Staff CSIRT Analyst
Core
Lead internal incident response, triage, and strategic preparedness for a 24/7 SOC protecting 5M+ endpoints.
Role type
Staff CSIRT Analyst (Strategic IC)
Builds
Internal security resilience, incident response playbooks, and detection efficacy for the company's own infrastructure.
Domain
Cybersecurity / Incident Response / SOC Operations
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident Response, SOC Operations, Digital Forensics (DFIR), EDR/MDR platforms, SIEM/ELK, Cloud Security (AWS/Azure/M365), Root Cause Analysis, Cross-functional Leadership, Automation/SOAR
Preferred skills
Purple Teaming, Post-Incident Reviews (PIRs), Playbook Development, Stakeholder Reporting
Technologies
EDR, MDR, SIEM, ELK, AWS, Azure, M365, SOAR, Confluence, Jira, Lucid Chart
Responsibilities
Lead identification, triage, and validation of security incidents; Design and execute response exercises (tabletops/purple teaming); Tune telemetry sources for high true-positive rates; Collaborate with offensive security to close visibility gaps; Lead cross-functional Post-Incident Reviews (PIRs) and drive remediation; Develop and present incident reports to stakeholders; Create and maintain incident response standards and playbooks.
Seniority
Staff, strategic leadership & hands-on execution