TL;DR
Incident Response Analyst (Cybersecurity): Supports the Incident Response lifecycle via triage and investigation of detections with an accent on front-line analysis and escalation of cybercrime and APT activity. Focus on developing detection criteria across a broad range of technologies and log sources to drive efficient process development and documentation.
Location: Remote (Must be a US citizen or Green Card holder and currently residing in the US)
Company
hirify.global is a global cybersecurity leader dedicated to protecting people, processes, and technologies with its AI-native platform.
What you will do
- Support Incident Response lifecycle through triage and investigation of detections.
- Develop detection criteria across a range of technologies and log sources.
- Identify coverage and efficiency gaps in available data and tooling.
- Provide information security reporting and security metrics.
- Participate in incident response and manage escalations as needed.
- Drive efficient process development and documentation for all aspects of the Incident Response lifecycle.
Requirements
- Experience responding to security events, including front-line analysis and escalation.
- Theoretical and practical knowledge with Mac, Linux, and Windows operating systems.
- Theoretical and practical knowledge with TCP/IP networking and application layers.
- Experience with security data collection, processing, and correlation.
- Must meet DoD SkillBridge Qualifications and be a current Active Duty Service Member.
- Must be a US citizen or Green Card holder.
Nice to have
- Scripting experience (Python, Perl, Bash, Power Shell, etc.).
- Experienced user of Splunk.
- Experience with host and network forensics.
- Experience with basic static and behavioral malware analysis.
- Previous project management experience desirable.
Culture & Benefits
- Committed to fostering a culture of belonging where everyone is valued and empowered.
- Supports veterans and individuals with disabilities through an affirmative action program.
- Proud to be an equal opportunity employer, not discriminating on the basis of race, color, creed, ethnicity, religion, sex, or other legally protected characteristics.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →