About this role
About the Role Incident Response Specialist is part of the Kaspersky Global Emergency Response Team, responsible for responding to cyber incidents and investigating threats worldwide. You will analyze malicious objects, investigate and respond to information security incidents, and interact with customers during incident handling. What You'll Do
- Analyze malicious objects and investigate and respond to information security incidents; interact with customers within incident handling.
- Apply static and dynamic analysis techniques using debuggers and disassemblers; utilize digital forensics, threat intelligence, network forensics, and reverse engineering tools.
- Detect, analyze, and respond to threats; maintain understanding of current indicators of compromise and methods to discover them.
- Gain knowledge of modern threats, vulnerabilities, typical attacks, their tooling, and how to detect and respond to them.
- Understand common network protocols, architectures and internal components of modern operating systems, and security technologies.
- Investigate computer incidents in large corporate networks; practical use of detection of targeted attacks.
- Create and tune detection rules (YARA, OpenIOC, STIX) and prepare project reports and analyses.
- Program in Python (or other scripting languages) to automate tasks.
- Hold professional certifications from Offensive Security, GIAC or equivalents. What We're Looking For
- Skills and experience with static and dynamic analysis of files, including debuggers and disassemblers.
- Proficiency with core tools for digital forensics, threat intelligence, network forensics, and reverse engineering.
- Experience analyzing malware samples.
- Understanding of current indicators of compromise and detection methods.
- Knowledge of modern threats, vulnerabilities, typical attacks, tools used to carry them out, and detection and response methods.
- Knowledge of common network protocols, architectures, and internal structures of modern operating systems, as well as information security technologies.
- Experience investigating computer incidents in large corporate networks.
- Experience applying detection of targeted attacks.
- Experience creating YARA, OpenIOC, STIX rules.
- Experience preparing incident reports and project analyses.
- Experience programming in Python (or other scripting languages).
- Possession of professional certifications from Offensive Security, GIAC or equivalents.