Senior Incident Response Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Incident Response Analyst (Cybersecurity): Leading advanced threat detection, investigation, and remediation efforts within the Security Operations program with an accent on high-fidelity alert analysis and process maturity. Focus on mitigating complex security incidents, assessing AI-related security risks, and mentoring junior analysts to strengthen the enterprise security posture.
Location: On-site in Center Valley, Pennsylvania, United States
Company
is a leading global provider of business decisioning data and analytics.
What you will do
- Lead high-fidelity alert investigations and perform deep technical analysis to rapidly identify and contain threats.
- Drive complex incident investigations to elevate the organization's detection and response maturity.
- Design scalable workflows and implement improvements to strengthen the Incident Response program.
- Develop and refine technical playbooks, response guides, and operational documentation.
- Mentor junior analysts and serve as the primary escalation point for critical and ambiguous security cases.
- Assess and mitigate AI-related security risks, including model misuse, prompt injection, and data leakage.
Requirements
- Must be based in or able to work on-site in Center Valley, Pennsylvania, USA.
- Possession of at least one SANS/GIAC Certification (GCIH, GREM, or GCFA preferred).
- Hands-on experience with SIEM platforms (Splunk, Microsoft Sentinel) and EDR tools (CrowdStrike, Carbon Black).
- Experience with cloud environments (Azure, AWS, GCP, AliCloud) and network log analysis (Netflows and PCAP).
- Deep understanding of the Mitre ATT&CK framework and Windows, Linux, and macOS internals.
- Proficiency in script analysis (Javascript, VBscript, PowerShell, Python) and malicious binary analysis.
Culture & Benefits
- Full-time employee status with corporate benefits.
- Opportunity to lead high-impact security initiatives within a global enterprise.
- Collaborative environment involving partnerships with Engineering, IT, Legal, and HR.
- Role involves a trusted position in the on-call rotation for high-severity incidents.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →