Associate Solution Consultant – Security Incident Handler

Trellix

Irvine (CA)

Hybrid

USD 100,000 - 140,000

Full time

3 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Retirement plans
Medical, Dental and Vision
Paid Time Off
Community involvement support

Job summary

Trellix is seeking an Associate Solution Consultant – Security Incident Handler in Irvine, CA. This full-time hybrid role works with our Elite Security Operations Task Force to monitor, detect, and respond to cyber threats across customer environments.

You'll engage with client IT and security teams, perform incident response, host/network forensics, and produce DFIR reports. 3–4 years of security experience and a Bachelor's degree are required; Trellix offers a collaborative environment and

Qualifications

  • 3 to 4 years in Information Security, including security monitoring or incident response.
  • Bachelor's degree; CS/IT or related cyber field preferred.

Responsibilities

  • Manage client engagements related to security monitoring and incident response.
  • Operate within 24x7x365 CSIRT team in a hybrid setup.
  • Respond to security incidents in production environments and investigate malware/email threats.
  • Prepare end-of-engagement and DFIR reports for leadership.
  • Identify new client opportunities and consulting leads.

Skills

Cybersecurity
Incident response
Threat hunting
Security monitoring
Python scripting
PowerShell scripting

Education

Bachelor's Degree
CS/IT related degree

Tools

Trellix ePO
ENS (Endpoint Security)
Detection & Response (EDR)
ATD Sandbox
Threat Intelligence Exchange (TIE)
Data Exchange Layer (DXL)
Data Loss Prevention (DLP)
SIEM
XDR
Email Gateway ATP

Job description

Associate Solution Consultant – Security Incident Handler

Associate Solution Consultant – Security Incident Handler

About Trellix
Trellix is a global company redefining the future of cybersecurity. The company’s comprehensive, open, and native cybersecurity platform helps organizations confronted by today’s most advanced threats gain confidence in the protection and resilience of their operations. Trellix, along with an extensive partner ecosystem, accelerates technology innovation through artificial intelligence, automation, and analytics to empower over 50,000 business and government customers with responsibly architected security. More at https://trellix.com .

Role Overview:

Develops and delivers detailed IT and cybersecurity solutions through consulting project activities. Responsibilities include client identification through final invoicing for engagements requiring varied interpersonal and technical skills. Technical responsibilities include problem identification, security monitoring, rapid incident response, threat detection, system architecture definition, software specification/design, implementation, testing, client training, and solution deployment. Performance is typically evaluated based on utilization (i.e., billable hours). Project management activities include interaction with company and client managers and cost/schedule monitoring. May have financial responsibilities including project cost estimating, proposal generation, and invoicing. May participate in sales and proposal presentations in addition to completing ongoing team account activities. Identifies additional product/services opportunities within customer organizations. Performance is typically measured by the capture of the consulting engagement and/or delivery of agreed solutions within budgeted hours.

Job Description:

Trellix Professional Services is seeking a Security Incident Handler with a passion for Cyber Security Defense and a strong understanding of security monitoring and incident response.

We have an onsite Elite team—one of the best Cyber Security consulting teams—working directly with our strategic customer as a joint Security Operations Task Force, and growing this piece of the business is a top priority!

This is a full-time hybrid role (3 days onsite, 2 days remote) with Public Sector Professional Services. You will work hand in hand with the customer’s Cyber Security, IT, and business teams to ensure the highest security around all Trellix Solutions and broader Cyber Security ecosystems. The Computer Security Incident Response Team (CSIRT) is responsible for 24x7x365 security monitoring and rapid incident response across the customer’s environments. As the ‘tip of the spear’ and the last line of defense protecting customer data and assets from adversaries, you will exercise judgment within broadly defined practices and policies in selecting methods, techniques, and evaluation criteria for obtaining results.

Note: This position may require occasional after-business-hour and weekend on-call shifts.

About the Role:

Manage and perform client work related to our product service offerings, security monitoring, and incident response.

Act as an integral member of the joint Security Operation Task Force and CSIRT team in a 24x7x365 operations environment.

Respond to security incidents in a production environment, including investigating/remediating endpoint malware infections and mitigating email-borne threats (phishing/spam).

Conduct host and network forensics during security incidents, analyzing system artifacts (file system, memory, running processes, network connections) for indicators of compromise (IOCs).

Identify and mitigate vulnerabilities using alternate or compensating controls where necessary.

Recognize potential security violations, report incidents as required by regulations, and mitigate adverse impacts.

Create end-of-engagement reports, technical DFIR (Digital Forensics & Incident Response) reports, and executive summaries describing findings and analysis.

Author formal reports, architecture designs, optimization guides, and best-practice white papers covering a variety of security topics.

Interact with company and client managers on cost/schedule monitoring, estimating, proposal generation, and invoicing.

Help identify and develop new client opportunities, expert services engagements, and potential consulting sales leads.

Maintain technical proficiency through self-training or formal training while sharing knowledge and mentoring consultant peers.

About You:

Experience: 3 to 4 years’ experience in Information Security, including operational security monitoring or incident response.

Education: Bachelor's Degree; technical degree or diploma preferred in computer science, information technology, or a related cyber field.

