10+ years of cybersecurity experience, including 2-5 years in T3 incident response focusing on system compromise analysis.
Proficient in conducting security reviews and vulnerability risk assessments using both manual and automated tools.
Familiarity with enterprise security solutions and incident crisis management.
Experience in performing attack simulations for training security teams.
Skilled in creating documented procedures and plans for security operations.
Willingness to participate in an on-call rotation, including weekends.
Must be eligible to work in the US without employer sponsorship.
Responsibilities
Manage daily incident response for customer incidents.
Conduct forensic analysis of compromised systems and recommend remediation steps.
Direct and prioritize incident response efforts, creating clear reports on compromises.
Oversee complex global incidents and perform large-scale compromise assessments.
Develop incident response plans and training playbooks.
Create attack scenarios for customer tabletop exercises.
Build and maintain sandbox environments for evaluating malicious code.
Benefits
Opportunity to work on high-impact global incidents.
Engagement in advanced incident response and forensic analysis.
Collaboration with a skilled team in a dynamic environment.
Exposure to a variety of enterprise security solutions and practices.
Potential for professional growth through training and incident simulations.
Full Job Description
Job Description
Responsible for daily incident management of customer incidents
Perform incident response and forensic analysis of compromised systems, identify and provide recommendations for remediation
Formulate and direct incident response efforts, prioritize those response efforts, and create legible incident reports that describe the compromise vector, attacker methodologies and artifacts
Ability to manage complicated global incidents
Ability to perform large-scale compromise assessments for customer environments
Build incident response plans and playbooks
Create attack scenarios for customer tabletop training exercises
Creation of detailed incident reports for customers and effective communication of findings to customers
Build and maintain sandbox/test lab environments to evaluate malicious code
Work within a team environment and will be responsible for coordinating work actions
Qualifications
This is not an entry level SOC role.
10+ years of cybersecurity experience out of which 2-5 years are experience performing T3 incident response with an emphasis on system compromise analysis.
Experience of performing security reviews/vulnerability risk assessments of network environments using both manual procedures and automated analysis tools.
Experience with enterprise security solutions, incident crisis management.
Experience with performing attack simulation for training security teams.
Experience with creating procedures and documented plans for security teams.
Ability to participate in on-call rotation, including at least one weekend a month.
Domestic and International travel may be required.
Must be eligible to work in the US without sponsorship from an employer now or in the future.