Security Analyst
Core
Investigate and respond to security events and incidents across endpoint, identity, network, application, cloud, and SaaS environments to protect enterprise systems and data.
Role type
Security Analyst (Tier 2/3 Incident Response)
Builds
Incident response capabilities, detection coverage, and risk reduction for QBE's global security operations.
Domain
Cybersecurity / Enterprise Security Operations
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident response, threat hunting, SIEM log correlation, EDR/XDR analysis, identity security (IAM/Active Directory), cloud security, scripting (PowerShell/Python), query languages (KQL/SPL), risk assessment, automation, process optimization
Preferred skills
Malware analysis, phishing/ransomware response, Zero Trust implementation, detection engineering partnership, knowledge sharing
Technologies
SIEM, EDR/XDR, Active Directory, Entra ID, Cloud platforms, SaaS, MITRE ATT&CK, PowerShell, Python, KQL, SPL
Responsibilities
Investigate and respond to security events across multiple environments; lead or support Tier 2/3 incident response including containment and eradication; correlate multi-source telemetry to determine root cause; conduct proactive threat hunting aligned to MITRE ATT&CK; improve detection capability by partnering with detection engineering; evaluate and operationalize new security technologies; maintain accurate incident documentation and recommend playbook enhancements.
Seniority
Mid-level, hands-on IC