1 день назад
Senior Incident Response Analyst (CrowdStrike)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Incident Response Analyst (CrowdStrike): Owning tier-1 and tier-2 security incidents and conducting host, memory, network, cloud, and identity forensic investigations with an accent on evidence handling, EDR/SIEM analysis, and healthcare data protection. Focus on reconstructing incident timelines, exercising containment authority, authoring IR playbooks, and automating or AI-assisting triage and evidence collection.
Location: United States — Remote
Company
provides telehealth support solutions that help companies deliver virtual patient care across all 50 states.
What you will do
- Own tier-1 and tier-2 incidents through detection validation, triage, scoping, containment, eradication, recovery, and post-incident review.
- Conduct host, memory, network, cloud, and identity forensic investigations with defensible evidence handling.
- Investigate EDR and SIEM telemetry, write queries, build correlation logic, and reconstruct incident timelines.
- Participate in the IR on-call rotation and exercise authorized containment actions such as host isolation and session revocation.
- Author and update incident-response playbooks and track post-incident findings to closure.
- Automate or AI-assist repetitive triage and evidence-collection work while producing technical timelines and executive summaries.
Requirements
- 6–8 years of hands-on security experience, primarily in incident response and/or digital forensics.
- Demonstrated ownership of the full incident lifecycle and independent investigations across host/disk, memory, network, cloud, and identity environments.
- Working depth with EDR/EPP and SIEM platforms, including endpoint response, query authoring, correlation logic, and timeline reconstruction.
- Hands-on fluency with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, EnCase, FTK, X-Ways, plaso, Zeek, or Wireshark.
- Knowledge of evidence handling, chain of custody, MITRE ATT&CK, and investigation scripting with Python, PowerShell, or similar.
- Demonstrated use of AI tools in security work, sound judgment regarding sensitive data, clear incident writing, and willingness to join the shared on-call rotation.
Nice to have
- CrowdStrike Falcon EDR, Falcon Next-Gen SIEM, and Falcon Shield experience.
- AWS incident response using CloudTrail, GuardDuty, and IAM investigation techniques.
- Okta identity investigations involving session hijacking, MFA fatigue, token theft, or SSO abuse.
- Healthcare, fintech, or other regulated-industry experience, including HIPAA, HITRUST, or SOC 2 breach workflows.
- Malware triage, SOAR or AI-assisted IR workflows, threat intelligence, IR program maturity, or relevant certifications and community contributions.
Culture & Benefits
- Remote work within the United States.
- Flat organizational structure with autonomy to contribute ideas and implement improvements.
- Medical, dental, and vision plans.
- Flexible Spending Accounts or Health Savings Accounts, flexible PTO, and a 401(k) with company match.
- Life insurance, pet insurance, and additional benefits.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Twilio
7 дней назад
Senior Security Engineer, Incident Response (AI)
141 520 - 176 900$
CrowdStrike
7 дней назад
Sr. Analyst, Falcon Complete (Cybersecurity)
6 дней назад
Senior Security Operations Analyst (Detection & Response)
117 800 - 166 950$
8 дней назад
Lead Security Analyst (Cybersecurity)
7 дней назад
Senior Security Analyst (Cybersecurity)
6 дней назад