3 дня назад
Threat Analyst 2 (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Threat Analyst 2 (Cybersecurity): Investigating and responding to security events across MDR customer environments with an accent on threat hunting, endpoint and network analysis, and customer-facing incident resolution. Focus on analyzing Windows event logs, researching indicators of compromise and vulnerabilities, and improving 24/7 security operations.
Location: Remote within the United Kingdom; applicants must have legal authorization to work in the United Kingdom without employer sponsorship.
Company
provides AI-driven cybersecurity technologies and managed detection and response services for organizations worldwide.
What you will do
- Investigate logs and security events using tooling and enterprise endpoint collection systems.
- Handle escalations from Tier I analysts and advise on investigation procedures.
- Conduct threat hunting across MDR customer environments and research indicators of compromise, exploits, and vulnerabilities.
- Create cases, communicate findings to technical and executive audiences, and support customers through threat neutralization and issue resolution.
- Collaborate with security, threat response, engineering, and ethical hacking teams.
- Contribute to security operations process improvements, reporting, and threat trend analysis.
Requirements
- At least 2 years of experience in a SOC environment or computer security team.
- Experience with endpoint and network security, including IDS, IPS, EDR, ATP, malware defenses, and monitoring.
- Experience with threat hunting, incident response procedures, Windows administration, and Windows event log analysis.
- Knowledge of TCP/IP, routing, switching, network protocols, and common adversary tactics and techniques.
- Working knowledge of Windows and either Apple or Linux-based operating systems.
- Bachelor’s degree in Information Technology, Computer Science, or a related field, or equivalent experience; strong analytical, troubleshooting, communication, and customer service skills.
Nice to have
- Knowledge of the MITRE ATT&CK framework.
- SQL query construction and OSQuery experience.
- PowerShell scripting and enterprise SIEM or information security data management experience.
- Advanced cybersecurity certifications.
Culture & Benefits
- Remote-first working model.
- Opportunity to work in a 24/7/365 managed detection and response service, including some weekends and holidays.
- Diversity and inclusion networks, community volunteering, and sustainability initiatives.
- Wellbeing days, fitness and trivia competitions, and monthly health and wellbeing webinars.
- Team-oriented environment with opportunities to contribute to cybersecurity innovation and continuous improvement.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →