Назад
Company hidden
11 часов назад

Cyber Threat Analyst (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Threat Analyst (Cybersecurity): Monitoring and responding to security events, tuning SIEM detection rules, and conducting threat hunting and vulnerability management with an accent on incident response, security automation, and multi-cloud environments. Focus on implementing playbooks, investigating attacks using MITRE ATT&CK and Cyber Kill Chain methodologies, and improving detection and response across Azure and AWS.

Location: Remote within the United States; preference for candidates in the Eastern timezone. Must be a US Citizen with the ability to obtain a security clearance.

Company

hirify.global develops AI-powered digital investigation and digital forensic solutions for public safety organizations, intelligence agencies, and businesses.

What you will do

  • Monitor and respond to security events, document incidents, and drive them to rapid resolution.
  • Monitor and tune SIEM alerts, including rules, parsing, correlation, and investigation.
  • Create detection rules based on emerging cyberattack methods and business threat strategies.
  • Conduct threat hunting and vulnerability management activities, including reporting and stakeholder follow-up.
  • Advise on and implement security improvements, including process automation and playbook integrations.
  • Perform internal and external security audits and contribute to incident response and disaster recovery plans.

Requirements

  • At least 5 years of experience as a Tier 2 Cyber Threat Analyst.
  • Security+ or CEH certification.
  • Hands-on experience with SIEM, playbook implementation such as Palo Alto XSOAR, and threat hunting.
  • Knowledge of the Cyber Kill Chain, MITRE ATT&CK, TCP/IP, network protocols, Active Directory, and file permissions.
  • Experience with Azure and AWS multi-cloud environments.
  • US citizenship and the ability to obtain a security clearance are required.

Nice to have

  • Experience with network, security, endpoint, EDR, firewall, and Windows, Linux, or macOS systems.
  • Experience writing incident response reports.
  • Powershell and Python scripting experience.

Culture & Benefits

  • Work remotely with a preference for Eastern timezone availability.
  • Collaborate with IT administrators, business managers, security leaders, and other stakeholders.
  • Equal opportunity and affirmative action employment environment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →