Cloud Security Module Lead-Service Support
Core
Lead end-to-end incident response, threat hunting, and security event investigation across cloud infrastructure and endpoints.
Role type
Senior Cloud Security Engineer (Incident Response)
Builds
Incident response runbooks, playbooks, and detection logic
Domain
Cloud Security / Incident Response
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Incident response triage and containment, Threat hunting, Splunk SPL query writing, AWS CloudTrail/CloudWatch/GuardDuty investigation, MITRE ATT&CK mapping, Technical report writing
Preferred skills
GCIH/GCFE certifications, IaC security tooling (Terraform/CloudFormation), Python/Bash scripting
Technologies
CrowdStrike Falcon, Splunk, AWS (CloudTrail, CloudWatch, GuardDuty, Security Hub, Config), Terraform, CloudFormation
Responsibilities
Lead end-to-end incident response (triage, containment, investigation, post-incident review), Hunt for threats and investigate alerts using CrowdStrike Falcon, Build and tune detection logic in Splunk, Audit and investigate events in AWS CloudTrail and native security services, Correlate signals across endpoint, network, and cloud layers, Document findings and produce clear incident reports
Seniority
Senior, hands-on IC