Analyst, Falcon Complete (Remote, NZD)
Core
Technical analyst in a virtual SOC detecting, containing, and remediating security incidents across endpoint, identity, email, network, and cloud environments.
Role type
Senior IC security incident responder (endpoint protection)
Builds
Real-time incident response and remediation for customer environments
Domain
Cybersecurity / Endpoint Protection / Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
Incident response coordination, EDR telemetry analysis, forensic artifact analysis, basic malware analysis, Windows internals, network protocol analysis, AI tool utilization
Preferred skills
MITRE ATT&CK framework application, Microsoft 365 security investigation, prompt engineering, agentic SOC workflows
Technologies
EDR platforms, forensic analysis tools, Microsoft 365, AI models
Responsibilities
Triage and investigate security detections across multiple environments; Analyze EDR telemetry and forensic artifacts to determine root cause; Investigate suspicious M365 activity including BEC and AITM attacks; Perform basic static and dynamic malware analysis; Develop processes for incident detection and countermeasures; Deliver clear customer communications during incident response
Seniority
Mid-level to Senior, hands-on IC