Skills
| Required/Preferred
| Years
| Candidate Experience
|
Progressively responsible information technology and cybersecurity experience in enterprise environments, including security engineering, security operations, endpoint security, identity security, cloud security, and messaging security.
| Required
| 7
|
|
Recent hands-on production experience configuring, administering, tuning, investigating and troubleshooting Palo Alto Cortex and Tanium security technologies, including Palo Alto Cortex for Endpoint and Tanium Comply Modules.
| Required
| 4
|
|
Recent hands-on production experience administering enterprise email security technologies. The required three years may consist of combined experience across these technologies, but experience with each named technology is mandatory.
| Required
| 3
|
|
Recent hands-on Microsoft Exchange Administrator experience, including Exchange Online administration, mail flow, transport rules, connectors, message tracing, anti-spam controls, anti-phishing controls, quarantine, mail routing, and troubleshooting security-related messaging issues.
| Required
| 3
|
|
Hands-on security incident-response experience, including alert triage, investigation, containment, eradication, recovery, root-cause analysis, and post-incident documentation.
| Required
| 3
|
|
Hands-on threat-hunting experience using endpoint, identity, email, network, and cloud telemetry to identify malicious or anomalous activity not detected through standard alerting.
| Required
| 2
|
|
Demonstrated experience developing and tuning detection logic, security policies, alert thresholds, exclusions, allow and block rules, indicators, automated response actions, and other controls to improve detection efficacy and reduce false positives.
| Preferred
|
|
|
Demonstrated ability to investigate endpoint, identity, and email threats using artifacts such as process trees, command lines, hashes, URLs, domains, IP addresses, message headers, authentication events, user activity, and related telemetry.
| Preferred
|
|
|
Demonstrated experience with Microsoft Entra ID or Azure Active Directory security, including authentication events, sign-in risk, conditional access, identity protection, multifactor authentication, and identity-related incident investigation.
| Preferred
|
|
|
Demonstrated experience using PowerShell or comparable scripting to support security administration, investigation, data collection, configuration, and repeatable operational tasks.
| Preferred
|
|
|
Demonstrated experience creating and maintaining technical configurations, operational procedures, incident records, threat-hunting reports, security metrics, and remediation recommendations suitable for operational and management review.
| Preferred
|
|
|
Demonstrated experience performing substantially similar services in at least one large, distributed enterprise environment.
| Preferred
|
|
|