Lead investigation and response for high-severity security incidents, from initial detection through containment, eradication, recovery, and post-incident review.
Design, tune, and maintain detection logic across our SIEM, EDR, and cloud security tooling, and retire the rules that generate noise instead of signal.
Conduct proactive threat hunts based on threat intelligence, adversary TTPs, and anomalies in telemetry.
Perform forensic analysis of endpoints, network traffic, and cloud environments to determine scope and root cause.
Write and maintain runbooks, playbooks, and post-incident reports that make the next response faster.
Partner with engineering and IT teams to close gaps surfaced by incidents and hunts, and to improve logging and telemetry coverage.
Automate repetitive response steps through SOAR (Security Orchestration, Automation, and Response) workflows or scripting.
Mentor junior analysts on investigation methodology, tooling, and escalation judgment.
Contribute to tabletop exercises, purple team engagements, and control validation.
Support audit and compliance evidence requests as they relate to security monitoring and incident response.
Responsibilities
Lead investigation and response for high-severity security incidents, from initial detection through containment, eradication, recovery, and post-incident review.
Design, tune, and maintain detection logic across our SIEM, EDR, and cloud security tooling, and retire the rules that generate noise instead of signal.
Conduct proactive threat hunts based on threat intelligence, adversary TTPs, and anomalies in telemetry.
Perform forensic analysis of endpoints, network traffic, and cloud environments to determine scope and root cause.
Write and maintain runbooks, playbooks, and post-incident reports that make the next response faster.
Partner with engineering and IT teams to close gaps surfaced by incidents and hunts, and to improve logging and telemetry coverage.
Automate repetitive response steps through SOAR (Security Orchestration, Automation, and Response) workflows or scripting.
Mentor junior analysts on investigation methodology, tooling, and escalation judgment.
Contribute to tabletop exercises, purple team engagements, and control validation.
Support audit and compliance evidence requests as they relate to security monitoring and incident response.