11 часов назад
Cyber Threat Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cyber Threat Analyst (Cybersecurity): Monitoring and responding to security events, tuning SIEM detection rules, and conducting threat hunting and vulnerability management with an accent on incident response, security automation, and multi-cloud environments. Focus on implementing playbooks, investigating attacks using MITRE ATT&CK and Cyber Kill Chain methodologies, and improving detection and response across Azure and AWS.
Location: Remote within the United States; preference for candidates in the Eastern timezone. Must be a US Citizen with the ability to obtain a security clearance.
Company
develops AI-powered digital investigation and digital forensic solutions for public safety organizations, intelligence agencies, and businesses.
What you will do
- Monitor and respond to security events, document incidents, and drive them to rapid resolution.
- Monitor and tune SIEM alerts, including rules, parsing, correlation, and investigation.
- Create detection rules based on emerging cyberattack methods and business threat strategies.
- Conduct threat hunting and vulnerability management activities, including reporting and stakeholder follow-up.
- Advise on and implement security improvements, including process automation and playbook integrations.
- Perform internal and external security audits and contribute to incident response and disaster recovery plans.
Requirements
- At least 5 years of experience as a Tier 2 Cyber Threat Analyst.
- Security+ or CEH certification.
- Hands-on experience with SIEM, playbook implementation such as Palo Alto XSOAR, and threat hunting.
- Knowledge of the Cyber Kill Chain, MITRE ATT&CK, TCP/IP, network protocols, Active Directory, and file permissions.
- Experience with Azure and AWS multi-cloud environments.
- US citizenship and the ability to obtain a security clearance are required.
Nice to have
- Experience with network, security, endpoint, EDR, firewall, and Windows, Linux, or macOS systems.
- Experience writing incident response reports.
- Powershell and Python scripting experience.
Culture & Benefits
- Work remotely with a preference for Eastern timezone availability.
- Collaborate with IT administrators, business managers, security leaders, and other stakeholders.
- Equal opportunity and affirmative action employment environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
15 часов назад
Principal Cybersecurity Engineer (US Federal)
184 800 - 277 200$
4 дня назад
Cybersecurity Engineer - US Federal
130 200 - 195 400$
4 часа назад
SOC Analyst (Cybersecurity)
CrowdStrike
5 дней назад
Principal Consultant - Cloud Red Team Blue Team (Cloud Cybersecurity)
140 000 - 195 000$
5 часов назад
Senior Channel Solutions Engineer (Cybersecurity)
2 часа назад