Act as the senior escalation point for complex or high-severity incidents.
Lead incident response lifecycle from detection through to post-incident review.
Perform high level forensic analysis across cloud, endpoint and network data.
Develop and execute hypothesis driven hunts across available telemetry.
Use results to identify gaps or refine detection logic.
Build, tune, and document detection logic in Sentinel, Defender, CrowdStrike and other platforms.
Translate threat intelligence into rules and analytics to support incidents.
Maintain and execute MITRE ATT&CK coverage plans.
Design and improve operational playbooks and SOAR workflows.
Implement response logic for recurring incident types.
Support the development of SOC Analysts by providing escalation support, training and structured feedback.
Requirements
The ability and willingness to work a 9:00-5:00 Mountain Standard Time (MST) schedule
Flexibility to work an on-call rotation which will include some weekends and public holidays (current schedule is 1 week every 6 weeks but is subject to change)
2+ years’ experience in SOC, IR or similar roles with demonstrable threat hunt or tier 3 response
Experience building detection logic and analytics rules (e.g. KQL, Sigma)
Deep understanding of MITRE ATT&CK, threat actors, and attack chains
Strong verbal and written communication skills including report writing skills, the ability to brief groups and translate technical terms into easy-to-understand concepts.
Experience in financial services, aviation, government or other regulated industries.
Benefits
Paid parental leave
Flexible working
Health and wellbeing rewards that can be tailored to support you and your family, including medical, dental and vision.
401k matching and tax-advantaged flexible spending plans, including healthcare, dependent care and commuter.
Income protection, including short and long-term disability benefits, life insurance and supplemental life insurance.
A welcoming and close-knit community, with experienced colleagues ready to help you grow.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.