171 Followers
75 Following
25 Posts

And once again its hiring time, rounding out the last two analyst roles for my team Forensics and Incident Response (FIRE)
@theparanoids
at Yahoo! Links here and details in the next tweets:

https://ouryahoo.wd5.myworkdayjobs.com/careers/job/United-States-of-America---Remote/Weekend-Shift--Forensic-and-Incident-Response-Operations--FIRE--Analyst_JR0022162

https://ouryahoo.wd5.myworkdayjobs.com/careers/job/United-States-of-America---Remote/Paranoids-Forensic-and-Incident-Response-Operations--FIRE--Analyst_JR0022159

Lets talk about the role:

9 PM EST - 9 AM EST - Fri - Sun (3 days, full benefits/salary)
12 AM EST - 8 AM EST - Mon - Fri

Full time remote roles (US Only)

We anticipate these roles will be about 60% threat hunting

There will be a healthy amount of monitoring and response as well

We know weekends, overnights, and 12 hour shifts can be hard (I've worked all of them) If it's not for you, thats ok! But if working for a great team, with a strong culture, doing amazing things lines up, come have a chat with us, we will try to make it as painless as possible!

Just as an aside, if you think you aren't qualified but are interested, APPLY ANYWAY! Come chat with us, share your experience, we are sure you have more to bring to the table than you probably give yourself credit for! If nothing else it's experience and meeting cool folks.

There is so much to say about how much I love this team, they really are the smartest folks I have ever worked with and honestly we can't wait to have you join us! If interested, apply, reach out, come talk to us we want to meet you! More info check out theparanoids.com

Weekend Shift- Forensic and Incident Response Operations (FIRE) Analyst

It takes powerful technology to connect our brands and partners with an audience of nearly 900 million. Whether you’re looking to write mobile app code, engineer the servers behind our massive ad tech stacks, or develop algorithms to help us process trillions of data points a day, what you do here will have a huge impact on our business—and the world. Want in? A Little About Us: We are the information security team at Yahoo; known as \"The Paranoids\". As part of the Paranoids Forensics and Incident Response Operations Team (FIRE), we protect Yahoo and its users from dedicated adversaries, working on the front lines monitoring for, hunting for, and responding to threats. We ensure that our users and company are kept safe. We take ownership of key processes supporting the mission of finding evil and enable you to stop advanced attackers and protect our users. Please note this shit is for those available to work remotely between 9pm-9am EST/ 6pm-6am PST Sunday-Monday. Responsibilities: Monitor and analyze security events from networks, applications, hosts, and databases Perform proactive research and identification of security anomalies and participate in regular threat hunting exercises Assess security incidents and assist Yahoo business units to remediate issues Work with a variety of security technologies including IDS, firewalls, EDR, etc Participate in a 24x7 on call rotation Available to work remote night shifts 9pm-9am EST/ 6pm-6am PST A Lot About You: Background in security fundamentals including network and host forensics, log analysis, and basic malware triage A passion for the field of information security and incident response. Understanding of common network services (web, mail, FTP, etc), network vulnerabilities, and attack patterns An ability to work independently and communicate via technology in a remote setting Preferred Qualifications: Experience with Splunk Security Information and Event Monitoring (SIEM) solution Experience in shell scripting, Python, or similar tool and automation languages Yahoo is proud to be an equal opportunity workplace. All qualified applicants will receive consideration for employment without regard to, and will not be discriminated against based on age, race, gender, color, religion, national origin, sexual orientation, gender identity, veteran status, disability or any other protected category. Yahoo is dedicated to providing an accessible environment for all candidates during the application process and for employees during their employment. If you need accessibility assistance and/or a reasonable accommodation due to a disability, please submit a request via the Accommodation Request Form (www.yahooinc.com/careers/contact-us.html) or call 408-336-1409. Requests and calls received for non-disability related issues, such as following up on an application, will not receive a response. At Yahoo, we know that diversity makes us stronger. We are committed to a collaborative, inclusive environment that encourages authenticity and fosters a sense of belonging. We strive for everyone to feel valued, connected, and empowered to reach their potential and contribute their best. Check out our diversity and inclusion (www.yahooinc.com/diversity/) page to learn more. US Only: Please be aware that Yahoo requires all employees entering a U.S. Yahoo office and/or attending a company event (including client events) are required to be vaccinated for COVID-19. This position will require the successful candidate to obtain and show proof of a vaccination to enter a U.S. Yahoo office and/or attending a company event (including client events). Yahoo is an equal opportunity employer, and will provide reasonable accommodation to those individuals who are unable to be vaccinated consistent with federal, state, and local law. The compensation for this position ranges from $88,500.00 - $184,375.00/yr and will vary depending on factors such as your location, skills and experience. The compensation package may also include incentive compensation opportunities in the form of discretionary annual bonus or commissions, in addition to equity incentives. Yahoo provides industry-leading benefits including healthcare, 401K savings plan, company holidays, vacation, sick time, parental leave and an employee assistance program. Eligibility requirements apply. Yahoo has a high degree of flexibility around employee location and hybrid working. In fact, our flexible-hybrid approach to work is one of the things our employees rave about. Most roles don’t require specific regular patterns of in-person office attendance. If you join Yahoo, you may be asked to attend (or travel to attend) on-site work sessions, team-building, or other in-person events. When these occur, you’ll be given notice to make arrangements. If you’re curious about how this factors into this role, please discuss with the recruiter. Currently work for Yahoo? Please apply on our internal career site. Yahoo is a global media and tech company that connects people to their passions. We reach nearly 900M people around the world, bringing them closer to what they love—from finance and sports, to shopping, gaming and news—with the trusted products, content and tech that fuel their day. For partners, we provide a full-stack platform for businesses to amplify growth and drive more meaningful connections across advertising, search and media. #yahoo

Exciting news time! Myself and my good friend Taylor Johnson just got accepted to come talk @BSidesCharm and share the Incident Response framework we developed and are using @theparanoids ! Can’t wait to see you all there, we are very excited to get this out in the world!!
Come see me and fellow Paranoids (moderator: @understudy) on stage at #magfest tonight at 8p! We also have a fun panel tomorrow at 4. Room 4!
Mary had a little Lambda
S3 its source of truth
And every time that Lambda ran
Her bill went through the roof
EXCLUSIVE: TikTok Spied On Forbes Journalists

ByteDance confirmed it used TikTok to monitor journalists’ physical location using their IP addresses, as first reported by Forbes in October.

Forbes

On a road trip in the south and stopped for food. Daughter couldn’t reach the taps to wash her hands so we went into the men’s bathroom so I could turn on the water for her.

Some dude went off about how inappropriate it was that she was in the bathroom, not for him but I should apologize for scarring her.

Let’s be real dudes have way to many repressed confidence issues to just be running around the bathroom with their junk out, we keep that shit private, I don’t know what bathrooms this guy is hanging out in.

@accidentalciso I feel like I should do this, this seems like the best way to make infosec and work related content, while I'm out on a ride :P

It's hiring time again at the Paranoids at Yahoo!

This time for current students for our Forensics and Incident Response (FIRE) intern program (Summer 2023). Come work with an amazing team doing awesome stuff! Links first, details below:

https://ouryahoo.wd5.myworkdayjobs.com/careers/job/United-States-of-America---Remote/Forensics-and-Incident-Response--FIRE--Operations-Analyst-Intern_JR0021557

https://ouryahoo.wd5.myworkdayjobs.com/careers/job/United-States-of-America---Remote/Foreniscs---Incident-Response-Operations-Intern_JR0021596

Heres the details:
Two roles open
Full time / Hourly
PAID
Remote
US Only
Must be a current student during the internship
Working hours are flexible

The intern program Yahoo has always been special to me, so what can we promise current students looking for prospective places to work to gain some real experience? Well mainly just that, real work experience.

Interns with us on FIRE are treated as part of the team, with the opportunity to work the same cases and investigations as a normal full time employee. Its 3 months of real on the job training, no coffee runs or busy work. That includes helping the team on projects, threat hunting, and learning how to be an awesome investigator.

The intern program for me has always been less about what we can get from you, and more about how we can help empower you in your career going forward. Providing you a great experience and real transferable skills that can help you get a start in your career.

Additionally we promise you a voice, all thoughts and ideas are welcome with us and if we hire you we want to hear from you. We want you to bring all the things you have learned with you to make us better, while we teach you things to make you better!

Outside of the work we also have a pretty robust security intern program, this includes intern only QA sessions with all our security Sr. Leaders, including @seanzadig our wonderful CISO, time to explore other teams and learn what they do, and some fun events along the way.

Lastly you'll get to the opportunity to work with 2 of the best managers in the space (in my opinion) and one of the best IR teams out there. At the end of the 3 months not only be confident in your ability, but have some connections to help you after school in the job market.

We look forward to meeting those of you who apply this year!

Forensics and Incident Response (FIRE) Operations Analyst Intern

Yahoo is a global media and tech company that connects people to their passions. We reach nearly 900M people around the world, bringing them closer to what they love—from finance and sports, to shopping, gaming and news—with the trusted products, content and tech that fuel their day. For partners, we provide a full-stack platform for businesses to amplify growth and drive more meaningful connections across advertising, search and media. #yahoo It takes powerful technology to connect our brands and partners with an audience of nearly 900 million. Whether you’re looking to write mobile app code, engineer the servers behind our massive ad tech stacks, or develop algorithms to help us process trillions of data points a day, what you do here will have a huge impact on our business—and the world. Want in? It takes powerful technology to connect our brands and partners with an audience of nearly 900 million. Whether you’re looking to write mobile app code, engineer the servers behind our massive ad tech stacks, or develop algorithms to help us process trillions of data points a day, what you do here will have a huge impact on our business—and the world. Want in? About our team: When you impact millions of people every day, you become a large target for adversaries of all types within all layers of the stack. Our job is to keep our users safe and make Yahoo one of the safest places on the Internet. We are the information security team at Yahoo; known as \"The Paranoids\". As part of the Paranoids Forensics and Incident Response Operations Team (FIRE), we protect Yahoo and its users from dedicated adversaries, working on the front lines monitoring for, hunting for, and responding to threats, we ensure that our users and company are kept safe. You are a highly motivated security analyst who will use Yahoo internal tools and other systems to detect and respond to security events. You are interested in protecting sensitive corporate and user data from unauthorized access at Internet scale and applying advanced technical, behavioral, and investigative solutions to find evil, ensuring that Yahoo data remains secure. During your time here we will: Enable you to stop advanced attackers and protect our users Encourage you to follow the investigation through till the end Challenge you to push the bounds of our security program and your own talents Responsibilities Monitor and analyze security events from networks, applications, hosts, and databases Perform proactive research and identification of security anomalies Participate in regular threat hunting exercises Assess security incidents and assist Yahoo business units to remediate issues Work with a variety of security technologies including IDS, firewalls, EDR, etc Contribute to the overall security posture of Yahoo Work to tune signatures and develop new use cases for finding badness Evaluate new log sources for security detection value and develop potential use cases Continue to focus on process improvement including developing playbooks Work on special projects as needed Requirements Background in security fundamentals including network and host forensics, log analysis, and basic malware triage A passion for the field of information security and incident response. Understanding of common network services (web, mail, FTP, etc), network vulnerabilities, and attack patterns Desired Experience with Splunk Security Information and Event Monitoring (SIEM) solution Experience in shell scripting, Python, or similar tool and automation languages Yahoo is proud to be an equal opportunity workplace. All qualified applicants will receive consideration for employment without regard to, and will not be discriminated against based on age, race, gender, color, religion, national origin, sexual orientation, gender identity, veteran status, disability or any other protected category. Yahoo is dedicated to providing an accessible environment for all candidates during the application process and for employees during their employment. If you need accessibility assistance and/or a reasonable accommodation due to a disability, please submit a request via the Accommodation Request Form (www.yahooinc.com/careers/contact-us.html) or call 408-336-1409. Requests and calls received for non-disability related issues, such as following up on an application, will not receive a response. At Yahoo, we know that diversity makes us stronger. We are committed to a collaborative, inclusive environment that encourages authenticity and fosters a sense of belonging. We strive for everyone to feel valued, connected, and empowered to reach their potential and contribute their best. Check out our diversity and inclusion (www.yahooinc.com/diversity/) page to learn more. US Only: Please be aware that Yahoo requires all employees entering a U.S. Yahoo office and/or attending a company event (including client events) are required to be vaccinated for COVID-19. This position will require the successful candidate to obtain and show proof of a vaccination to enter a U.S. Yahoo office and/or attending a company event (including client events). Yahoo is an equal opportunity employer, and will provide reasonable accommodation to those individuals who are unable to be vaccinated consistent with federal, state, and local law. The compensation for this position ranges from $45,760.00 - $135,200.00/yr and will vary depending on factors such as your location, skills and experience. The compensation package may also include incentive compensation opportunities in the form of discretionary annual bonus or commissions, in addition to equity incentives. Yahoo provides industry-leading benefits including healthcare, 401K savings plan, company holidays, vacation, sick time, parental leave and an employee assistance program. Currently work for Yahoo? Please apply on our internal career site.

@SheHacksPurple Thats a good life right there!
@jp_callahan @seanzadig honestly I am not sure. I'll look into this thanks @jp_callahan!