**Business Title:** Cyber Threat Hunting and Incident Response Analyst - Remote
**Requisition Number:** 93788 - 73
**Function:** Business Support Services
**Area of Interest:**
Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizations in today's most important industries. Our growth is driven by delivering real results for our clients. It's also enabled by our culture, which encourages individual development, embraces an inclusive environment, rewards innovative excellence and supports our communities. With qualities like those, it's no wonder we're consistently ranked among the best companies to work for by Fortune Magazine, Consulting Magazine, Working Mother Magazine, Diversity Inc. and others. If you're as passionate about your future as we are, join our team.
KPMG is currently seeking a Sr. Associate, Cyber Threat Hunting and Incident Response Analyst to join our Digital Nexus Group organization.This role is a remote work opportunity.
+ Perform all phases of incident response life cycle: preparation, analysis, containment, eradication, remediation, recovery and post-incident activity
+ Complete threat hunting in both on-premises and cloud environments
+ Define, document, test and manage incident response processes, document processes and procedures in the form of playbooks and reference guides
+ Evaluate external threat intelligence sources related to zero-day attacks, exploit kits and malware to determine organizational risk and improve threat detection by incorporating into detection tools
+ Conduct forensics, host-based disk and memory as well as network; analyze to determine root cause and impact
+ Develop security monitoring by using cases and supporting content for security tools such as dashboards, alerts, reports, rules; including but not limited to the configuration and monitor security information and event management (SIEM) platform for security alerts
+ Minimum five years of recent security monitoring experience and incident response activities preferably within a professional services firm or similar environment; experience with IT process definition and/or improvement
+ Bachelor's degree from an accredited college/university or equivalent work experience
+ Solid understanding of network and system intrusion and detection methods; examples of related technologies include Splunk, Next Generation Endpoint Protection Platforms (EPP), Security information and event management (SIEM), hacking tools techniques and procedures
+ Experience with coding and analytics, malware analysis, endpoint lateral movement detection methodologies and host forensic tools
+ Understanding of network protocol analysis, public key infrastructure, SSL, Microsoft Windows and Active Directory, Linux, open-source software, scripting, SQL and software programming
+ Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future; candidates must be able to perform work during the Eastern or Central time zones regular business hours
KPMG LLP (the U.S. member firm of KPMG International) offers a comprehensive compensation and benefits package. KPMG is an affirmative action-equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link ( https://assets.kpmg.com/content/dam/kpmg/us/pdf/2018/09/eeo.pdf) contains further information regarding the firm's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please.
KPMG does not currently require partners or employees to be fully vaccinated or test negative for COVID-19 in order to go to KPMG offices, client sites or KPMG events, except when mandated by federal, state or local law. In some circumstances, clients also may require proof of vaccination or testing (e.g., to go to the client site).