Operate and support an innovative managed detection and response (MDR) service for a global customer base
Investigate and remediate detections from security tooling, triaging alerts and distinguishing false positives from genuine threats
Execute remediation using built-in capabilities and remote PowerShell commands
Handle customer queries via the MDR mailbox and assist with user management and investigations
Monitor detection trends to optimise allow/block listing and improve detection quality
Support onboarding of new customers by guiding tool deployment and contributing to account management
Actively contribute to improving operational processes and technologies and help assess new tools
Create technical resources and PowerShell scripts to automate threat identification and remediation
Mentor team members and share expertise in detection analysis, customer support, and proactive threat hunting
Share information with internal teams and report to Matt Smith
Requirements
Solid experience in Security Operations (SecOps), particularly detection and response
Proven ability to investigate and remediate incidents using EDR/XDR tools
Working knowledge of log query languages such as SQL, Splunk, or KQL
Strong grasp of endpoint security, networking protocols, and cloud technologies
Scripting or programming experience for security tooling and SOAR platforms
Familiarity with the Mitre ATT&CK framework
Understanding of Microsoft Windows Active Directory environments
Established investigation and log analysis skills
Experience with customer onboarding, user management, and account support
PowerShell experience for remote remediation and automation
Benefits
Love what you do: We show up each day ready to take on the world. Our passion and intensity set us apart and makes the difference to our colleagues, customers, brokers and carriers.
Challenge everything: We’re never afraid to question the way that things are done and we constantly challenge ourselves and others to makes things better.
Have fun, be good: Insurance is a serious business, but we don’t take ourselves too seriously. We make it fun to work at CFC, we welcome all viewpoints, and we treat everyone how we would expect to be treated.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
Security Operationsdetection and responseEDR toolsXDR toolslog query languagesSQLSplunkKQLPowerShellMitre ATT&CK framework