Cyber Defense Response Analyst II
Core
Mid-level technical role focused on responding to and remediating cyber incidents, conducting threat hunts, and building automation tools in a multi-cloud environment.
Role type
Mid-level Cyber Defense Response Analyst (DFIR)
Builds
Security tools for incident response, incident response runbooks and playbooks
Domain
Cybersecurity / Digital Forensics and Incident Response (DFIR)
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Endpoint forensics, malware analysis, threat hunting, Python (Pandas, REST APIs), SIEM log analysis, cloud security (AWS/GCP/Azure), networking fundamentals
Preferred skills
GCIH, GCFE, GCFA, OSCP, Sec+ certifications
Technologies
Q Radar, Sentinel, Splunk, Chronicle, ArcSight, KAPE, EnCase, Cellebrite, FTK, Magnet Axiom, Autopsy, Ghidra, Ida Pro, PEStudio, x64dbg
Responsibilities
Drive full incident response lifecycle from triage to remediation; conduct regular threat hunts to identify misconfigurations and anomalies; build/integrate security tools using AI and Python; lead tabletop exercises; maintain internal knowledge base of runbooks and playbooks
Seniority
Mid-level, hands-on IC