Principal Threat Hunter

  • Warszawa
  • Novartis
Sandoz is going through an exciting and transformative period as a global leader and pioneering provider of sustainable Generic and Biosimilar medicines.Now as an independently listed company, Sandoz aims to increase its strategic focus, operate with greater agility, set clearer business objectives, enhance shareholder returns, and strengthen its culture for us, the Sandoz associates. This is an exciting time in our history, and by creating a new and ambitious path, it will provide a unique opportunity for us all, both professionally and personally.Join us as a Founder of our ‘new’ Sandoz!As part of the Sandoz Security Operations team the Principal Threat Hunter will ensure that the organization performs has the necessary steps to investigate the company’s environment against the relevant industry threats. The position is responsible for analyzing and correlating large data sets to uncover novel threats and attack techniques that may be present within the company’s environments. A Principal Threat Hunter also will be tasked with and collaborating with SOC, Cyber Forensics, CTI, SOAR, Vulnerability Management and other cybersecurity teams to identify opportunities to develop analytical methods to detect advanced threat actors who utilize emerging tactics and techniques. In support of these processes, the role will also include developing and documenting new and innovative threat hunt hypotheses to increase the team's ability to find existing threats that are otherwise going unidentified or unnoticed. The role will also be expected to actively share knowledge and mentor more junior SOC members.Your Key Responsibilities:Your responsibilities include, but not limited to:•Perform regular Threat Hunts based on the information provided by other cybersecurity functions. •Develop valuable hunt strategies.•Uncover new Threats, TTP’s and vulnerabilities. •Support the development, implementation, and continuous improvement of the Threat Hunting Process•Perform Intel based, hypothesis based and custom hunts.•Cooperate with external vendors to gain critical insight into the tactics used by attackers in the industry.•Work with SOC, CTI and Vulnerability Management Teams to secure the company’s systems against identified threats.•Perform threat modelling for applications and infrastructure.•Identify internal risks from both technical and process standpoint (internal threats, DLP issues, PII protection)•Share the security knowledge by contributing to Knowledge Base and cybersecurity best practices.