обновлено 8 дней назад
Cybersecurity Incident Response Specialist
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cybersecurity Incident Response Specialist (Elastic/CrowdStrike/GCP): Leading incident response for government-compliant and commercial environments, including monitoring, triage, threat hunting, malware analysis, and security gap remediation with an accent on FedRAMP, CONUS, and NIST compliance. Focus on analyzing web application logs, conducting network forensics and reverse engineering, and coordinating high-priority incidents across internal teams, customers, and law enforcement.
Location: Atlanta, Georgia, USA, or remote within the United States; hybrid if Atlanta-based. Candidates must have continuously resided in the continental United States for at least three years immediately preceding application.
Company
develops IoT, connected transportation, fleet management, web analytics, and machine-learning solutions for commercial vehicles.
What you will do
- Own incident response operations for government compliance environments, including FedRAMP and CONUS environments.
- Monitor, triage, investigate, and track security incidents affecting systems, networks, products, and customers.
- Analyze web application logs and conduct security audits, risk analysis, network forensics, penetration testing, malware analysis, and reverse engineering.
- Lead threat hunts and strategic incident-response projects during lower-incident periods.
- Develop security gap assessments, policies, procedures, playbooks, training, and tabletop exercises.
- Coordinate incident communications with customers, internal stakeholders, leadership, and law enforcement, and provide SME guidance during remediation.
Requirements
- Post-secondary diploma or degree in Computer Science, Engineering, or a related field.
- 3–5 years of experience in incident response or security operations.
- Hands-on experience with Elastic, CrowdStrike, and SQL; scripting proficiency in Python, PowerShell, and Bash.
- Experience with GCP; familiarity with AWS, Azure, Oracle Cloud, Splunk, or QRadar is beneficial.
- Strong investigative, communication, and independent execution skills, with willingness to participate in an on-call rotation.
- Ability to pass an enhanced background check and provide documentation of continuous lawful US residency; some exceptions apply to US citizens.
Nice to have
- CCSP certification.
- CISSP or SANS certifications.
Culture & Benefits
- Flexible hybrid working model supporting in-person and virtual work.
- Home office reimbursement and cloud-based collaboration tools.
- Medical and dental benefits, retirement savings program, and parental leave top-up.
- Online learning and networking opportunities.
- Electric vehicle purchase incentive program.
- Benefits are offered to full-time permanent employees only.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
EDR Engineer / Senior EDR Engineer (Cybersecurity)
78 500 - 117 500$
14 дней назад
Security Analyst (Cybersecurity)
50 - 65$
11 дней назад
Senior Manager, Security Engineering and Operations (Cybersecurity)
146 400 - 219 600$
14 дней назад
Associate Solution Consultant – Security Incident Handler (Cybersecurity)
10 дней назад
Cyber Detection Event Analyst
CrowdStrike
13 дней назад
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis) (Cybersecurity)
85 000 - 120 000$