Investigate security alerts, perform in-depth analysis, and respond to cybersecurity events in real-time
Implement containment to limit the impact of security threats while ensuring business continuity
Identify, analyze, & respond to web-based threats, including SQL injection, credential stuffing, server-side request forgery, cross-site scripting, and other vulnerabilities
Collaborate with cross-functional teams to manage and resolve security incidents swiftly & effectively
Analyze adversarial tactics and recommend detection & protection strategies
Lead postmortem reviews, conduct root cause analyses, and drive remediation efforts
What You’ll Bring
Proficiency in one or more of the following areas: Detection Engineering, Incident Response, Security Operations, DFIR, Security DevOps, SecOps, Threat Hunting, Site Reliability Engineering
Experience leading multiple stakeholders such as engineering/operations teams, internal business units, and external incident response teams throughout the incident lifecycle
Experience performing large-scale log analysis across diverse & uncommon log sources; familliarity with Splunk, Elastic, or similar tools is a plus
Experience working with/in Linux containers & orchestration systems (Kubernetes) and cloud environments (AWS)
Familiarity with security event correlation, data visualization, graphing, timelines, trending, behavioral analytics and/or anomaly detection is a plus
Familiarity with endpoint tools & investigations, network traffic analysis, and/or phishing & social engineering countermeasures is a plus
Critical thinking, problem-solving & investigative mindset; ability to operate at scale and adapt to change in complex and diverse environments