Tech Stack
Cyber SecurityDNSLinuxNode.jsPythonUnix
About the role
- Lead response efforts for cybersecurity incidents, including triage, investigation, containment, and recovery.
- Monitor and analyze security events using EDR/IDS/IPS and SIEM tools.
- Perform malware, memory, and disk forensic analysis during investigations.
- Configure and fine-tune detection technologies to improve signal fidelity and reduce false positives.
- Develop and maintain incident response strategies, playbooks, and automation workflows.
- Participate in a 24x7 on-call rotation to support continuous monitoring and rapid response.
- Collaborate with Security Engineering to design and improve detection, automation, and mitigation workflows.
- Evaluate and recommend emerging security technologies for adoption.
- Conduct vulnerability assessments, risk analysis, and red team-style threat hunts.
- Partner with business units to define and support enterprise security requirements and initiatives.
- Author documentation, training materials, and internal knowledge bases.
Requirements
- Security Incident Response
- EDR/IDS/IPS (e.g., endpoint detection & response, intrusion detection/prevention)
- SIEM and SOAR tools
- Malware, memory, and disk forensics
- Linux/Unix and Windows administration
- Threat hunting and threat intelligence integration
- Scripting and automation (Python, PowerShell, etc.)
- Security certifications (GCIH, GSEC, or CYSA+)
- Minimum 5 years of experience in a Security Operations role
- Experience in leading incident response, including hands-on forensics and threat analysis
- Deep knowledge of security tools including SIEM, SOAR, EDR, IDS/IPS, HIDS/NIDS, WAF, and DNS security
- Proficiency with scripting and automation tools (e.g., Python, PowerShell)
- Expertise in Linux/Unix and Windows operating systems
- Familiarity with cryptography, data encryption, and DLP technologies
- Experience developing detection use cases and automated playbooks
- Strong communication skills with the ability to present to technical and non-technical audiences
- Demonstrated ability to work collaboratively in a fast-paced environment
- Work authorization: GC, USC, All valid EADs except OPT, CPT, H1B