Senior Incident Response Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Incident Response Analyst (Cybersecurity): Leading advanced threat detection, investigation, and remediation within the Security Operations program with an accent on complex incident handling and SOC process improvement. Focus on analyzing malicious binaries, mitigating AI-related security risks, and enhancing detection capabilities across multi-cloud environments.
Location: Hybrid in Jacksonville, Florida, United States
Company
is a leading global provider of business data and analytics.
What you will do
- Lead high-fidelity alert investigations and perform deep technical analysis to contain and remediate threats.
- Manage complex security incidents and drive the organization's detection and response maturity.
- Design scalable workflows and refine technical playbooks to strengthen the Incident Response program.
- Mentor junior analysts and serve as the primary escalation point for critical security cases.
- Partner with detection engineering to improve log ingestion, alert logic, and signal quality.
- Assess and mitigate security risks associated with AI, including prompt injection and data leakage.
Requirements
- Must be based in or able to work hybrid in Jacksonville, Florida, USA.
- SANS/GIAC Certification (GCIH, GREM, or GCFA preferred).
- Hands-on experience with SIEM (Splunk, Sentinel) and EDR tools (CrowdStrike, Carbon Black).
- Proficiency in cloud environments (Azure, AWS, GCP) and network log analysis (PCAP, Netflows).
- Deep knowledge of Mitre ATT&CK, malware behavior, and OS internals (Windows, Linux, macOS).
- Ability to analyze scripts (Python, PowerShell, JS, VBScript) and malicious binaries.
Culture & Benefits
- Professional growth opportunities within a global security program.
- Collaborative environment working across Engineering, IT, Legal, and HR.
- Commitment to equal employment opportunity and workplace accessibility.
- Participation in an on-call rotation for high-severity incidents.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →