CSIRT Analyst

CTG

Buffalo (NY)

On-site

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CTG Buffalo is seeking a CSIRT Analyst to strengthen our blue team. You will handle elevated security alerts and incidents, perform DFIR tasks, and participate in proactive threat hunting using diverse tools. You will contribute to SIEM/xDR detections and co‑lead purple team exercises with the Red Team.

Ideal candidates have 3–5 years of hands-on incident response experience, solid forensics skills, and a proactive mindset. A bachelor's or master's degree or equivalent experience is expected.

Qualifications

  • 3–5 years of experience in a similar role.
  • Hands-on disk, memory and log acquisition in a forensically sound manner with post-incident reporting.
  • A bachelor or master degree or equivalent through experience.
  • Hands-on and proactive mindset with a can-do attitude.
  • Experience with MDR tools like CrowdStrike, Defender, SentinelOne, and related technologies.
  • Knowledge of security monitoring with SIEM technologies.

Responsibilities

  • Handle security alerts/incidents escalated by SOC Analysts (Tier 2).
  • Collaborate with the team to address security events and incidents.
  • Conduct DFIR assignments, including DFIR readiness assessments.
  • Participate in weekly Threat Hunting duty to proactively identify threats.
  • Perform compromise assessments to identify scope and impact.
  • Collect Threat Intelligence (IOCs and TTPs).
  • Contribute to Detection Engineering in SIEM and xDR.
  • Work with Red Team for Purple Teaming exercises to improve defenses.
  • Co-write processes and procedures related to DFIR, Threat Intelligence, and Threat Hunting.
  • Be part of Incident Response on-call service.

Skills

Security monitoring
Incident response
Threat hunting
DFIR
SIEM

Education

Bachelor or Master degree

Tools

CrowdStrike Falcon
MS Defender for Endpoint
SentinelOne
Vectra
Darktrace
SOAR playbooks

Job description

Do you have a passion for Cyber Security, especially advanced Managed Detection & Response (MDR)? Does Incident Response, Digital Forensics, Threat Hunting, Threat Intelligence and everything related to Cyber Security feel like second nature to you? Are you a Cyber Defender at heart, driven to strengthen the blue team and help organizations that are under attack? If you answered yes to all of these questions, you might be the perfect fit for our CSIRT Analyst role!

  • You handle security alerts/incidents that have been escalated by the SOC Analysts (Tier 2)
  • You will handle security alerts and incidents together with your team
  • You conduct DFIR assignments, including DFIR readiness assessments
  • You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
  • You will perform compromise assessments to identify potential compromises and their scope
  • You collect Threat Intelligence (IOCs and TTPs)
  • You will contribute to Detection Engineering in SIEM, xDR.
  • Together with the Red Team you will do Purple Teaming exercises to test and improve defenses
  • You contribute to the creation of playbooks in SOAR
  • You will co-write processes and procedures related to DFIR, Threat Intelligence, Threat Hunting.
  • You will be part of our Incident Response on call service.

What you need to succeed:

  • At least 3-5 years of experience in a similar position.
  • Significant hands-on experience in disk, memory and log acquisition in a forensically sound manner, parsing and deep forensic analysis of extracted artifacts and professional post-incident report writing
  • A bachelor or master degree or equivalent through experience.
  • A hands-on and proactive mindset with a 'can do' mentality.
  • Experience and/or interest in working with the following MDR tools: EDR (CrowdStrike Falcon, MS Defender for Endpoint, Sentinel One, ...), NDR (Vectra, Darktrace, ...), xDR (CrowdStrike Identity Protection, MS Defender for Office/Clouds Apps/Identity/...).
  • Knowledge of Security Monitoring with SIEM technologies.A passion about the following security capabilities: Security Monitoring, Digital Forensics, Incident Response, Threat Intelligence, Threat Hunting.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CSIRT Analyst
CSIRT Analyst

Computer Task • Buffalo (NY)

On-site
USD 80,000 - 120,000
CSIRT Analyst - MDR, DFIR & Threat Hunting
CSIRT Analyst - MDR, DFIR & Threat Hunting

Computer Task • Buffalo (NY)

On-site
USD 80,000 - 120,000
Cybersecurity Analyst
Cybersecurity Analyst

EXOS • Indianapolis (IN)

On-site
USD 90,000 - 120,000
Senior Detection & Response Analyst
Senior Detection & Response Analyst

Remote Jobs • United States

On-site
USD 110,000 - 190,000
Senior Security Analyst – Security Operations Center
Senior Security Analyst – Security Operations Center

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Sr. SOC Analyst
Sr. SOC Analyst

Insight Global • Santa Ana (CA)

On-site
USD 120,000 - 150,000
Sr. Cyber Defense Analyst
Sr. Cyber Defense Analyst

Patriot Talent Solutions • United States

On-site
USD 120,000 - 190,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Cybersecurity Engineer
Cybersecurity Engineer

Vortalsoft Inc • New Jersey

On-site
USD 90,000 - 130,000