4 дня назад
Incident Response Analyst (Cybersecurity)
140 000 - 160 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Incident Response Analyst (Cybersecurity) (SIEM/SOAR, Cloud Security, AI): Investigating, containing, and resolving cybersecurity incidents across endpoint, identity, network, cloud, SaaS, email, application, and data environments with an accent on threat detection, digital forensics, and automation-first SOC operations. Focus on correlating multi-platform telemetry, developing detection logic and response playbooks, automating investigations with scripting and APIs, and improving detection and response capabilities.
Location: Washington, DC; in-office 4 days per week
Salary: $140,000–$160,000 base salary annually, plus potential discretionary annual incentive and benefits.
Company
Global investment firm managing private market investments across private equity, credit, and AlpInvest.
What you will do
- Investigate, document, contain, remediate, and coordinate cybersecurity incidents across endpoint, identity, network, cloud, SaaS, email, application, and data environments.
- Handle escalated events from a Tier 1 MSSP and correlate SIEM, XDR, EDR, identity, network, cloud, email, and data protection telemetry.
- Develop, test, and tune detection logic, correlation rules, analytics, queries, and behavioral detections.
- Automate alert enrichment, evidence collection, investigation, case management, containment, and remediation using scripting, APIs, orchestration, and AI-assisted security technologies.
- Develop and maintain incident response playbooks, operational metrics, reporting, and continuous-improvement initiatives.
- Perform threat hunting, share technical findings, mentor analysts, and collaborate with security engineering, threat intelligence, identity, cloud, infrastructure, and application security teams.
Requirements
- Four-year college degree or equivalent relevant experience.
- At least 5 years of overall IT experience and 3 years of IT security operations and incident response experience.
- Strong knowledge of incident response methodologies, digital forensics, evidence collection, root-cause analysis, and cloud security practices.
- Proficiency with SOAR platforms, including Palo Alto XSIAM, and SIEM tools.
- Proficiency with AWS or Azure; familiarity with Terraform or CloudFormation.
- Experience with Python, Bash, or PowerShell, endpoint security, network security, Windows, Linux, and macOS.
Nice to have
- GCIH, SANS, CISSP, or CCSP certification.
- Knowledge of financial services and alternative asset management.
Culture & Benefits
- Retirement benefits, health insurance, life insurance, and disability coverage.
- Paid time off and paid holidays.
- Family planning benefits and wellness programs.
- Potential eligibility for an annual discretionary incentive program based on individual and organizational performance.
- Opportunities for technical research, training, professional development, and participation in an evolving Security Operations Center.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Security Engineer, Level 5, Detection & Response (Cybersecurity)
178 000 - 313 000$
7 дней назад
Manager / Sr. Manager, SecOps & Cyber Defense
185 000 - 235 000$
6 дней назад
SOC Lead (Cybersecurity)
96 086 - 111 683$
6 дней назад
Senior Detection and Response Engineer
200 000 - 240 000$
7 дней назад
Senior Manager, Cybersecurity (AI)
216 000 - 324 000$
5 дней назад
Senior Security Operations Analyst III (Cybersecurity)
145 000 - 170 000$