analysts and researchers across NextEra’s Advanced Cyberdefense Center (ACC) to analyze and attribute malicious cyber activity to known or suspected cyber threat actors and malware variants. Team members participate in monthly and ad-hoc operations meetings of threat actor activity to inform broader stakeholders of observed trends. Team members are strongly encouraged to execute due diligence of all TDS operations. For example, team members should identify areas for process improvement and collaborate with other cross-functional teams to automate and streamline new or existing workflows.
TDS needs someone who is always ready to get involved in any challenge and work to build solutions.
Responsibilities
- Perform day-to-day functions of the Cyber Threat Intelligence team to monitor, track and analyze Threat Actor Groups and emerging threats in service of the defense of the enterprise.
- Understand the sophisticated threats that NextEra Energy may be exposed to and lead dissemination of that information, in a pragmatic way
- Maintain team resources to support business & operational needs
- Establish and sustain service level goals with key business partners while seeking opportunities to improve upon them
- Raise issues to leadership in a timely manner with appropriate information regarding risk, action times, and root cause analysis
- Develops program metrics and reporting frameworks, compiles, and analyzes data for accurately timely reporting of activity
- Drive prioritization and focus across various cross-functional service areas to provide useful intelligence
- Establish and maintain relationships with industry partners to continuously improve NextEra’s defensive posture
- Define strengths you'll need from intelligence and hunt practitioners to ensure continuous development of internal resources
- Build technical briefs, reports, and single-source of record
Requirements
- At least 5 years’ experience developing and/or operating on a threat intelligence, incident response, or similar team (4-year degree or equivalent experience)
- Highly effective and proven in engaged with senior leaders and executives, successfully translating technical and ambiguous matters to business applicable
- Ability to build positive relationships internally and externally, in-person and virtually
- Understanding of the analytical mapping methods (MITRE ATT&CK Framework and/or the Cyber Kill Chain, Diamond, ACH)
- Demonstrated ability to identify, coordinate and respond to security incidents using commercial and/or open-source technologies.
- Experience with Incident Response methodology in investigations, and the groups behind targeted attacks and tactics, techniques, and procedures (TTPs)
- Strong ability to summarize events/incidents effectively to different constituencies such as legal counsel, executive management, and technical staff, both in written and verbal forms.
- Experience using various digital investigation tools (e.g. VirusTotal, RiskiQ, Team Cymru, TITAN, RecordedFuture)
- Refined and tested problem-solving skills and experience
- Ability to persuade and/or negotiate desired outcomes
- Strong technical understanding of IT fundamentals and core cybersecurity related principals (e.g., networking, OSI model, operating system internals, malware, attack chains, etc.)
- Ability to leverage NetFlow and other network-related telemetry to identify and track potential threats.
- Demonstrated analytical and critical thinking skills, ability to analyze a wide source of disparate data and extract meaningful relationships and conclusions based on the data.
Listing Details
- Citizenship: Not Provided
- Incentives: Bonus
- Education: Bachelors Degree
- Travel: No Travel
- Telework: Not Provided