Security Operations & Incident Response Analyst
Core
First line of defense and engine for threat detection/response, owning end-to-end incident response, threat hunting, vulnerability management, and identity governance for a global digital advertising platform.
Role type
Senior Security Operations & Incident Response Analyst (L3)
Builds
Threat detection capabilities, incident response playbooks, vulnerability remediation programs, and identity access controls.
Domain
Cybersecurity / Digital Advertising
Required skills
Incident response lifecycle management, threat hunting, vulnerability management, identity and access management (IAM), privileged access management (PAM), SIEM operations, EDR/XDR usage, digital forensics, threat intelligence analysis, compliance with ISO 27001/NIS2/PCI DSS
Preferred skills
GCIH, GCFE, GCFA, CEH, CompTIA CySA+, OSCP certifications, experience with Tenable Nessus/Qualys/Rapid7, CyberArk/BeyondTrust/Azure PIM, MISP/VirusTotal, MITRE ATT&CK framework
Technologies
SIEM platforms, EDR/XDR tools, Tenable Nessus, Qualys, Rapid7, CyberArk, BeyondTrust, Azure PIM, MISP, VirusTotal
Responsibilities
Own and coordinate the end-to-end incident response process (identification, triage, containment, eradication, recovery, post-incident review). Lead data breach investigations including evidence gathering, PII exposure assessment, and coordination with Legal/Privacy/HR. Conduct proactive threat hunting and manage the threat intelligence function. Manage the vulnerability management programme including scanning, prioritization, and remediation tracking. Oversee IAM and PAM programmes including access reviews and privileged account monitoring.
Seniority
Senior, hands-on IC