19 часов назад
Cyber Security Analyst Leads (Cyber Threat Hunting)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cyber Security Analyst Leads (Cyber Threat Hunting) (Cyber Threat Hunting): Leading proactive, hypothesis-based threat hunts across endpoint, network, identity, and cloud telemetry with an accent on threat intelligence, enterprise EDR/SIEM investigations, and incident response. Focus on translating adversary TTPs into MITRE ATT&CK-mapped detections, automating hunting workflows with Python, PowerShell, and Bash, and identifying latent compromise in M&A environments.
Location: Jacksonville, Florida, United States; telecommuting and/or working from home may be permissible under company policies.
Company
provides financial technology and services.
What you will do
- Lead proactive, hypothesis-based threat hunts across endpoint, network, identity, and cloud telemetry.
- Investigate malware, credential compromise, and unauthorized access using enterprise EDR and SIEM platforms.
- Correlate multi-source evidence, scope incidents, support containment and remediation, and document investigative conclusions.
- Translate threat intelligence and adversary tactics into behavioral analytics mapped to MITRE ATT&CK.
- Partner with security operations, penetration testing, and detection engineering teams to turn successful hunts into durable detections and response playbooks.
- Automate hunting and investigative workflows and assess pre- and post-acquisition environments for inherited risk and latent compromise.
Requirements
- Bachelor’s degree or foreign equivalent in Computer Science, Cyber Security, Digital Forensics, or a related field, plus seven years of progressively responsible experience; alternatively, a relevant master’s degree plus five years of experience.
- Experience investigating endpoint threats with enterprise EDR, including behavioral detections, process trees, command-line activity, and persistence mechanisms.
- Experience developing, tuning, and investigating enterprise SIEM detections using authentication, endpoint, network, and cloud audit data.
- Experience supporting incident response, including triage, scoping, containment, and remediation.
- Proficiency with Python, PowerShell, and Bash for security automation, data analysis, alert enrichment, and investigations.
- Experience applying threat intelligence, IOCs, adversary tactics and techniques, and open-source intelligence to security detections and investigations.
Culture & Benefits
- Full-time employment with .
- Work-from-home or telecommuting arrangements may be available under company policy.
- Conditional offers for US positions require a drug test.
- Equal opportunity employment and reasonable accommodation review are provided.
Hiring process
- Qualified applicants should apply directly through the website.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →