Mandiant logo
Enterprise Security Architect (Remote Germany) - Mandiant Berlin, de Bookmark Share Print 275 0 1

Listing Description


Job Description

Mandiant Security Transformation Services helps organizations build an effective security operations program that minimizes organizational risk and reduces the impact of security breaches. With a targeted focus in cloud architecture, our consultants work from initial assessment and configuration review of security controls, to detailed technical recommendations that can be practically implemented to harden environments (both cloud and on-premises), enhance visibility and detection, and improve processes to reduce the risk of compromise.

Mandiant seeks Enterprise Architect, Incident Response Remediation Consultants with strong technical skills and an eagerness to lead projects and work with our clients. Candidates will need to apply their Active Directory, network architecture, security hardening, and logging enforcement skills to assist clients in improving their security posture as well as implementing containment and remediation actions during incident response engagements. Our consultants must be comfortable working in teams to tackle challenging projects, communicating with clients, providing hands-on assistance with containment and remediation activities, and creating and presenting high-quality deliverables. 

What You Will Do

  • Design and assist clients with network architecture enhancements and configuration modifications to defend against identified threats and attacker techniques
  • Conduct Incident Response containment and remediation engagements for clients 
  • Create and document detailed remediation guides and tracking documents, for clients to leverage to prepare for, and execute a coordinated remediation event 
  • Recommend and document specific countermeasures and mitigating controls 
  • Articulate Mandiant’s capabilities in marketing discussions, proposal efforts, and capability briefings 
  • Develop comprehensive and accurate reports and presentations for both technical and executive audiences 
  • Effectively communicate remediation strategies and workstreams to client stakeholders including technical staff, executive leadership, and legal counsel 

 


Qualifications

 The successful candidate will have 5+ years’ of information security experience and additionally be able to demonstrate a strong proficiency in three or more of the following areas:

  • Prior experience as a lead system administrator or network engineer in an enterprise environment 
  • Thorough understanding of enterprise security controls in Active Directory / Windows environments 
  • Active Directory Trusts and Architectures 
  • Privileged Access Management best practices 
  • Windows and Unix endpoint hardening and security control enforcement 
  • Expertise in enforcing application listing and host-based restrictions 
  • Implementation and enforcement of technologies such as Credential Guard and Device Guard 
  • Understanding of enterprise networking and knowledge of network segmentation strategies 
  • Implementation and management for both network and host-based firewall configurations 
  • Implementing logging configurations for network devices and Windows and Unix endpoints 
  • PowerShell scripting

Additional Qualifications: 

  • Must be eligible work in EU member states, or Swiss or UK  without sponsorship
  • Prior training and public speaking engagement experience 
  • Ability to lead a team of highly technical security professionals 
  • Willingness to travel up to 50%


    Listing Details

    • Citizenship: Not Provided
    • Incentives: Not Provided

     

    • Education: Not Provided
    • Travel: Not Provided
    • Telework: Full Telecommute



    About Us

    NinjaJobs is a community-run job platform developed by information security professionals. Our unique approach of focusing strictly on cybersecurity positions allows us to personalize the user experience.

    Our Contacts

    1765 Greensboro Station Pl.
    Suite 900
    Tysons Corner Va 22102

    (703) 594-7765