Tech Stack
AWSAzureCloudCyber SecurityDockerFirewallsGoogle Cloud PlatformKubernetesPython
About the role
- Lead investigation, containment, eradication, and recovery of advanced cyber threats and security incidents
- Serve as escalation point for Level 1 and Level 2 analysts; provide guidance and mentorship
- Utilize threat intelligence, SIEM, EDR, and other security tools to analyze and mitigate security events
- Conduct root cause analysis (RCA) and forensic investigations to determine attack vectors and impact
- Develop and implement advanced detection rules, correlation searches, and playbooks for threat hunting
- Oversee real-time monitoring of security alerts and ensure rapid response to potential threats
- Maintain and optimize security monitoring tools such as SIEM, SOAR, and EDR solutions
- Perform proactive threat hunting to identify undetected malicious activities
- Analyze emerging threats, vulnerabilities, and attack techniques; leverage TIPs and MITRE ATT&CK
- Collaborate with DevOps and IT to implement secure configurations and improve security controls
- Prepare detailed reports and post-incident documentation; participate in audits, risk assessments, and tabletop exercises
Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Security, or related field (or equivalent experience)
- Minimum 5+ years of hands-on experience in cybersecurity operations, SOC, or threat intelligence
- Required certifications: Security+ / CySA+ / SSCP
- Preferred certifications: CISSP, CISM, CEH, GCIH, GCFA, GCIA, OSCP
- Proficiency with SIEM platforms (Microsoft Sentinel or other SIEMs)
- Experience with EDR/XDR solutions (CrowdStrike, Defender for Endpoint)
- Hands-on experience with IDS/IPS, SOAR, and forensic tools (Wireshark, VIRUSTOTAL, Microsoft Sentinel SOAR)
- Strong knowledge of email security platforms and threat intelligence frameworks (Proofpoint, MITRE ATT&CK, Cyber Kill Chain)
- Familiarity with cloud security (AWS, Azure, GCP) and container security (Kubernetes, Docker)
- Proficiency in scripting & automation (Python, PowerShell, Bash)
- Strong understanding of network security, firewalls, and intrusion detection systems
- Excellent problem-solving and analytical skills
- Strong communication and leadership abilities
- Ability to work under pressure in high-stakes security incidents
- Candidate will report to Manager IT
- Competitive salary, benefits, and professional development opportunities
- Comprehensive mindfulness programs with a premium Calm membership
- Volunteer paid time off available after 6 months of employment for eligible employees
- Company volunteer and donation matching program
- Employee Assistance Program (EAP)
- Personalized wellbeing programs through the OnTrack program
- On-demand digital course library for professional development
- Other local benefits
ATS Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
cybersecurity operationsthreat intelligenceroot cause analysisforensic investigationsdetection rulescorrelation searchesthreat huntingscriptingautomationnetwork security
Soft skills
problem-solvinganalytical skillscommunicationleadershipability to work under pressure
Certifications
Security+CySA+SSCPCISSPCISMCEHGCIHGCFAGCIAOSCP