Назад
Company hidden
4 дня назад

Cyber Defense Analyst III (AI)

103 500 - 172 500$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Defense Analyst III (AI): Monitoring and validating complex security threats across network, host, identity, and GCP telemetry with an accent on automation, detection engineering, and AI-assisted triage. Focus on building Python scripts and SOAR playbooks, operationalizing Detection-as-Code with Git and CI/CD, and conducting hypothesis-driven threat hunts.

Location: Chicago - 20 S. Wacker

Salary: $103,500–$172,500 per year, plus an annual target bonus and equity opportunity.

Company

hirify.global operates a global derivatives marketplace and develops financial market infrastructure.

What you will do

  • Analyze and validate complex security events across network, host, identity, and GCP telemetry.
  • Provide enriched and validated alerts for the Incident Response team.
  • Automate repetitive SOC activities with Python scripts, PowerShell, and SOAR playbooks.
  • Develop, test, tune, and deploy SIEM detection rules using Git and CI/CD workflows.
  • Test and refine AI-assisted and agentic triage workflows with engineering and automation teams.
  • Conduct threat hunts, operationalize threat intelligence, mentor junior analysts, and document monitoring processes.

Requirements

  • 4–6 years of experience in a SOC, detection engineering, or advanced cyber defense monitoring environment.
  • Strong knowledge of network protocols, Windows, Linux, macOS, and the MITRE ATT&CK framework.
  • Practical Python or PowerShell experience with REST APIs, JSON/XML parsing, and monitoring automation.
  • Hands-on experience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Torq, or Tines.
  • Experience with cloud environments, preferably GCP or AWS, including cloud telemetry and identity abuse investigations.
  • BA/BS in Computer Science, Information Security, Engineering, or a related field, or equivalent experience and certifications.

Nice to have

  • SANS GCIA, GCFA, GCDA, SEC573, or AWS/GCP security certifications.
  • Experience or strong interest in Detection-as-Code, CI/CD, and testing LLM prompts for security investigations.

Culture & Benefits

  • Annual target bonus opportunity and broad-based equity program.
  • Comprehensive health coverage and a retirement package with a 401(k) and pension plan.
  • Paid time off, education reimbursement, and mental health benefits.
  • Collaborative environment focused on continuous learning, critical thinking, and automation.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →