Investigating and remediating detections from security tooling across a growing global customer base
Supporting customers with queries and engaging in proactive threat hunting based on data from threat intelligence sources
Triaging alerts from security tools, distinguishing false positives from genuine threats, and executing remediation
Handling customer queries via the MDR mailbox, assist with user management and investigations
Monitoring detection trends to optimise allow/block listing
Supporting the onboarding of new customers by guiding tool deployment and contributing to ongoing account management
Contributing to improving operational processes and technologies by offering feedback and helping assess new tools
Creating technical resources such as PowerShell scripts to automate threat identification and remediation
Requirements
Solid experience in Security Operations (SecOps), particularly in detection and response
Proven ability to investigate and remediate incidents using EDR/XDR tools
A working knowledge of log query languages such as SQL, Splunk, or KQL is essential
Strong grasp of endpoint security, networking protocols, and cloud technologies
Scripting or programming experience for security tooling and SOAR platforms
Familiarity with the Mitre ATT&CK framework
Understanding of Microsoft Windows Active Directory environments
Benefits
**Love what you do:****We show up each day ready to take on the world. Our passion and intensity set us apart and makes the difference to our colleagues, customers, brokers and carriers.******Challenge everything:****We’re never afraid to question the way that things are done and we constantly challenge ourselves and others to makes things better.******Have fun, be good:****Insurance is a serious business, but we don’t take ourselves too seriously. We make it fun to work at CFC, we welcome all viewpoints, and we treat everyone how we would expect to be treated.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
Security Operationsdetection and responseEDR toolsXDR toolslog query languagesSQLSplunkKQLscriptingprogramming