Cybersecurity Specialist
Core
Investigate, validate, and respond to security incidents; perform threat hunting and proactive investigations using advanced security technologies.
Role type
Security Operations Specialist (SOC Analyst)
Builds
Incident response capabilities and detection/mitigation of security risks
Domain
Cybersecurity / IT Security
Deliverable
client delivery
Required skills
incident investigation, alert triage, root cause analysis, containment and remediation, threat hunting, log analysis, endpoint telemetry analysis, familiarity with MITRE ATT&CK and Cyber Kill Chain, knowledge of NIST/ISO 27001/CIS Controls, Windows OS and Active Directory administration, networking fundamentals
Preferred skills
CrowdStrike certifications (CCFA, CCFR, CCFH), experience with SIEM platforms
Technologies
CrowdStrike Falcon, Microsoft Defender, SIEM platforms
Responsibilities
Investigate and respond to security incidents escalated by CrowdStrike Falcon Complete or reported by users; Analyze alerts and suspicious activity using endpoint telemetry, threat intelligence and SIEM logs; Perform root cause analysis of security incidents and document findings; Execute containment and remediation actions; Conduct threat analysis and participate in threat hunting; Escalate complex incidents to senior analysts; Document incidents and lessons learned; Collaborate with Global SOC team to enhance security posture; Contribute to development and improvement of incident response playbooks; Support post-incident reviews
Seniority
Mid-level, hands-on IC