5 часов назад
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder (Cybersecurity): Leading advanced incident investigations and full-lifecycle response across on-premises, cloud, identity, SaaS, API, and hybrid environments with an accent on digital forensics, threat hunting, and detection engineering. Focus on investigating ransomware and APTs, developing Elastic Security detections with KQL, ES|QL/EQL, SQL, PowerShell, and Python, and mentoring Tier 1 and Tier 2 analysts.
Location: Baltimore, MD, United States
Company
is a financial services company operating in a highly regulated industry.
What you will do
- Lead advanced investigations into ransomware, APTs, zero-day exploits, insider threats, credential theft, cloud compromise, lateral movement, business email compromise, and data exfiltration.
- Manage the full incident response lifecycle from detection and triage through containment, eradication, recovery, validation, root cause analysis, and post-incident review.
- Investigate and perform forensic analysis across Windows and Linux systems, Active Directory, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS, APIs, containers, Kubernetes, databases, and hybrid cloud environments.
- Analyze telemetry from SIEM, EDR/XDR, NDR, firewalls, IDS/IPS, WAF, VPN, DNS, email security, cloud audit logs, identity providers, and application systems.
- Develop Elastic Security detections and SIEM correlation rules using KQL, ES|QL/EQL, SQL, PowerShell, and Python.
- Conduct MITRE ATT&CK-based threat hunting, mentor Tier 1 and Tier 2 analysts, and produce technical incident reports.
Requirements
- Minimum 8 years of progressive cybersecurity experience, including 6 years in a Security Operations Center and 4 years leading complex enterprise investigations.
- Minimum 2 years of advanced digital forensics, threat hunting, and detection engineering experience.
- Expert experience with Elastic Security, CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, and Defender for Cloud Apps.
- Advanced knowledge of on-premises infrastructure, Windows Server, Linux, Active Directory, AD CS, VMware, Hyper-V, networking, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS, APIs, containers, Kubernetes, databases, and hybrid cloud architectures.
- Expert proficiency with KQL, ES|QL/EQL, SQL, PowerShell, Python, and Bash, plus knowledge of TCP/IP, DNS, DHCP, VPN, PKI, Kerberos, NTLM, OAuth, OIDC, SAML, and JWT.
- At least two relevant certifications, such as GCFA, GCFE, GCIH, GCIA, GREM, CISSP, SC-200, SC-100, or AWS Certified Security – Specialty, and a bachelor's degree in cybersecurity, computer science, information technology, or equivalent experience.
Nice to have
- Experience in financial services or another highly regulated industry.
- Experience with DFIR engagements involving ransomware, nation-state threats, insider threats, enterprise-scale incidents, and AD CS abuse.
Culture & Benefits
- Full-time employment with a financial services organization.
- Equal employment opportunity across legally protected characteristics.
- Work involving regulated-industry security operations and enterprise-scale environments.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 часов назад
Senior Security Analyst (Cybersecurity)
6 дней назад
SOC Analyst (Cybersecurity)
123 850 - 161 000$
5 дней назад
Cyber Defense Response Analyst II (Cybersecurity)
93 900 - 156 500$
1 день назад
Cyber Defense and Incident Response Analyst (Cybersecurity)
95 170 - 156 355$
24 часа назад
Lead Analyst – Cyber Incident Response (AI)
6 дней назад
Senior Security Operations Center (SOC) Analyst
139 000 - 151 000$