1. Objectives - Develop and test detection rules or trusted catalogs within client's EDR (connected to an XDR) - Validate rules by ensuring proper triggering and minimal false positives - Document detections and update technical documentation on an ongoing basis - Align detections with MITRE ATT&CK techniques and threat intelligence - Provide regular status updates and collaborate on priorities defined by the client 2. Deliverables - Detection Rules: Sigma/YARA/compatible with client's rules, implemented and tested - Policies and Configurations - Baseline and customized hardening of client EDR - Ongoing Documentation - Living technical documentation maintained throughout the engagement (configurations, rules, validation results) - Progress Reports - Regular updates on developed rules, validation outcomes, and next priorities - Metrics will be based on incremental delivery and validation checkpoints, not on a fixed number of rules per month
- Thu nhập hấp dẫn Tối thiểu 13 tháng lương/năm Đánh giá tăng lương hàng năm Thưởng hiệu quả công việc hàng tháng, thưởng dự án, thưởng ngày lễ, thưởng Tết,… Trợ cấp thai sản cho nhân viên nữ ngoài bảo hiểm xã hội - Chăm sóc sức khỏe Khám sức khỏe định kỳ hằng năm tại các trung tâm y tế chất lượng cao Chương trình bảo hiểm sức khỏe toàn diện Rikkei Care - Phát triển sự nghiệp Tham gia các chương trình đào tạo được tổ chức thường xuyên bởi các chuyên gia trong và ngoài nước Công ty tài trợ chi phí thi các chứng chỉ quốc tế Thưởng thành tích khi đạt các chứng chỉ ngoại ngữ Cơ hội làm việc tại Nhật, Mỹ, Hàn và nhiều quốc gia khác trên thế giới,… - Môi trường năng động, tích cực Thời gian làm việc linh động, nghỉ thứ 7 + chủ nhật hàng tuần 12 ngày phép/năm + 1 ngày nghỉ du lịch Chế độ team building hàng quý, du lịch hàng năm Tham gia các giải đấu thể thao indoor, outdoor, e-sport,… Tham gia các Câu lạc bộ bóng đá, bóng bàn, cầu lông, bơi lội, âm nhạc, tiếng Anh,…
- Proficiency in Python, PowerShell, Bash, and Regex for scripting and automation. - Strong understanding of Windows internals, attack vectors, and common evasion techniques. - Hands-on experience with EDR platforms and EDR cybersecurity rules - Hands-on experience with Elastic Security - Familiarity with MITRE ATT&CK, threat hunting, and adversary emulation. - Experience tuning detection rules to reduce false positives and improve signal fidelity. - Ability to interpret threat intelligence and translate it into actionable detection logic.