Key Responsibilities:
- Lead high-fidelity alert investigations, performing deep technical analysis to rapidly identify, contain, and remediate threats
- Own complex incident investigations, driving technically precise conclusions and elevating the organization's detection and response maturity
- Champion process development by identifying gaps, designing scalable workflows, and implementing improvements that strengthen the incident response program
- Create and refine technical playbooks, documentation, and response guides to ensure clarity, consistency, and operational excellence across the program
- Provide mentorship, guidance, and coaching to less experienced analysts to support skill development and operational readiness
- Serve as the escalation point for critical and ambiguous cases, applying advanced threat analysis and sound judgment under pressure
- Collaborate with cross-functional stakeholders to resolve incidents holistically and drive organization wide security improvements
- Apply analytical and technical expertise to continuously enhance security operations processes, workflows, and response capabilities
- Contribute to the evolution of the detection landscape by partnering with technical stakeholders to improve log ingestion, alert logic, and signal quality
- Assess and mitigate AI-related security risks, including model misuse, prompt injection, data leakage, and emerging automation attack vectors
- Participate in an on-call rotation, responding to high-severity incidents as a subject matter expert
Key Skills:
- Bachelor's degree in Computer Science, Information Security, or a related field
- Minimum of eight years of experience in incident response, security operations, or a related field
- At least one SANS/GIAC certification, with GCIH, GREM, or GCFA preferred
- Hands-on experience with SIEM platforms, including splunk and microsoft sentinel
- Hands-on experience with EDR tools, including crowdstrike and carbon black
- Experience working in cloud environments, including Azure, AWS, GCP, and AliCloud
- Proficiency in network log analysis, including NetFlow and PCAP files
- Deep working knowledge of the Mitre Attack framework and its application to threat detection and response
- Strong understanding of malware behavior, exploitation techniques, and Windows, Linux, and macOS internals
- Ability to analyze scripts across multiple languages, including JavaScript, VBScript, PowerShell, and Python
- Experience conducting malicious binary analysis across Windows, macOS, and Linux platforms
- Strong written and verbal communication skills, with the ability to present technical findings clearly to peers and senior leadership
- Proficiency in Microsoft Office Suite
- Show an ownership mindset in everything you do; be a problem solver, be curious and be inspired to take action, be proactive, seek ways to collaborate and connect with people and teams in support of driving success
- Continuous growth mindset, keep learning through social experiences and relationships with stakeholders, experts, colleagues and mentors as well as widen and broaden your competencies through structural courses and programs
- Where applicable, fluency in English and languages relevant to the working market