SOC Analyst & Incident Response Lead
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
SOC Analyst & Incident Response Lead (Cybersecurity): Managing critical security events, conducting forensic investigations, and enhancing the incident response program with an accent on Tier 3 analysis, malware reverse engineering, and threat intelligence correlation. Focus on leading end-to-end incident response, root cause analysis, and optimizing detection use cases for emerging threats.
Hybrid in Texas, US. Must be authorized to work in the United States without visa sponsorship.
Salary: $93,000–$125,500 + bonus potential + benefits
Company
Enterprise software leader that unifies customer experiences through the Infinity platform.
What you will do
- Act as escalation point for complex security incidents using Azure Sentinel and other tools.
- Conduct forensic investigations across endpoints, networks, and cloud (Azure, M365).
- Perform malware analysis, reverse engineering, and memory/disk forensics.
- Lead end-to-end incident response, including containment, eradication, and recovery.
- Collaborate on detection engineering, threat intelligence, and playbook maintenance.
- Facilitate post-incident reviews and executive reporting.
Requirements
- 5+ years in SOC or Incident Response, including leading major incidents (ransomware, APT).
- Strong forensic skills (disk, memory, log, network).
- Advanced proficiency in SIEM (Microsoft Sentinel), EDR (Defender), scripting (PowerShell, Python).
- Knowledge of MITRE ATT&CK, TTPs, cloud (Azure), networks, OS.
- Available to work outside regular hours.
- Must be authorized to work in the US without sponsorship.
Nice to have
- GIAC GCFA, GCIH, CISSP, OSCP, or Microsoft certs (SC-200, SC-300, AZ-500).
Culture & Benefits
- Community-focused environment valuing contributions and growth.
- Strong connections with team, work, and mission.
- Competitive pay range with bonus and benefits.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →