Join our Cyber Defense Center as a Senior Security Operations Specialist and become part of a global team dedicated to safeguarding our organization's people, systems, and data.
As a member of our Security Operations Center (SOC), you will lead the investigation and response to complex cyber threats, drive continuous improvement of detection and response capabilities, and act as a senior escalation point for the SOC team. Using advanced security technologies, threat intelligence, and proactive threat hunting techniques, you will play a key role in protecting our global environment against sophisticated adversaries.
Responsibilities
- Investigate, validate, and respond to complex security incidents escalated by CrowdStrike Falcon Complete MDR Service, SOC analysts, users, and other IT departments.
- Lead investigations of advanced security incidents using CrowdStrike Falcon, Microsoft Defender, SIEM platforms, and other security technologies.
- Analyze alerts, suspicious activity, attack patterns, and threat actor behavior using endpoint telemetry, threat intelligence, cloud telemetry, and SIEM data.
- Perform advanced root cause analysis, determine attack scope and impact, and provide detailed findings and recommendations.
- Lead containment, eradication, and recovery activities for major security incidents.
- Conduct proactive threat hunting activities and initiate investigations based on intelligence, emerging threats, and hypothesis-driven analysis.
- Coordinate with Incident Response, Infrastructure, Cloud, Identity, and Business teams during major cyber incidents.
- Produce high-quality incident reports, executive summaries, lessons learned, and technical documentation.
- Collaborate with the Global SOC team and cybersecurity stakeholders to strengthen operational effectiveness and security monitoring maturity.
- Lead the development, optimization, and maintenance of incident response playbooks, use cases, and operating procedures.
- Stay up to date with emerging cybersecurity threats, attack techniques, adversary tradecraft, and security technologies.
- Develop and tune detection rules, analytics, and correlation logic to improve SOC visibility and effectiveness.
- Perform advanced threat modeling and map detections to the MITRE ATT&CK framework.
- Mentor junior and mid-level SOC analysts and provide technical guidance during investigations.
- Act as a senior escalation point for high-severity incidents and provide incident leadership during major cyber events.
- Identify security gaps, recommend strategic improvements, and drive implementation of detection and response enhancements.
- Support purple-team exercises, tabletop exercises, and adversary emulation activities to validate security controls.