Associate Principal, Cyber Defense
Core
In-depth analysis and response to escalated security incidents, investigating complex events, and implementing mitigation measures to maintain organizational security posture.
Role type
Associate Principal, Cyber Defense (Senior IC)
Builds
Security incident response capabilities and detection mechanisms for a financial market utility.
Domain
Cybersecurity / Financial Services
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Advanced threat intelligence, incident response techniques, security log analysis, network traffic analysis, endpoint data analysis, containment and eradication strategies, post-incident review, security playbook development, API integration for security tools, threat actor methodology knowledge, network exploitation understanding, cloud security techniques, operating system hardening, vulnerability assessment, directory services security, web application firewall management.
Preferred skills
NIST Cyber Security Framework implementation, SOAR playbook development, scripting for security integrations, project management, financial services industry experience.
Technologies
Splunk, IBM QRadar, LogRhythm, Splunk SOAR, Cortex XSOAR, FortiSOAR, CrowdStrike, SentinelOne, Microsoft Defender, Qualys, Nessus, nmap, Active Directory, Entra ID, AWS, Azure, GCP, Solaris, Linux, Windows, IDS/IPS, firewalls, proxy servers, Web Application Firewalls.
Responsibilities
Monitor security alerts and events from various security tools; Perform advanced analysis of security logs, network traffic, and endpoint data; Review and respond to security incidents escalated by Tier 1 analysts; Conduct thorough investigations to determine the scope and impact of security incidents; Implement containment, eradication, and recovery measures for confirmed incidents; Document and report findings, actions taken, and lessons learned; Provide guidance and support to Tier 1 analysts on complex security issues; Participate in post-incident reviews to identify areas for improvement.
Seniority
Senior, hands-on IC