We are building a team to provide world-class innovative, creative and efficientbusiness services to our Firm and clients.
As an innovative hub connected with theFirm's offices globally, BM Global Services Buenos Aires Center will provide all aspectsof business support for the Firm and its global clients in the areas of Alternative LegalServices, Finance, Technology, Knowledge, Operations, Business Development,Marketing and Communications, and People.
Our clients are facing more competition and challenges, which demands faster,commercially sound responses, more competitive prices, better quality, continuousinnovation and higher levels of legal and business knowledge.
The BM Global ServicesBuenos Aires Center will help us continue to deliver precisely that, by centralizing manyof our services in an appealing market.
Role Purpose :
The Incident Response Analyst will provide detection, containment, and analysis ofsecurity events to protect the confidentiality, integrity, and availability of informationsystems in accordance with the firm's business objectives, regulatory requirements,and strategic goals.
Main Responsibilities :
Provide Tier 2 incident response services to the global organization on behalf of the Information Security Team.
Receive, process, and resolve tickets per defined SLA's.
Analyze information garnered from monitoring systems, operational incidents, and other sources to determine the scope and impact of potential security incidents, and process accordingly.
Critically assess current practices and provide feedback to management on improvement opportunities.
Assist with the design and implementation of threat detection and prevention solutions identified as necessary for the protection of Firm assets.
Effectively utilize common IR toolsets, platforms, and processes, such as SIEM, log management, packet capture, and breach detection systems.
Provide assistance with forensic examinations and chain -of-custody procedures as directed by the Security Incident Response Engineers.
Provide input into standards and procedures.
Report compliance failures to management for immediate remediation.
Maintain assigned systems to ensure availability, reliability, integrity, including the oversight of current and projected capacity, performance, and licensing.
Provide status reports and relevant metrics to the Security Operations Manager.
Contribute to the Firm's security-related information repositories and other marketing / awareness endeavours.
Participate in special projects as needed.
Key Skills and Experience Required :
Foundational knowledge of IR concepts and best practices, including forensics and chain-of-custody.
Experience with common IR tools such as SIEM, log management, IDS, breach detection systems (APT / BDS / EDR), and packet capture.
Broad understanding of TCP / IP, DNS, common network services, and other foundational topics.
Working knowledge of malware detection, analysis, and evasion techniques.
Able to conduct static and dynamic analysis of malware to extract indicators of compromise, profile malware behaviour, and provide recommendations for mitigating and detecting malware.
Able to analyze suspicious websites, script-based and malware code
Experienced with vulnerability management tools such as Qualys, Nessus or other vulnerability scanning discovery tools
Broad familiarity with the threat landscape and the ability to adapt practices to evolving circumstances.
Identify, analyze, and report threats within the enterprise by using information collected from a variety of sources (IDS / IPS, SIEM, AV), to protect data and networks.
Implement techniques to hunt for known and unknown threats based on available threat intelligence reports and knowledge of the attacker's TTPs.
Ability to gather and analyze facts, draw conclusions, define problems, and suggest solutions.
Maintain critical thinking and composure under pressure.
Strong written and oral communication skills. Ability to convey complex concepts to non-technical constituents. Proficiency in oral and written English.
Capable of providing assistance with the preparation of internal training materials and documentation.
Ability to be productive and maintain focus without direct supervision.
Passionate in the practice and pursuit of IR excellence.
Exhibits a disciplined and rigorous approach to incident handling.
Willing to accommodate shift-based work for a global organization.
Provide exemplary customer service by striving for first call resolution and demonstrating, empathy, respect, professionalism, and expertise.
Experience with digital forensics on host or network and identification of anomalous behaviour on network or endpoint devices.
Familiar with host and network based forensic tools such as EnCase, FTK, Sleuth Kit, X Ways etc.
We are committed to promoting diversity and inclusion for all. Our unique internationalculture is reflected in the drawing together of a worldwide family of individuals fromdiverse cultures and backgrounds in all of our offices.
We encourage the best people -regardless of race, religion or belief if any, gender, gender identity, disability, sexualorientation or age - to fulfill their professional aspirations with us.
If you are ready to join us, please upload your Resume in English.