Threat Operations Security Engineer I
Why Box Needs You?
Threat Operations is a team within Box’s Global Security Office consisting of Threat Hunting, Threat Detection, Threat Intelligence, and Malware Analysis. The team is an integral part of Box’s corporate and production security program, collaborating with Incident Response and the Red Team regularly.
The Threat Operations Security Engineer will support team by setting up and maintaining cloud assets for the development and extraction of IOCs and ATT&CK techniques from malicious binaries.
The Threat Operations Security Engineer will also work closely with Malware Analysis, Threat Intelligence and Security Engineering to implement automation enhancements on ThreatOps workflows. This role will also work closely with the Shield product team and Malware Analysis to enhance the Box Shield Product.
What You'll Do?
-
Setup, configuration and maintenance of cloud assets (AWS)
-
Implementation of identity and access management hardening to secure ThreatOps systems
-
Implementation of automation to enhance ThreatOps workflows
-
Participate in technical working sessions with Malware Analysis, Threat Intel, Detection Engineering
-
Develop new tools, templates, and methods as needed to support ThreatOps
-
Document processes, procedures, and system setups
-
Shifted hours occasionally needed for collaboration with the Global Security Team
Who you are?
-
You have 1+ years of experience in the security industry, related internships or as a cloud systems engineer
-
You have experience with Linux and system fundamentals, hypervisor & container security (especially in modern cloud environments)
-
You have knowledge of Windows and/or Mac system fundamentals
-
You have enthusiasm and passion for cyber security
-
You possess development skills (for example Python, Terraform, Bash scripting, Micro-service architecture, API testing or fuzzing, etc)
-
You have understanding of network protocols (TCP/UDP, SSH, TLS, DNS, DHCP, IPMI, SNMP, etc) and applied cryptography (encryption, signing, certificates, algorithms)
-
You have excellent interpersonal and communication skills with a sense of urgency and impatience infused with infectious enthusiasm to drive our vision
-
You have strong collaborative skills and ability to work in a diverse global team of security professionals
-
You communicate fluently in English