Cybersecurity Analyst (Blue Team N2) – On-site
Core
Investigate and respond to escalated security incidents, perform technical root cause analysis, and execute containment and remediation actions.
Role type
Mid-level Blue Team Security Analyst (Incident Response)
Builds
Incident response playbooks, SIEM use cases, and security process improvements
Domain
Cybersecurity / Incident Response
Deliverable
client delivery
Required skills
Incident investigation and triage, Root cause analysis, Containment and remediation, SIEM configuration and use case creation, SOAR automation, Playbook development, Ticketing and workflow management, Technical troubleshooting
Preferred skills
CEH certification, BTL1/BTL2 GIAC certification
Technologies
SIEM platforms, SOAR tools, Remedy
Responsibilities
Investigate and handle security incidents escalated by the N1 team, Perform in-depth technical analysis to identify root causes, Execute containment, remediation, and mitigation actions, Monitor and track incidents through to full resolution, Create and optimize use cases within SIEM platforms, Develop and maintain incident response playbooks (SOAR), Document procedures, solutions, and improvements in the knowledge base
Seniority
Mid-level, hands-on IC