Cybersecurity Incident Response Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Cybersecurity Incident Response Analyst: Managing end-to-end triage and closure of security events with an accent on threat hunting, forensics, and incident response. Focus on designing playbooks, implementing detection capabilities, and ensuring the effectiveness of technical security controls within a global, cloud-integrated environment.
Location: Must be based in Los Angeles, CA
Company
is a leading entertainment and sports agency with a highly collaborative, service-oriented culture.
What you will do
- Conduct daily incident response and SOC-related detection activities.
- Design, engineer, and implement incident response runbooks and playbooks.
- Perform host, cloud, network, memory, and log forensics to support investigations.
- Coordinate with technical and business stakeholders throughout the incident lifecycle.
- Review security logs and reports to provide actionable findings and recommendations.
- Measure and improve the effectiveness of technical security controls using the NIST framework.
Requirements
- Minimum 3 years of experience in Information Technology, including at least 2 years in incident response, threat hunting, or forensics.
- Bachelor’s or master’s degree in a relevant field.
- Strong technical background with expertise in at least two areas: Windows/Linux forensics, network traffic analysis, log analysis, or malware analysis.
- Solid understanding of operating systems, networks, firewalls, and cloud infrastructure.
- Experience building workflows and playbooks for incident response.
- Familiarity with the NIST framework and continuous improvement processes.
Culture & Benefits
- Collaborative, service-oriented work environment.
- Opportunity to work with leading-edge technology and cloud services.
- Commitment to equal employment opportunity and inclusive workplace policies.
- Periodic on-call responsibilities as part of the role.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →