Threat Specialist
Core
Triage global security alerts, respond to incidents, and drive automated detection and response for a diversified trading firm's security operations.
Role type
Threat Specialist (Security Operations)
Builds
Automated detection, response, and configuration for global security posture
Domain
Cybersecurity / Financial Services
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Incident Response Cycle, static & dynamic malware analysis, SIEM administration, EDR usage, SOAR playbook management, scripting (PowerShell, Bash, Python, Ruby, Perl), data analysis of security events
Preferred skills
Digital forensics, physical security knowledge, GitHub usage, commercial/open-source tool evaluation
Technologies
SIEM, EDR, SOAR, IPS, Web Security, Endpoint Protection, Event Logs, GitHub, PowerShell, Bash, Python, Ruby, Perl
Responsibilities
Perform triage of global security alerts from various sources; Respond to incidents identified from analysis of security alerts; Triage & route internal support tickets; Creation & revision of threat detections; Perform SIEM product administration for event correlation; Perform SOAR playbook/dashboard management; Provide insider threat investigation assistance; Drive automated detection, response, and configuration through scripting; Evaluate commercial and open-source tools; Collaborate with internal Infosec peers; Contribute to internal documentation; Educate users on security best practices; Assess security risks for new projects; Attend security conferences and training.
Seniority
Mid-level, hands-on IC