Cyber Security Investigator
Core
Conduct time-sensitive cyber security incident management, threat response, and forensic analysis to identify and mitigate Advanced Persistent Threat (APT) activities and indicators of compromise for ExxonMobil's digital assets.
Role type
Senior IC Cyber Security Investigator (Incident Response & Threat Hunting)
Builds
Incident response playbooks, Alert and Detection Strategies (ADS), and forensic evidence for threat mitigation
Domain
Energy & Chemicals / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Forensic analysis, Threat hunting, Malware analysis, SIEM usage, EDR usage, Network protocol analysis, Cloud security incident response, Scripting (Python/PowerShell), Incident documentation
Preferred skills
Root cause analysis, Behavioral analytics, Anomaly detection, Static/dynamic malware analysis, Vulnerability testing, Simulated attack execution
Technologies
Splunk, CrowdStrike, AWS, Azure, GCP, TCP/IP, DNS, HTTP/S
Responsibilities
Conduct and document time-sensitive cyber security incident management and threat response; Identify and mitigate indicators of compromise and Advanced Persistent Threat activities (APT); Participate in 24/7 SOC on-call shift rotations; Develop and maintain playbooks which provide an investigation guideline; Assist in the development, documentation and maintenance of new Alert and Detection Strategies (ADS) focused on tactics, techniques and procedures (TTP); Support cyber security escalation teams.
Seniority
Mid-Senior, hands-on IC