Cyber Detection and Response Specialist
Core
Provides cyber security incident detection and response for computing, network, and application environments by investigating vulnerabilities, performing security data analytics, and responding to MSSP/SOC events.
Role type
Cyber Detection and Response Specialist (IC)
Builds
Managed Security Service Partner (MSSP) platform operations and customizations
Domain
Insurance industry cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SIEM content development, incident response, threat hunting, scripting/programming, log analysis, network security fundamentals, Windows/UNIX administration, security controls understanding
Preferred skills
SPLUNK, SANS, ISC2, CompTIA CySA certifications, experience with Arcsight/Qradar/Nitro, vendor product exposure (Splunk/F5/Palo Alto/Qualys)
Technologies
Splunk, Arcsight, Qradar, Nitro, F5, Palo Alto, Qualys, regex
Responsibilities
Review and investigate potential security vulnerabilities and incidents; perform security data analytics; respond to MSSP/SOC events; develop and customize MSSP platform; address critical/high/medium findings per incident response policy
Seniority
Mid-level, hands-on IC