
Deepfield Security Operations Engineer
City : Ottawa, Ontario
Category : Permanent
Industry : Customer Services
Employer : Nokia
Join us in creating the technology that helps the world act together
We are a B2B technology innovation leader pioneering the future where networks meet cloud. At Nokia you will have a positive impact on people’s lives and help build the capabilities needed for a more productive, sustainable, and accessible world.
Be part of a culture built on an inclusive way of working where we are open to your ideas, you are empowered to take risks and are encouraged to be fearless in bringing your authentic self to work.
The team you'll be part of
The pandemic has highlighted how important telecoms networks are to society. Nokia’s Network Infrastructure group is at the heart of a revolution to bring more and faster network capacity to people worldwide through our ambition, innovation, and technical expertise. Deepfield is a Nokia owned company that builds the analytic and security solutions that monitor and defend over 90% of internet backbone networks. We produce cutting-edge research at the intersection of data science, visualization, and network analytics, and we create, deploy, and maintain the largest global network analytics platform. Join us and help us advance state-of-the-art network intelligence. The Nokia Deepfield Security Operations (SecOps) team is a global team of technical experts that helps our customers deal with complex DDoS attacks. SecOps engineers troubleshoot issues on the Deepfield platform, analyze DDoS attacks samples from our DDoS Library, and design the most
effective set of countermeasures when customers request SecOps intervention under attack.
What you will learn and contribute to
As part of the SecOps team, you will be part of the organization that maintains one of the biggest and most detailed DDoS attack sample Library of the internet. You will learn how to use big-data analytics to help customers protect themselves from all DDoS attacks.
Are you passionate about solving problems?
As part of our team, you will:
You will help customers under DDoS attacks successfully deal with the threat utilizing the most efficient countermeasures and provide technical assistance related to DDoS detection and mitigation.
- Provide use case driven support to customers using all Deepfield Applications (Cloud Intelligence, Subscriber Intelligence, Operational Intelligence, Defender DDoS) with a focus on Defender (DDoS attack detection & auto-mitigation)
- Become a Defender & DDoS subject matter expert for Deepfield customers & Nokia internal
teams - Develop expertise to triage, debug, de-code, reproduce and resolve Defender DDoS detection and mitigations
- Research, analyze and report on global DDoS threats, trends and evolution
- Contribute to Secure Genome library
- Inspect DDoS attack samples to identify possible false-positives/false-negatives, and recommend corrective actions on detection/mitigation rules
- Be a member of the Deepfield Emergency Response Team for Customer Support during active DDoS events, including 24x7 1 week on call rotation, approximately every 6 weeks.
- Triage escalated customer Defender/DDoS issues and attacks
- Work closely with R&D to manage escalation of customer issues that require development team engagement and support
- Actively participating in the Security Operations Community external to Nokia
- Post-sales Security customer consulting and support, including ERTS (Emergency Response Team Support) Service
- Assist with writing and updating technical documentation
- Work alongside industry leaders in Network Security
Your skills and experience
We are hiring an experienced (minimum 5+ years) Security Operations Engineer. Expertise with Security incident handling & response, Network security and IP networks is a must. Knowledge of Customer Support process and Customer escalation support is required. Experience with TCP/IP, Routing and Switching, and network management and support is required. The ability for the Security Operations engineer to go deep into technical questions, as well as having solid problem-solving skills are extremely important. A sense of ownership, initiative and responsibility is essential for this role. The Security Operations Engineer is a subject matter expert on network security, DDoS detection and mitigation, and the Deepfield Defender solution.
Our ideal candidate is an experienced Security/IP engineer with a passion for coding and intricate algorithms; someone who thrives in a complex, fast-moving environment and is comfortable in on-call rotations and high intensity events — Deepfield Security Operations engineers must be able to triage difficult problems, deliver under pressure, ensure system stability, manage customer expectations, and constantly improve processes.
You have:
- Bachelor’s Degree in Electrical or Computer Engineering / Computer Science, or equivalent
related experience in a technical field. - Experience with Security Incident Handling & Response, for example:
- Investigating a data breach, determining the cause and scope of the incident, and
taking steps to prevent further unauthorized access - Conducting a forensic analysis of a compromised system to identify the root cause of
the security incident and determine the extent of the damage - Developing and implementing a plan to restore services and data after an attack
- Actively managing customer support during security incidents
- Investigating a data breach, determining the cause and scope of the incident, and
- Domain knowledge of Network Security, for example:
- Network protocols, such as TCP/IP, HTTP, and FTP
- Network security protocols, such as SSL, TLS, and SSH
- Network perimeter security, including firewalls and virtual private networks (VPNs)
- Intrusion detection and prevention systems (IDPS)
- Network monitoring and analysis tools, such as packet sniffers and log analysis tools (e.g. Wireshark, tcpdump)
- Understanding how networks, routers, firewalls, and other security devices work, for example:
- How data is transmitted over a network and the different layers of the OSI model
- How a firewall works and different types of firewall technologies, such as stateful inspection and application-level filtering
- How various VPN technologies can be used to secure remote access to a network
- Functions and capabilities of network security devices, such as intrusion detection and prevention systems (IDPS), load balancers, and web application firewalls (WAFs)
- Experience delivering Customer Support, Technical Support or Customer Escalation Management
- Proficiency in Linux systems (Ubuntu)
- Ability to work well under pressure: our customers can face very large and complex DDoS attacks and will rely on you to restore service and minimize disruptions to their own customers.
- Listening and communication: strong written and oral communication skills are essential, to convey clear and authoritative responses to Deepfield customers
- Scripting experience with Python
- Building strong relationships with customers
- Being a self-starter, pro-active in identifying customer issues and driving to resolution
- Thriving in a fast-paced, quickly evolving, tech start-up environment
- Contributing remotely to a collaborative, dynamic, and diverse team
It would be nice if you also had:
- Security audit and compliance knowledge
- Familiarity with big data technologies (such as Hadoop, Pandas DataFrames)
- Proficiency with advanced configuration and management of Service Provider networks
- Understanding of how distributed compute cluster functions
- Working within a ticket tracking system (ie JIRA)
What we offer
Nokia offers flexible and hybrid working schemes, continuous learning opportunities, well-being programs to support you mentally and physically, opportunities to join and get supported by employee resource groups, mentoring programs and highly diverse teams with an inclusive culture where people thrive and are empowered.
Nokia is committed to inclusion and is an equal opportunity employer
Nokia has received the following recognitions for its commitment to inclusion & equality:
- One of the World’s Most Ethical Companies by Ethisphere
- Gender-Equality Index by Bloomberg
- Workplace Pride Global Benchmark
At Nokia, we act inclusively and respect the uniqueness of people.
Nokia’s employment decisions are made regardless of race, color, national or ethnic origin, religion, gender, sexual orientation, gender identity or expression, age, marital status, disability, protected veteran status or other characteristics protected by law.
We are committed to a culture of inclusion built upon our core value of respect.
Join us and be part of a company where you will feel included and empowered to succeed.