Core Technical Expertise:

Understanding of cyber threats, attack vectors, detection capabilities, incident management processes, and compensating security controls.

Experience monitoring and leveraging Trellix products: Trellix ePO, Endpoint Security (ENS), Trellix Detection & Response / Active Response (EDR), Advanced Threat Defense (ATD Sandbox), Threat Intelligence Exchange (TIE), Data Exchange Layer (DXL), Data Loss Prevention (DLP), SIEM, XDR, and Email Gateway ATP.

Monitoring and log analysis across Network/Host IDSs, UEBA, WAFs, Database Security, Firewalls/Routers/Switches/VPNs, File Integrity Monitoring (FIM), Active Directory, and OS logs.

Host and network forensics capabilities, system artifact analysis, and threat hunting methodologies.

Basic technical understanding of the MITRE ATT&CK™ framework and MITRE’s Ten Strategies of a World-Class Cybersecurity Operations Center .

Knowledge of TCP/IP protocol suites (packet/traffic dissection) and OS logging configuration (Syslog, flat-files).

Familiarity with Windows, Mac, and Linux OS administration, application hardening, and security controls.

Strong Linux and Python skills are preferred. Experience with PowerShell, Perl, Go, C#, or general shell scripting is a significant plus.

Understanding of relevant infrastructure technologies: Virtualization (VMware, Nutanix) and Cloud Services (AWS, Azure).

Soft Skills & Professionalism:

Excellent client-facing presentation, verbal, and written communication skills (ability to communicate with technical staff and executive leadership).

Advanced proficiency in Microsoft Office Suite (Word, Excel, PowerPoint).

Ability to prioritize and manage multiple tasks independently in a high-tempo environment.

Company Benefits and Perks:

We believe that the best solutions are developed by teams who embrace each other's unique experiences, skills, and abilities. We work hard to create a dynamic workforce where we encourage everyone to bring their authentic selves to work every day. We offer a variety of social programs, flexible work hours and family-friendly benefits to all of our employees.

  • Retirement Plans
  • Medical, Dental and Vision Coverage
  • Paid Time Off
  • Support for Community Involvement

We're serious ab out our commitment to a workplace where everyone can thrive and contribute to our industry-leading products and customer support, which is why we prohibit discrimination and harassment based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status.

Our Commitment to You:

At Trellix, we are committed to creating a safe and trustworthy experience for our customers, employees, and candidates. Please be aware that fraudulent recruiting activity can occur through fake job postings or impersonated communications.

Trellix conducts interviews through professional channels only and does not use text messages, instant messaging, or group chats for interviews. We will never request sensitive personal information—such as your date of birth, Social Security number, or national ID number—during the interview process.

Trellix also does not require candidates to pay fees, purchase products or services, or process payments of any kind as part of the recruiting or hiring process. And Trellix will never keep any original work authorization documents that we may be required to review during the hiring process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Threat Hunter (TS/SCI Clearance Required)
Cyber Threat Hunter (TS/SCI Clearance Required)

Trellix • Fairfax (VA)

On-site
USD 120,000 - 170,000
Retirement Plans
Medical, Dental and Vision Coverage
Paid Time Off
+1
Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

Trellix • Reston (VA)

On-site
USD 120,000 - 170,000
Retirement Plans
Medical, Dental and Vision Coverage
Paid Time Off
+1
Senior Community Engagement Manager
Senior Community Engagement Manager

Trellix • Northern (KY)

Hybrid
USD 80,000 - 120,000
Retirement Plans
Medical, Dental and Vision Coverage
Paid Time Off
+1
Senior Community Engagement Manager
Senior Community Engagement Manager

Trellix • Dover (DE)

On-site
USD 90,000 - 125,000
Retirement Plans
Medical, Dental and Vision Coverage
Paid Time Off
+2
Senior Manager, Transformation
Senior Manager, Transformation

Trellix • United States

On-site
USD 150,000 - 180,000
Retirement Plans
Medical, Dental and Vision Coverage
Paid Time Off
+2
Senior Manager, Customer Success
Senior Manager, Customer Success

Trellix • Northern (KY)

Hybrid
USD 140,000 - 190,000
Retirement Plans
Medical, Dental and Vision Coverage
Paid Time Off
+2
Content Marketing Manager
Content Marketing Manager

Trellix • United States

Remote
USD 120,000 - 150,000
Retirement plans
Medical, Dental and Vision Coverage
Paid Time Off
+1
Major Account Executive, SouthEast
Major Account Executive, SouthEast

Trellix • Atlanta (GA)

On-site
USD 150,000 - 335,000
Retirement Plans
Medical, Dental and Vision Coverage
Paid Time Off
+1
SLED & Healthcare Account Executive
SLED & Healthcare Account Executive

Trellix • Fairfax (VA)

On-site
USD 135,000 - 160,000
Retirement Plans
Medical, Dental and Vision Coverage
Paid Time Off
+1
Technical Support Engineer
Technical Support Engineer

Trellix • Plano (TX)

On-site
USD 70,000 - 80,000
Retirement Plans
Medical, Dental and Vision Coverage
Paid Time Off
+1