Incident Responder
WHAT YOU WILL BE DOING- Incident Detection and Analysis:
- Lead the monitoring of security alerts and events from various sources including SIEM systems, IDS/IPS, firewalls, and endpoint security solutions.
- Perform initial triage, validation, and classification of incidents to determine the severity and potential impact.
- Conduct in-depth analysis of security incidents to identify the root cause and understand the attack vectors.
- Incident Response and Remediation:
- Respond promptly to cybersecurity incidents following established incident response procedures.
- Contain and eradicate threats by isolating affected systems, removing malicious artifacts, and applying necessary patches or configurations.
- Coordinate with IT and other relevant teams to ensure effective incident resolution and system recovery.
- Forensic Investigation:
- Lead and conduct digital forensic investigations to collect and preserve evidence related to security incidents.
- Analyze compromised systems, network traffic, and log files to reconstruct attack timelines and identify indicators of compromise (IOCs).
- Prepare detailed incident reports and documentation for internal use and regulatory compliance.
- Continuous Improvement:
- Participate in post-incident reviews to identify lessons learned and recommend improvements to incident response processes and security controls.
- Stay current with the latest cybersecurity threats, vulnerabilities, and attack techniques to enhance response capabilities.
- Contribute to the development and maintenance of incident response playbooks, runbooks, and standard operating procedures.
- Collaboration and Communication:
- Work closely with other security team members, IT staff, and business units to ensure a coordinated and effective response to incidents.
- Provide timely and clear communication to stakeholders regarding the status and impact of incidents.
- Assist in conducting security awareness training and exercises to improve the organization's overall security posture.
WHAT WE NEED FROM YOUMust-Have Qualifications:- Bachelor's degree in Cybersecurity, Information Security, Computer Science, or related field
- 3-5 years of experience in incident response, digital forensics, and cybersecurity operations
- Strong understanding of network protocols, operating systems, and security technologies.
- Prior experience mentoring others
- Proven experience with security information and event management (SIEM) tools, intrusion detection/prevention systems (IDS/IPS), and endpoint security solutions.
- Strong analytical and problem-solving skills, with a proactive and self-starter mindset.
- Excellent communication and interpersonal skills, with the ability to work effectively in a fast-paced environment and manage multiple priorities.
- Commitment to continuous improvement and staying current with the latest security trends and best practices.
- Ability to work 100% on-site in Pontiac, MI
Nice to Have Qualifications: - Relevant certifications (e.g., CISSP, CISM, CEH, GCIH)
THE PLACE & THE PERKSMore reasons you'll love working here include:
- Paid Time Off (PTO) after just 30 days
- Additional parental and maternity leave benefits after 12 months
- Adoption reimbursement program
- Paid volunteer hours
- Paid training and career development
- Medical, dental, vision and life insurance
- 401k with employer match
- Mortgage discount and area business discounts
- Free membership to our large, state-of-the-art fitness center, including exercise classes such as yoga and Zumba, various sports leagues and a full-size basketball court
- Wellness area, including an in-house primary-care physician's office, full-time massage therapist and hair salon
- Gourmet cafeteria featuring homemade breakfast and lunch
- Convenience store featuring healthy grab-and-go snacks
- In-house Starbucks and Dunkin
- Indoor/outdoor café with Wi-Fi