Network Detection and Response Engineer

3 weeks ago


Cary, United States MetLife Services and Solutions, LLC Full time
Description and Requirements

Role Value Proposition:

The Cyber Platforms and Automation team is primarily based out of MetLife's global technology headquarters in Cary, NC. This team manages the key cybersecurity platforms including SIEM, UEBA, SOAR, MSV, NDR, and the Cybersecurity Lab, and develops security content and processes to automate threat detection and incident response. The team takes immense pride in pursuing the vision to transform the Security Operations Center (SOC) into next generation with AI-driven cybersecurity technologies and processes to detect and predict threats with high accuracy, to prevent and respond to threats with high efficiency.

This is an exciting opportunity to directly contribute to completing MetLife's SOC visibility triad by establishing the network detection and response capabilities that will complement the existing logging and endpoint detection and response programs.

Success in this role requires you to demonstrate skills to work collaboratively with a very diverse group of stakeholders from global regions and backgrounds like cyber security experts, network engineers, infrastructure operations, Business leaders, etc. The ideal candidate will apply their deep experience in network security and engineering to bolster our threat detection and incident response capabilities across both traditional data center and public cloud environments. With a robust foundation in information security principles, you will play a vital role in protecting our organization's critical assets.

Key Responsibilities

The Security Lead, Network Detection, and Response will be responsible for the following tasks and activities:

Global Solution Deployment:
  • Understand the regional network architecture and engineer NDR solution deployment by identifying the correct choke points to optimize packet capture and metadata collection.
  • Architect and deploy software censors for the VMware infrastructure visibility for high-value assets and flow and packet collection for major cloud service providers (Azure, AWS, and GCP).
  • Threat Detection and Analysis: Develop and maintain network security monitoring strategies for hybrid (data center and cloud) environments to proactively monitor, identify, and analyze anomalous network activity, leveraging NDR.
  • Security Incident Response: Facilitate investigations into potential security incidents, providing in-depth analysis to determine the scope and impact. Collaborate on incident containment, remediation, and root cause analysis to mitigate risks.
  • Signature and Rule Development: Create custom rule detection, tune existing rules to reduce false positives, and understand behavioral detection based on ML and AI.
  • Threat Hunting: Facilitate conducting proactive hunts and campaigns for advanced threats and attack patterns across our network infrastructure, applying advanced analytics and threat intelligence.
  • Continuous Improvement: Stay updated on the evolving threat landscape and emerging cybersecurity technologies. Propose enhancements to existing security systems, processes, and detection capabilities.
  • Documentation and Reporting: Maintain detailed documentation of security incidents, investigations, and resolution steps. Provide clear reporting to management on security posture and identified risks.
Essential Business Experience and Technical Skills:

Required:
  • Minimum of 5 years of proven experience in network security roles, with a solid background in network engineering/Microsoft cloud administration/Identity and Access Management
  • Deep understanding of TCP/IP protocols, network traffic analysis, and common attack vectors.
  • Proven experience with security information and event management (SIEM) solutions, IDS/IPS systems, Packet aggregator technologies, and network forensic tools.
  • Expertise in network security monitoring and threat detection methodologies within public cloud platforms (AWS, Azure, GCP, etc.).
  • Knowledge of data center network architecture, security best practices, and relevant technologies.
  • Knowledge of modern adversary tactics, techniques, and procedures used to exploit Identity and Access
  • Information Security: Strong foundation in information security principles, compliance frameworks, and risk management.
  • Analytical Skills: Exceptional ability to analyze complex data sets, correlate events, and identify patterns indicative of malicious activity.
  • Problem Solving: Highly methodical approach to troubleshooting, incident response, and root cause analysis.
  • Ability to empathize and collaborate with colleagues, manage, and execute tasks, and prioritize efforts for risk reduction.
Preferred:
  • Industry Certifications: Relevant technical and security certifications such as CISSP, GIAC, GCIH, and relevant network or cloud security certifications.
  • Scripting/Automation: Proficiency in a scripting language (Python, KQL, SQL, etc.) for security automation tasks.
  • Global Experience: Prior experience working on multiple global projects with regional partners.


At MetLife, we're leading the global transformation of an industry we've long defined. United in purpose, diverse in perspective, we're dedicated to making a difference in the lives of our customers.

Benefits We Offer

Our U.S. benefits address holistic well-being with programs for physical and mental health, financial wellness, and support for families. We offer a comprehensive health plan that includes medical/prescription drug and vision, dental insurance, and no-cost short- and long-term disability. We also provide company-paid life insurance and legal services, a retirement pension funded entirely by MetLife and 401(k) with employer matching, group discounts on voluntary insurance products including auto and home, pet, critical illness, hospital indemnity, and accident insurance, as well as Employee Assistance Program (EAP) and digital mental health programs, parental leave, volunteer time off, tuition assistance and much more

About MetLife
Recognized on Fortune magazine's list of the 2023 "World's Most Admired Companies" as well as the 2023 Fortune 100 Best Companies to Work For ®, MetLife , through its subsidiaries and affiliates, is one of the world's leading financial services companies; providing insurance, annuities, employee benefits and asset management to individual and institutional customers. With operations in more than 40 markets, we hold leading positions in the United States, Latin America, Asia, Europe, and the Middle East.

Our purpose is simple - to help our colleagues, customers, communities, and the world at large create a more confident future. United by purpose and guided by empathy, we're inspired to transform the next century in financial services. At MetLife, it's #AllTogetherPossible . Join us

Equal Employment Opportunity/Disability/Veterans

If you need an accommodation due to a disability, please email us at accommodations@metlife.com. This information will be held in confidence and used only to determine an appropriate accommodation for the application process.

MetLife maintains a drug-free workplace.

  • Cary, United States MetLife Full time

    Role Value Proposition: The Cyber Platforms and Automation team is primarily based out of MetLife’s global technology headquarters in Cary, NC. This team manages the key cybersecurity platforms including SIEM, UEBA, SOAR, MSV, NDR, and the Cybersecurity Lab, and develops security content and processes to automate threat detection and incident response. The...


  • Cary, North Carolina, United States MetLife Full time

    Description and Requirements Role Value Proposition: The Cyber Platforms and Automation team is primarily based out of MetLife's global technology headquarters in Cary, NC. This team manages the key cybersecurity platforms including SIEM, UEBA, SOAR, MSV, NDR, and the Cybersecurity Lab, and develops security content and processes to automate threat detection...


  • Cary, United States MetLife Full time

    Description and Requirements Role Value Proposition: The Cyber Platforms and Automation team is primarily based out of MetLife's global technology headquarters in Cary, NC. This team manages the key cybersecurity platforms including SIEM, UEBA, SOAR, MSV, NDR, and the Cybersecurity Lab, and develops security content and processes to automate threat...


  • Cary, North Carolina, United States MetLife Full time

    Description and Requirements Role Value Proposition: The Cyber Platforms and Automation team is primarily based out of MetLife's global technology headquarters in Cary, NC. This team manages the key cybersecurity platforms including SIEM, UEBA, SOAR, MSV, NDR, and the Cybersecurity Lab, and develops security content and processes to automate threat detection...

  • Network Engineer

    2 months ago


    Cary, United States eTeam Full time

    Detailed Job Description: Seeking an experienced Network Engineer to join our IT Global Infrastructure team. The position is primarily responsible for the coordination of network operations balanced with the delivery of best in class customer service at our Austin Office. This position requires a detail-oriented individual with the ability to make logical...

  • Network Engineer

    1 week ago


    Cary, United States eTeam Full time

    Detailed Job Description: Seeking an experienced Network Engineer to join our IT Global Infrastructure team. The position is primarily responsible for the coordination of network operations balanced with the delivery of best in class customer service at our Austin Office. This position requires a detail-oriented individual with the ability to make logical...

  • Network Engineer

    2 months ago


    Cary, United States CompuPlus Inc. Full time

    Education Experience Qualifications and Skills• BS Degree (preferably in a technical discipline)• 6+ years of engineering experience or comparable experience• 5+ years of experience in network/system administration• Strong Organizational and communication skills• Proficient problem-solving skills• Strong Interpersonal skills with the ability...

  • Network Engineer

    2 weeks ago


    Cary, United States CompuPlus Inc. Full time

    Education Experience Qualifications and Skills• BS Degree (preferably in a technical discipline)• 6+ years of engineering experience or comparable experience• 5+ years of experience in network/system administration• Strong Organizational and communication skills• Proficient problem-solving skills• Strong Interpersonal skills with the ability...

  • Network Engineer

    2 months ago


    Cary, North Carolina, United States CompuPlus Inc. Full time

    Education Experience Qualifications and Skills BS Degree (preferably in a technical discipline) 6+ years of engineering experience or comparable experience 5+ years of experience in network/system administration Strong Organizational and communication skills Proficient problem-solving skills Strong Interpersonal skills with the ability to work...

  • Network Engineer

    2 weeks ago


    Cary, North Carolina, United States CompuPlus Inc. Full time

    Education Experience Qualifications and Skills BS Degree (preferably in a technical discipline) 6+ years of engineering experience or comparable experience 5+ years of experience in network/system administration Strong Organizational and communication skills Proficient problem-solving skills Strong Interpersonal skills with the ability to work...

  • Network Engineer

    4 weeks ago


    Cary, North Carolina, United States MetLife Full time

    Description and Requirements Role Value Proposition: The Network Engineer will provide Tier 2 global support for the MetLife enterprise network infrastructure. This includes our data centers, e-Commerce environment, and remote access segments. This also includes supporting our public cloud infrastructure. The candidate should have broad knowledge of...

  • Network Engineer

    2 weeks ago


    Cary, North Carolina, United States MetLife Full time

    Description and Requirements Role Value Proposition: The Network Engineer will provide Tier 2 global support for the MetLife enterprise network infrastructure. This includes our data centers, e-Commerce environment, and remote access segments. This also includes supporting our public cloud infrastructure. The candidate should have broad knowledge of...

  • Network Engineer

    1 month ago


    Cary, United States Navitas Full time

    Job DescriptionJob DescriptionNetwork Engineer - DNS/DHCPRaleigh, NC- Will consider alternate locations based on qualifications.Navitas Business Consulting is seeking a Network Engineer- DNS/DHCP professional to provide service to our Federal Client in the Raleigh NC area but we will consider alternate locations based on qualifications. Responsibilities:...


  • Cary, United States Danta Technologies Full time

    Role: Network Voice Engineer Location: Cary, North Carolina (Onsite) Duration: Long Term Contract Mandatory Skills: CUCM, Cisco Voice, Avaya **Job Description:** The Network Voice Engineer specializing in Cisco technologies is responsible for the design, implementation, and maintenance of voice communication systems. This role involves working...


  • Cary, United States Danta Technologies Full time

    Role: Network Voice Engineer Location: Cary, North Carolina (Onsite) Duration: Long Term Contract Mandatory Skills: CUCM, Cisco Voice, Avaya **Job Description:** The Network Voice Engineer specializing in Cisco technologies is responsible for the design, implementation, and maintenance of voice communication systems. This role involves working...


  • Cary, United States Danta Technologies Full time

    Role: Network Voice Engineer Location: Cary, North Carolina (Onsite) Duration: Long Term Contract Mandatory Skills: CUCM, Cisco Voice, Avaya **Job Description:** The Network Voice Engineer specializing in Cisco technologies is responsible for the design, implementation, and maintenance of voice communication systems. This role involves working...


  • Cary, United States American Tower Corporation Full time

    The TeamWe are seeking a Principal Engineer, Cybersecurity Engineering to join American Tower's Information Security team. The team protects the confidentiality, integrity, and availability of data and systems in core systems and platforms. Day to day you will observe all the security operations occurring across the networks and manage the security...


  • Cary, United States Coilcraft Full time

    Vision Systems Engineer Coilcraft is a successful, privately-held company in Cary, IL with a worldwide reputation for high-quality passive electronic components. Coilcraft operates in a wide range of industries, including telecommunications, computers, automotive, broadband communications, and consumer electronics. We are seeking a Vision Systems Engineer to...


  • Cary, United States Secmation Full time

    Job DescriptionJob DescriptionThe software developer will work with our engineering teams and be involved in developing critical cybersecurity technology to support a variety of applications including protection of network traffic, securing autonomous vehicles and critical infrastructure, and engineering tools which automate the application of security...

  • Linux Devops Engineer

    2 months ago


    Cary, United States Diverse Lynx Full time

    Title: DevOps Engineer Location: Cary, NC, US Onsite (Hybrid) Job Description: Technical/Functional Skills UNIX/RHEL Administration •ELK (Elasticseach / Logstash / Kibana) •DevOps: Docker, Ansible, Terraform, Git •Google Cloud Platform •Network Security Monitoring - Zeek / Suricata and other similar Network Detect & Response platforms...