Назад
Company hidden
4 дня назад

Incident Response Analyst (Cybersecurity)

140 000 - 160 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Incident Response Analyst (Cybersecurity) (SIEM/SOAR, Cloud Security, AI): Investigating, containing, and resolving cybersecurity incidents across endpoint, identity, network, cloud, SaaS, email, application, and data environments with an accent on threat detection, digital forensics, and automation-first SOC operations. Focus on correlating multi-platform telemetry, developing detection logic and response playbooks, automating investigations with scripting and APIs, and improving detection and response capabilities.

Location: Washington, DC; in-office 4 days per week

Salary: $140,000–$160,000 base salary annually, plus potential discretionary annual incentive and benefits.

Company

Global investment firm managing private market investments across private equity, credit, and AlpInvest.

What you will do

  • Investigate, document, contain, remediate, and coordinate cybersecurity incidents across endpoint, identity, network, cloud, SaaS, email, application, and data environments.
  • Handle escalated events from a Tier 1 MSSP and correlate SIEM, XDR, EDR, identity, network, cloud, email, and data protection telemetry.
  • Develop, test, and tune detection logic, correlation rules, analytics, queries, and behavioral detections.
  • Automate alert enrichment, evidence collection, investigation, case management, containment, and remediation using scripting, APIs, orchestration, and AI-assisted security technologies.
  • Develop and maintain incident response playbooks, operational metrics, reporting, and continuous-improvement initiatives.
  • Perform threat hunting, share technical findings, mentor analysts, and collaborate with security engineering, threat intelligence, identity, cloud, infrastructure, and application security teams.

Requirements

  • Four-year college degree or equivalent relevant experience.
  • At least 5 years of overall IT experience and 3 years of IT security operations and incident response experience.
  • Strong knowledge of incident response methodologies, digital forensics, evidence collection, root-cause analysis, and cloud security practices.
  • Proficiency with SOAR platforms, including Palo Alto XSIAM, and SIEM tools.
  • Proficiency with AWS or Azure; familiarity with Terraform or CloudFormation.
  • Experience with Python, Bash, or PowerShell, endpoint security, network security, Windows, Linux, and macOS.

Nice to have

  • GCIH, SANS, CISSP, or CCSP certification.
  • Knowledge of financial services and alternative asset management.

Culture & Benefits

  • Retirement benefits, health insurance, life insurance, and disability coverage.
  • Paid time off and paid holidays.
  • Family planning benefits and wellness programs.
  • Potential eligibility for an annual discretionary incentive program based on individual and organizational performance.
  • Opportunities for technical research, training, professional development, and participation in an evolving Security Operations Center.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →