Greg Carson

Threat Intelligence and Incident Response Lead @TMX Group

Toronto, ON, CA
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Mar 2018 — Present

Threat Intelligence and Incident Response Lead @TMX Group

View department →

Evaluate, POC, Implement and Manage Breach Attack Simulation (BAS) and integrate with use case development, threat intelligence and security operations programs• Advise senior leadership on SOC and Security Engineering roadmap (technology and process)• Evaluate, Implement and Manage Threat Intelligence Platform (TIP)• Curate and integrate third party Open-Source and commercial IOC streams with TIP• Integrate Threat Intelligence with appropriate tools in the security stack and develop use cases• Fine tune indicator streams and develop methodology reducing risk of intelligence based proactive blocking and streamlining intelligence based investigations• Evaluate, POC, Implement and Manage Endpoint Detection and Response (EDR) tool• Lead incident response and forensics activities acting as point of escalation for our L1/L2 analysts• Coordinate internal Threat Intelligence reporting• Lead Threat Hunting activities• Lead Continual Use Case Development workshops and contribute to hands-on SIEM and EDR use case development• Leverage IT services for introducing automation to SOC operations• Conduct annual tabletop exercises• Execute quarterly social engineering exercises• Assist in development of internal red team and purple team activities

EDUCATION

2007 — 2011

University of Ontario Institute of Technology

BIT, Specializations in Networking & IT Security

SKILLS

Endpoint SecurityNetworkingMcafeeRsa ArcherVulnerability ManagementDlpIncident HandlingFirewallsContent FilteringTcp/IpLinuxWeb Application SecurityIpsDefense in DepthNessusRsa SecurityVpnCheckpointTroubleshootingThe Kill ChainSiemNetwork SecurityRsa Security AnalyticsProject ManagementCisco TechnologiesSecuritySecurity+Security Operations CenterSecurity Architecture DesignPci DssPenetration TestingLog ManagementCehVmwareSystem AdministrationComputer SecurityNetwork ArchitectureProxyVulnerability AssessmentFirewall

ABOUT GREG CARSON

With over a decade of experience in Information Security I\'ve had the opportunity to work at a few great companies and tackle some big challenges. I\'ve met some incredibly brilliant and hard working people along the way who I like to think have made me smarter and more well informed. I believe that training, mentoring and a passion for continual learning are the keys to developing competency and confidence in Cybersecurity or any field. There are many niches within security and I\'ve had the opportunity to work in different areas which gives me a unique perspective and ability to solve an array of challenges in our industry. Some of these experiences include:• SOC Operations (Tier 1, Tier 2, Tier 3, Team Lead roles) and SOC Design• Technical Account Management• Security Operations policy development (Incident Response playbook, Incident Playbook development, incident triage and handling procedures, technology documentation)• Work for both MSSP and on In-House security teams• Penetration Testing and Red Team work in many countries (Metasploit, Kali, Nessus, Burp, Cobalt Strike, PhishMe, Empire, Bloodhound and other frameworks)• Conduct Purple team exercises (Mandiant Security Validation) & Create Tabletop Exercises• Manage and implement large SIEM deployment spanning multiple continents and assets logging• Incident Response and Forensics work across North America (FireEye HX, Crowdstrike Falcon, Sentinel One, enCase, Volatility, FTK Imager, Mandiant Redline)• Implement and Integrate Threat Intelligence Tools (Anomali, MISP)• Research (Primary and Secondary) and Coordinate Threat Hunting (MITRE and IOC based)• Lead security assessments (ISO 27001)• Find ways to continually push security messaging and evolve security tools and processes in organizationsI have strong communication skills and excel in; documenting architecture, creating procedures, and communicating risks to business.On the technology side I am familiar with a variety of SIEM, DLP, Firewall and EDR tools. In recent years I\'ve worked with QRadar, Splunk, RSA Netwitness, McAfee IPS, SNORT, Fortinet, FireEye HX, Crowdstrike, Anomali, and other tools. I\'ve also run proof of concepts for many other competing technologies.

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Greg Carson — Threat Intelligence and Incident Response Lead at TMX Group in Toronto, ON, CA | Unifers