Назад
Company hidden
5 часов назад

Security Operations Center (SOC) Tier 3 Analyst / Incident Responder (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder (Cybersecurity): Leading advanced incident investigations and full-lifecycle response across on-premises, cloud, identity, SaaS, API, and hybrid environments with an accent on digital forensics, threat hunting, and detection engineering. Focus on investigating ransomware and APTs, developing Elastic Security detections with KQL, ES|QL/EQL, SQL, PowerShell, and Python, and mentoring Tier 1 and Tier 2 analysts.

Location: Baltimore, MD, United States

Company

hirify.global is a financial services company operating in a highly regulated industry.

What you will do

  • Lead advanced investigations into ransomware, APTs, zero-day exploits, insider threats, credential theft, cloud compromise, lateral movement, business email compromise, and data exfiltration.
  • Manage the full incident response lifecycle from detection and triage through containment, eradication, recovery, validation, root cause analysis, and post-incident review.
  • Investigate and perform forensic analysis across Windows and Linux systems, Active Directory, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS, APIs, containers, Kubernetes, databases, and hybrid cloud environments.
  • Analyze telemetry from SIEM, EDR/XDR, NDR, firewalls, IDS/IPS, WAF, VPN, DNS, email security, cloud audit logs, identity providers, and application systems.
  • Develop Elastic Security detections and SIEM correlation rules using KQL, ES|QL/EQL, SQL, PowerShell, and Python.
  • Conduct MITRE ATT&CK-based threat hunting, mentor Tier 1 and Tier 2 analysts, and produce technical incident reports.

Requirements

  • Minimum 8 years of progressive cybersecurity experience, including 6 years in a Security Operations Center and 4 years leading complex enterprise investigations.
  • Minimum 2 years of advanced digital forensics, threat hunting, and detection engineering experience.
  • Expert experience with Elastic Security, CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, and Defender for Cloud Apps.
  • Advanced knowledge of on-premises infrastructure, Windows Server, Linux, Active Directory, AD CS, VMware, Hyper-V, networking, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS, APIs, containers, Kubernetes, databases, and hybrid cloud architectures.
  • Expert proficiency with KQL, ES|QL/EQL, SQL, PowerShell, Python, and Bash, plus knowledge of TCP/IP, DNS, DHCP, VPN, PKI, Kerberos, NTLM, OAuth, OIDC, SAML, and JWT.
  • At least two relevant certifications, such as GCFA, GCFE, GCIH, GCIA, GREM, CISSP, SC-200, SC-100, or AWS Certified Security – Specialty, and a bachelor's degree in cybersecurity, computer science, information technology, or equivalent experience.

Nice to have

  • Experience in financial services or another highly regulated industry.
  • Experience with DFIR engagements involving ransomware, nation-state threats, insider threats, enterprise-scale incidents, and AD CS abuse.

Culture & Benefits

  • Full-time employment with a financial services organization.
  • Equal employment opportunity across legally protected characteristics.
  • Work involving regulated-industry security operations and enterprise-scale environments.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →