Security Analyst (Detection and Incident Response)
Core
Frontline responder in the Security Operations Center (SOC) identifying, triaging, and remediating security detections and anomalies to protect systems from nation-state and brand-destroying actors.
Role type
Security Analyst (Detection and Incident Response)
Builds
Detection capabilities and response playbooks for endpoint and network visibility
Domain
Aerospace / Cybersecurity
Deliverable
client delivery
Required skills
OS auditing (Linux, Windows, macOS), network and host-based collection tools, incident response processes, scripting for automation
Preferred skills
Threat actor TTPs understanding, reverse engineering, C2 exploitation, system/network forensics, cloud security, SIEM usage (Elastic, Splunk)
Technologies
Elastic, Splunk, Linux, Windows, macOS
Responsibilities
Identify, triage, and remediate security detections and anomalies; investigate security incidents from detection through root cause; collect evidence and collaborate with engineering to secure systems; enhance detection capabilities against sophisticated attacker TTPs; improve endpoint and network visibility and response playbooks
Seniority
Individual Contributor, Level I or Level II