Назад
Company hidden
1 день назад

Senior Cybersecurity Incident Analyst (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Cybersecurity Incident Analyst (Cybersecurity): Protecting a global enterprise by investigating complex cyber incidents and developing scalable detection capabilities across cloud, identity, endpoint, network, application, and manufacturing environments with an accent on threat hunting, detection engineering, and cross-functional cyber defense. Focus on designing and tuning SIEM, EDR, NDR, SOAR, and cloud-native detections, automating enrichment workflows with AI and scripting, and improving coverage using threat intelligence and MITRE ATT&CK.

Location: Hybrid in Warren, Michigan, with reporting to the location at least 3 times a week

Company

hirify.global develops vehicles and mobility solutions with a vision focused on zero crashes, zero emissions, and zero congestion.

What you will do

  • Lead advanced investigations into complex security incidents, emerging threats, and high-severity escalations.
  • Develop, implement, tune, and validate detection logic across SIEM, EDR, NDR, SOAR, cloud-native security, and other monitoring platforms.
  • Conduct threat hunting and apply threat intelligence, adversary tradecraft, and MITRE ATT&CK to improve detection coverage.
  • Build automation, enrichment workflows, and operational efficiencies using AI, scripting, and security orchestration technologies.
  • Partner with incident response, threat intelligence, cloud security, product security, manufacturing security, and other cybersecurity teams.
  • Mentor analysts and detection engineers while driving initiatives that improve visibility and investigative effectiveness.

Requirements

  • Bachelor’s degree in cybersecurity, computer science, information technology, engineering, or a related technical field, or equivalent practical experience.
  • 5+ years of cybersecurity experience focused on detection engineering, security operations, incident response, threat hunting, intrusion detection, or security event analysis.
  • Experience with enterprise SIEM platforms, log-centric detection, correlation logic, behavioral analytics, threat intelligence, endpoint security, and EDR.
  • Experience investigating events across endpoint, network, cloud, identity, and application environments.
  • Knowledge of attacker tactics, techniques, procedures, and the MITRE ATT&CK framework; scripting experience with Python, PowerShell, or similar technologies.
  • Ability and willingness to participate in a 24x7 on-call rotation; GM does not provide immigration-related sponsorship for this role.

Nice to have

  • Cloud security monitoring and detection engineering across Azure, AWS, and GCP.
  • SaaS security monitoring, identity threat detection, network security monitoring, IDS/IPS, packet analysis, or network telemetry.
  • Experience with manufacturing, operational technology, industrial control systems, vehicle cybersecurity, automotive architectures, or embedded security telemetry.
  • Application security monitoring, API security, runtime protection, CI/CD security telemetry, malware analysis, reverse engineering, or digital forensics.
  • SOAR workflow development, security certifications, or experience mentoring cybersecurity professionals and leading technical initiatives.

Culture & Benefits

  • Hybrid work arrangement with regular onsite collaboration.
  • Relocation benefits may be available.
  • Total rewards and employee well-being benefits are available from the first day.
  • Focus on inclusion, belonging, professional development, and meaningful change.

Hiring process

  • Applicants may be required to complete role-related assessments and pre-employment screening.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →