Loading jobs…
Loading jobs…
Boku Inc. — White Plains, New York
Join Atlas Air Worldwide. Move the World with Us! At Atlas Air Worldwide, we’re not just an airline, we’re a global engine powering cargo, passenger, and leasing operations across more than 70 countries.
As a leader in outsourced aviation logistics, we’re built on a foundation of safety , service excellence , integrity , innovation , teamwork , and responsibility . With over 30 years of history, a modern all-Boeing fleet, and nearly 5,000 teammates collaborating across operations, technical, and corporate functions, we’re driven by purpose. If you're ready to grow, innovate, and help us deliver excellence every single day, you belong here.
This position is responsible for cybersecurity operations and defense including threat assessment, incident handling, and managing vulnerabilities against Atlas Air Global Technology environment. Values and Behavioral Standards: To ensure the effective communication and application of company values and behavioral standards, as stated in our company “Code of Conduct” policy, and to respond appropriately in the event of any known departure.
Responsibilities
: This position will be responsible for security event monitoring, vulnerability assessments, web application penetration tests, integrity checking, and maintaining necessary standards controls, and procedures.
What You Will Do
: Cyber Defense Design, implement, and leverage advanced detections using SIEM and SOAR technology Develop innovative custom detection rules and automated remediation, playbooks, and alerts tailored to the organization's threat landscape for enterprise and customer security. Leverage industry standard MITRE frameworks to identify detection coverage and address gaps. Evaluate, validate, tune, and sunset detection capabilities to optimize Alert to Incident ratio Maintains operational playbooks and workbooks to improve security detection and response Participate directly in the security incident response process and effectively contribute to the containment and eradication of threats and recovery of technology from cybersecurity incidents.
Monitor multiple sources of incident reporting (mailboxes, hotlines, external sources) and optimize response times through automated routines Propose and define new SIEM content and monitoring use cases as needed upon emergence of new applications, threats, and policies. Monitor and resolve security alerts from the SIEM and other security systems, as well as those escalated by the MSV providing SOC services, for potential threats and compliance issues. Improve detection systems for performance, scalability, and cost effectiveness.
Threat/Vulnerability Management Conduct threat modeling to proactively identify and address security risks before exploitation.
Qualifications
: 5+ years’ experience in Security Operations or related IT operational roles.