Назад
Company hidden
7 часов назад

Lead Analyst – Cyber Incident Response (AI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Analyst – Cyber Incident Response (AI) (Cybersecurity): Leading cyber incident response and building scalable AI-enabled automation for threat detection, triage, containment, and remediation with an accent on incident handling, threat hunting, forensic investigation, and SOAR engineering. Focus on designing intelligent security workflows, integrating AI/ML and LLM capabilities, and operationalizing resilient response pipelines across enterprise security platforms.

Location: Saint Petersburg, Florida, United States; hybrid workstyle

Company

hirify.global is a financial services firm with a Cyber Threat Center focused on protecting the enterprise from sophisticated cyber adversaries.

What you will do

  • Handle severity 1 and severity 2 security incidents through triage, investigation, containment, eradication, recovery, and post-incident analysis.
  • Lead incident response initiatives and serve as an escalation point during incidents and the weekly on-call rotation.
  • Design, build, and maintain scalable SOAR automation and AI-enabled workflows for detection, enrichment, triage, and response.
  • Develop forensic detective and investigative capabilities using emerging security technologies.
  • Apply programming, data science, AI/ML, and LLM capabilities to threat hunting and incident response analysis.
  • Collaborate with incident response, threat intelligence, threat hunting, security engineering, and technology teams while mentoring analysts.

Requirements

  • Bachelor’s degree in computer science, computer engineering, management information systems, cybersecurity, or a related field.
  • 6–10 years of general experience, including 5–8 years in information security, cybersecurity operations, and incident response.
  • At least 4 years of hands-on incident response experience and at least 2 years of programming or scripting with Python, JavaScript, PowerShell, or Rust.
  • Experience developing automation workflows, APIs, integrations, orchestration, case management, and security operations solutions.
  • Experience with SIEM, EDR, SOAR, threat intelligence, log management, cloud security, and enterprise security telemetry.
  • Ability to lead high-priority incidents, communicate technical findings, build repeatable playbooks, and mentor analysts.

Nice to have

  • CISSP, GCIH, GCIA, GCFE, OSCP, or CEH certification.

Culture & Benefits

  • Hybrid work environment with less than 25% travel.
  • Benefits may include medical, dental, vision, life, critical illness, accident, disability, and retirement coverage.
  • Paid vacation, holidays, sick leave, and parental leave may be available.
  • People-first culture centered on developing, collaborating, deciding, delivering, and improving.
  • Work alongside cybersecurity, technology, business, vendor, and leadership stakeholders.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →