Related Posts
Alvarez & Marsal Hey everyone, I have a Turnaround and Restructuring Consultant interview coming up soon at Alixpartners. It’s the second round of interviews with a Director and Managing Director. Any tips/help would be greatly appreciated. Thanks EY PwC AlixPartners FTI Consulting Deloitte Alvarez & Marsal
Had a bad showing for case interview about a month ago. I knew the material i just straight up had a bad day. Took feedback in exit interview and feel prepared to reapply for a different role with no cool off time… should I still wait or shoot my shot?
Asking as I am curious if my app will be flagged as I just applied to another role recently.EY-Parthenon
More Posts
Great idea! 👏
DOGE to the moon?
Been a great year for games. What was your fave?
Anyone interested in Theo v2?

Additional Posts in Cyber Security Bowl
Anyone working in Pharma industry?
Best prep material for cissp?
Any tripwire pros here? How did you get started?
New to Fishbowl?
unlock all discussions on Fishbowl.



Do you have any more details on the job description?
You can reference the NIST or SANS Incident Response frameworks (https://cybersecurity.att.com/blogs/security-essentials/incident-response-steps-comparison-guide)
Also some companies say “IR” but really mean security operations.
You may need to know more about digital forensics/windows artifacts. Is the role entry level?
Mentor
If you're unfamiliar with Splunk and SIEM technologies - do the free Splunk fundamentals course on their website. TryHackMe.com has some blue team rooms that could be helpful.
It does all depend on the role though - EY1 is absolutely right that "IR" usually means SOC. With SOC work, SIEM is vital, but also knowing what types of vulnerabilities are out there, basic networking (what port is what), etc. If it's a legitimate threat hunting role - go deep into offensive. The best threat hunters think like the attackers and need to know the entire Kill Chain, MITRE ATT@CK (hot topic), pivot techniques, standard processes and their behaviors, powershell, bash, etc. I'd argue that threat hunters are the blue team rockstars - the defensive equivalent of your penetration testers - they need to know a lot and be extraordinarily competent.
You might also get into digital forensics depending on the role (more actual IR). If you have the extra money - Autopsy has a great foundations course on using their software that provides a lot of insight to artifact discovery as well as hands-on experience working with a great forensics tool.
Get familiar with stride and other threat modeling frameworks
Community Builder
owasp threats