10 дней назад
Cyber Security Incidence Response Lead
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cyber Security Incidence Response Lead (Cybersecurity/Incident Response): Leading complex enterprise cybersecurity investigations across endpoint, identity, cloud, network, email, and security telemetry with an accent on containment, eradication, root-cause analysis, and cross-functional coordination. Focus on threat hunting, insider-risk investigations, incident-response program maturity, detection engineering, automation, and senior on-call escalation.
Location: Onsite at the Framingham, Massachusetts facility; candidates may relocate to the area, with relocation assistance potentially available.
Company
Digital Solutions strengthens ’ cyber defense capabilities and protects associates, customers, data, and enterprise technology.
What you will do
- Lead complex cybersecurity investigations from escalation through containment, eradication, recovery, and post-incident review.
- Analyze endpoint, identity, cloud, network, email, and log-based telemetry to determine attacker activity, scope, root cause, and business impact.
- Provide senior technical guidance and coordinate response activities across security, infrastructure, cloud, identity, legal, privacy, risk, human resources, and business teams.
- Develop and improve incident response plans, procedures, playbooks, exercises, metrics, documentation, and escalation processes.
- Conduct proactive threat hunting and insider-risk investigations involving suspicious behavior, access misuse, data loss, or malicious internal activity.
- Partner with detection engineering, threat intelligence, and security technology teams to improve detection coverage, investigation capabilities, and automation; participate in an on-call escalation rotation.
Requirements
- Onsite work at the Framingham, Massachusetts facility is required.
- Bachelor’s degree in computer science, information security, a related field, or equivalent work experience.
- 7+ years of cybersecurity experience, including incident response, digital forensics, threat hunting, detection engineering, or security operations.
- Experience conducting complex investigations in large enterprise environments and developing incident response plans, playbooks, exercises, metrics, or related processes.
- Experience with post-incident reviews, root-cause analysis, lessons-learned documentation, and cross-functional technical response coordination.
- Ability to make sound technical recommendations, communicate business risk clearly, and participate in an on-call escalation rotation.
Nice to have
- Cybersecurity certifications or advanced training such as GCIH, GCFA, GCFE, GNFA, or CISSP.
- Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Endpoint, Microsoft Entra ID, SIEM, EDR/XDR, SOAR, or security automation.
- Experience with enterprise threat hunting, detection content, identity- or cloud-based attacks, insider risk, data loss, ransomware, credential compromise, business email compromise, or supply-chain incidents.
- Experience in large distributed, retail, or e-commerce environments and knowledge of PCI DSS and applicable privacy requirements.
Culture & Benefits
- Inclusive culture with associate-led Business Resource Groups.
- 22 days of paid time off plus 7 observed paid holidays and 1 floating holiday.
- Company-match 401(k) plan.
- Physical and mental health wellness programs.
- Online and retail discounts.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
Principal Cybersecurity Engineer (AI)
184 800 - 277 200$
10 дней назад
Endpoint Security Engineer (SentinelOne)
120 000 - 140 000$
10 дней назад
Sr. Manager, Security Engineering (Cybersecurity)
145 750 - 204 400$
14 дней назад
Product Champion (Cybersecurity)
144 501 - 190 000$
10 дней назад
Director of Security Operations (Cybersecurity)
10 дней назад
Security Engineer III (Cybersecurity)
152 200 - 228 400$