Reinsurance Group of America, Incorporated→
Threat Engineer at Reinsurance… · United…
Entry LevelHybridFull-timeUnited States, Creve Coeur, MO, CityPlace$78k–$111k/yr
Skills
incident responsesecurity engineeringoffensive securitythreat emulationpenetration testingsecurity operationstelemetry gap identificationpurple team collaborationcybersecurity metricsnetwork analysishost analysiscloud platform analysisidentity platform analysiswindows internalsmac internalslinux internalscloud computing - awsmicrosoft 365 ecosystemmicrosoft domain environmentsiam/aaa technologiesactive directoryoktaopenidsamloauthjwtphysical networking technologiesvirtual networking technologiessiem - splunkedr - crowdstrikeedr - microsoft defenderemail securitydnswork within a teamanalytical skillshandle multiple taskspriorities
Job Description
Summary: Reinsurance Group of America, Incorporated is a Fortune 200 Company focused on life- and health-related solutions. The Threat Engineer role is responsible for supporting and maturing standards and procedures to manage cyber risk through proactive threat hunting, detection engineering, and operational monitoring.
Responsibilities:
- If required, participate in a 24/7 on-call rotation, alert triage, investigation
- Support the following functions: threat detection, offensive security
- Support the development of orchestrations and automations that reduce manual tasks
- Perform junior level intrusion and/or defensive analysis
- Support security related audit/compliance/risk-reduction efforts at a junior level
- Support offensive and/or defensive security tool development, procurement, and management
- Determine and deliver logging requirements to better detect and respond to security threats
- Support the delivery of projects that drive down the overall risk and/or impact of a cybersecurity incident
- Performs other duties as assigned
Required Qualifications:
- Associate's Degree (AA) or equivalent experience
- 1+ Years of experience in one or more areas; incident response, security engineering, offensive security, threat emulation, penetration testing, or security operations
- Experience identifying and addressing telemetry gaps in security monitoring
- Experience contributing to purple team, including supporting risk hunting, telemetry validation, detection efficacy
- Experience developing and supporting cybersecurity metrics and reporting to support security operations
- Ability to support complex incidents and evolve strategies based on new information
- Junior level analytical skills with the ability to investigate network, host, cloud and identity platforms
- Ability to work independently within a globally distributed environment
- Strong written and verbal communications skills Assist in creating automation\workflows to scale security operations
- Ability to quickly adapt to new methods, work under tight deadlines and stressful conditions
- Junior level investigative, analytical and problem solving skills required
- Junior level ability to set goals and handle multiple tasks and projects simultaneously
- Ability to appropriately balance priorities, deadlines, and deliverables required
- Ability to work well within a team environment and participate in department/team projects
- Technical Requirements: Windows, Mac, and Linux internals, Cloud computing (AWS), M365 suite and ecosystem, Microsoft domain environments, IAM/AAA technologies and architectures (Active Directory, Okta, OpenID, SAML, Oauth, JWT), Physical and Virtual Networking technologies and architecture, SIEM (Splunk), EDR (CrowdStrike, Microsoft Defender), Email security, DNS
Preferred Qualifications:
- Bachelor's Degree in Arts/Sciences (BA/BS) or professional industry certification
- 2+ Years of relevant experience
- Technical Requirements: Cloud Computing (GCP, Azure), Forensic tools (FTK, Encase, X-Ways, SIFT), Scripting (Powershell/Python/Javascript/Typescript), Service Now
Required Skills: Incident response, Security engineering, Offensive security, Threat emulation, Penetration testing, Security operations, Telemetry gap identification, Purple team collaboration, Cybersecurity metrics, Network analysis, Host analysis, Cloud platform analysis, Identity platform analysis, Windows internals, Mac internals, Linux internals, Cloud computing - AWS, Microsoft 365 ecosystem, Microsoft domain environments, IAM/AAA technologies, Active Directory, Okta, OpenID, SAML, OAuth, JWT, Physical networking technologies, Virtual networking technologies, SIEM - Splunk, EDR - CrowdStrike, EDR - Microsoft Defender, Email security, DNS, work within a team, Analytical skills, handle multiple tasks, priorities
Benefits: Annual bonus plan, Long-term equity incentive plan, Full range of health, retirement, and other employee benefits
Benefits
Annual bonus plan
Long-term equity incentive plan
Full range of health, retirement, and other employee benefits