TL;DR
Senior Cyber Defense Analyst (Cybersecurity): Monitoring, investigating, and responding to security alerts across cloud, endpoint, identity, and application layers with an accent on real-time threat protection and incident ownership. Focus on critical thinking, relentless automation, and end-to-end incident management in a hybrid environment.
Location: Remote - USA
Salary: $144,500–$170,000 USD
Company
hirify.global is an AI-driven cybersecurity company focused on protecting hybrid environments from threats.
What you will do
- Monitor, triage, and correlate security alerts from SIEM, EDR, IAM, CSPM, and CDR tools.
- Lead containment, eradication, and recovery for endpoint, cloud, and identity incidents.
- Proactively hunt for threats using MITRE ATT&CK and investigate anomalies across various telemetry sources.
- Build or enhance SOAR playbooks and create custom automation scripts.
- Track and report operational metrics (MTTD, MTTR) and maintain documentation.
Requirements
- 5-7 years of hands-on SOC or Incident Response experience in a cloud-first or hybrid environment.
- Strong understanding of attacker lifecycle, MITRE ATT&CK, and threat actor TTPs.
- Experience with EDR (CrowdStrike preferred), SIEM (Splunk preferred), and SOAR (Torq, XSOAR, or Phantom).
- Familiarity with AWS, Okta, and SaaS platforms.
- Proficiency in writing queries and automations using Python, Bash, or SPL.
- Excellent analytical, investigative, documentation, and communication skills.
Nice to have
- Experience with CSPM/CDR/VM tools.
- Knowledge of Containers and Kubernetes security.
- Relevant certifications (CEH, Security+, GCIH, GCIA, or AWS Security Specialty).
Culture & Benefits
- Individual compensation packages include bonus, restricted stock units (RSUs), and benefits.
- hirify.global is an equal opportunity employer.
- Hiring practices include video interviews and pre-employment checks aligned with security and privacy standards.
- Commitment to protecting applicant privacy.
Будьте осторожны: если вас просят войти в iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →