You have deep expertise across operating systems, including Windows, Linux, and macOS, and are highly proficient with multiple cloud platforms like AWS, Azure, and GCP. Your hands-on experience with security controls such as EDRs and IPS devices makes you a strong technical leader. You also bring experience in computer forensics and malware analysis, along with prior SIEM/SOAR experience or security monitoring and response training.
Your in-depth knowledge of cybersecurity and IT security ranging from understanding risks and threats to implementing prevention measures equips you to analyze and secure complex systems. You are skilled in networking and network security, proficient in network monitoring and protocols, and have a strong understanding of security standards and best practices. Your technical capabilities extend to Python programming, scripting, and the analysis of phishing and malware techniques.
You thrive in agile environments, making informed decisions quickly, and excel at communicating complex ideas, whether in writing, speaking, or presenting.
What you ll do:
Key responsibilities of the role:
Triage Information Security events from multiple sources, including EDR, IPS, proxies, firewalls, employee reports, etc., to identify potential cybersecurity incidents. Use in-depth research to inform the company s resolution process.
Collect and analyze raw events/alerts and construct timelines surrounding adversarial activities.
Respond to Information Security incidents by applying containment and eradication strategies.
Manage, lead, and provide guidance on active incidents.
Communicate incident updates to management and key stakeholders.
Drive innovation and improve fidelity of alerting by identifying opportunities in new technologies, capabilities, processes, and procedures.
Partner with offensive security teams to address shortcomings in the layered defense, including actively participating in purple teaming exercises.
Mentor and train other cybersecurity analysts.
What you need to bring:
Education & Experience Requirements:
Bachelor s degree (or equivalent work experience) required, preferably in computer science, engineering, or a related area of study.
Typically, 6+ years of relevant experience (Information Security operations / Incident Response)
Hands on experience in detecting, responding to, containing, and remediating live security incidents is essential.