7 часов назад
Lead Analyst – Cyber Incident Response (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Lead Analyst – Cyber Incident Response (AI) (Cybersecurity): Leading cyber incident response and building scalable AI-enabled automation for threat detection, triage, containment, and remediation with an accent on incident handling, threat hunting, forensic investigation, and SOAR engineering. Focus on designing intelligent security workflows, integrating AI/ML and LLM capabilities, and operationalizing resilient response pipelines across enterprise security platforms.
Location: Saint Petersburg, Florida, United States; hybrid workstyle
Company
is a financial services firm with a Cyber Threat Center focused on protecting the enterprise from sophisticated cyber adversaries.
What you will do
- Handle severity 1 and severity 2 security incidents through triage, investigation, containment, eradication, recovery, and post-incident analysis.
- Lead incident response initiatives and serve as an escalation point during incidents and the weekly on-call rotation.
- Design, build, and maintain scalable SOAR automation and AI-enabled workflows for detection, enrichment, triage, and response.
- Develop forensic detective and investigative capabilities using emerging security technologies.
- Apply programming, data science, AI/ML, and LLM capabilities to threat hunting and incident response analysis.
- Collaborate with incident response, threat intelligence, threat hunting, security engineering, and technology teams while mentoring analysts.
Requirements
- Bachelor’s degree in computer science, computer engineering, management information systems, cybersecurity, or a related field.
- 6–10 years of general experience, including 5–8 years in information security, cybersecurity operations, and incident response.
- At least 4 years of hands-on incident response experience and at least 2 years of programming or scripting with Python, JavaScript, PowerShell, or Rust.
- Experience developing automation workflows, APIs, integrations, orchestration, case management, and security operations solutions.
- Experience with SIEM, EDR, SOAR, threat intelligence, log management, cloud security, and enterprise security telemetry.
- Ability to lead high-priority incidents, communicate technical findings, build repeatable playbooks, and mentor analysts.
Nice to have
- CISSP, GCIH, GCIA, GCFE, OSCP, or CEH certification.
Culture & Benefits
- Hybrid work environment with less than 25% travel.
- Benefits may include medical, dental, vision, life, critical illness, accident, disability, and retirement coverage.
- Paid vacation, holidays, sick leave, and parental leave may be available.
- People-first culture centered on developing, collaborating, deciding, delivering, and improving.
- Work alongside cybersecurity, technology, business, vendor, and leadership stakeholders.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Cyber Defense Response Analyst II (Cybersecurity)
93 900 - 156 500$
16 часов назад
Cyber Defense and Incident Response Analyst (Cybersecurity)
95 170 - 156 355$
CrowdStrike
5 дней назад
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
85 000 - 120 000$
6 дней назад
SOC Analyst (Cybersecurity)
123 850 - 161 000$
19 часов назад
Senior Cyber Defense Incident Responder (Cybersecurity)
4 дня назад