Lead Analyst – Cyber Incident Response
Core
Lead incident response and engineering initiatives within a financial services Cyber Threat Center, focusing on threat hunting, malware analysis, and AI-enabled security operations.
Role type
Senior IC Lead Analyst (Cyber Incident Response & Automation)
Builds
Intelligent automation workflows, AI/ML models, and scalable security orchestration pipelines for threat detection and response.
Domain
Financial Services / Cybersecurity Operations
Deliverable
production ML models | product features | infrastructure
Required skills
Incident response (triage, containment, eradication), malware analysis, forensic investigations, Python/JavaScript/PowerShell/Rust scripting, API development, SOAR platform management, SIEM/EDR integration, data correlation strategies, agentic AI/LLM application.
Preferred skills
CISSP, SANS GCIH/GCIA/GCFE, OSCP, CEH certifications, experience with cloud security platforms, LLM integration for security operations.
Technologies
SOAR, SIEM, EDR, Python, JavaScript, PowerShell, Rust, LLMs, GenAI, Cloud platforms, Ticketing systems.
Responsibilities
Manage severity 1 and 2 security incidents; design and maintain scalable automation solutions; develop forensic detective capabilities; operate on-call rotation as escalation point; prototype and deploy emerging AI-driven technologies; mentor analysts; collaborate with threat intelligence and engineering teams.
Seniority
Senior, hands-on IC with leadership responsibilities