Investigate and remediate detections from security tooling across a global customer base.
Triage alerts, distinguish false positives from genuine threats, and execute remediation using built-in capabilities and remote PowerShell commands.
Handle customer queries via the MDR mailbox, assist with user management and investigations, and monitor detection trends to optimise allow/block listing.
Support onboarding of new customers by guiding tool deployment and contributing to account management.
Actively contribute to improving operational processes and assess new tools and technologies.
Create PowerShell scripts and automation for threat identification and remediation to enhance service efficiency.
Engage in proactive threat hunting using threat intelligence data and share findings with internal teams.
Mentor team members and share expertise in detection analysis, customer support, and threat hunting.
Requirements
Solid experience in Security Operations (SecOps), particularly in detection and response.
Proven ability to investigate and remediate incidents using EDR/XDR tools.
Working knowledge of log query languages such as SQL, Splunk, or KQL.
Strong grasp of endpoint security, networking protocols, and cloud technologies.
Scripting or programming experience for security tooling and SOAR platforms.
Familiarity with the Mitre ATT&CK framework.
Understanding of Microsoft Windows Active Directory environments.
Established investigation and log analysis skills.
Benefits
Love what you do: We show up each day ready to take on the world. Our passion and intensity set us apart and makes the difference to our colleagues, customers, brokers and carriers.
Challenge everything: We’re never afraid to question the way that things are done and we constantly challenge ourselves and others to makes things better.
Have fun, be good: Insurance is a serious business, but we don’t take ourselves too seriously. We make it fun to work at CFC, we welcome all viewpoints, and we treat everyone how we would expect to be treated.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
Security Operationsdetection and responseEDR toolsXDR toolslog query languagesSQLSplunkKQLscriptingPowerShell