CSIRT Analyst

Computer Task

Northern (KY)

Hybrid

USD 90,000 - 130,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

CTG is seeking a CSIRT Analyst to join our security operations to defend against cyber threats. You will handle security alerts escalated by SOC, perform DFIR tasks, and participate in proactive threat hunting using modern MDR tools and SIEM/xDR platforms.

This role includes on-call incident response and collaboration across Red/Blue teams. The ideal candidate has 3–5 years of relevant experience, hands-on forensics capabilities, and a degree or equivalent experience, with a proactive, can-do

Qualifications

  • 3–5 years in a similar CSIRT/IR role.
  • Hands-on disk, memory and log acquisition with forensic rigor.
  • Strong post-incident reporting and documentation.
  • Bachelor or Master degree or equivalent experience.

Responsibilities

  • Handle security alerts/incidents escalated by SOC Analysts (Tier 2).
  • Collaborate with team on incidents and DFIR assignments.
  • Participate in weekly Threat Hunting duties with TTPs.
  • Perform compromise assessments to identify scope.
  • Collect Threat Intelligence (IOCs and TTPs).
  • Contribute to Detection Engineering in SIEM/xDR/SOAR.
  • Co-write processes for DFIR, Threat Intelligence, Threat Hunting.
  • Be part of Incident Response on-call service.

Skills

Incident Response
Threat Hunting
Digital Forensics
Threat Intelligence
Security Monitoring
MDR Tools
SIEM

Education

Bachelor's degree

Tools

CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne
Vectra
Darktrace
CrowdStrike Identity Protection
Microsoft Defender for Office/Cloud Apps/Identity
SOAR

Job description

Do you have a passion for Cyber Security, especially advanced Managed Detection & Response (MDR)? Does Incident Response, Digital Forensics, Threat Hunting, Threat Intelligence and everything related to Cyber Security feel like second nature to you? Are you a Cyber Defender at heart, driven to strengthen the blue team and help organizations that are under attack? If you answered yes to all of these questions, you might be the perfect fit for our CSIRT Analyst role!

  • You handle security alerts/incidents that have been escalated by the SOC Analysts (Tier 2)
  • You will handle security alerts and incidents together with your team
  • You conduct DFIR assignments, including DFIR readiness assessments
  • You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
  • You will perform compromise assessments to identify potential compromises and their scope
  • You collect Threat Intelligence (IOCs and TTPs)
  • You will contribute to Detection Engineering in SIEM, xDR.
  • Together with the Red Team you will do Purple Teaming exercises to test and improve defenses
  • You contribute to the creation of playbooks in SOAR
  • You will co-write processes and procedures related to DFIR, Threat Intelligence, Threat Hunting.
  • You will be part of our Incident Response on call service.
What you need to succeed:
  • At least 3-5 years of experience in a similar position.
  • Significant hands-on experience in disk, memory and log acquisition in a forensically sound manner, parsing and deep forensic analysis of extracted artifacts and professional post-incident report writing
  • A bachelor or master degree or equivalent through experience.
  • A hands-on and proactive mindset with a 'can do' mentality.
  • Experience and/or interest in working with the following MDR tools: EDR (CrowdStrike Falcon, MS Defender for Endpoint, Sentinel One, ...), NDR (Vectra, Darktrace, ...), xDR (CrowdStrike Identity Protection, MS Defender for Office/Clouds Apps/Identity/...).
  • Knowledge of Security Monitoring with SIEM technologies.
  • A passion about the following security capabilities: Security Monitoring, Digital Forensics, Incident Response, Threat Intelligence, Threat Hunting.
About CTG

CTG, a Cegeka company, delivers IT and business solutions that enhance clients’ digital agility, empowering them to seize new opportunities and overcome any challenge. Backed by more than 60 years’ experience and a commitment to being a reliable, results-driven partner, we work shoulder to shoulder with clients to shape digital together. Our vision is to be an indispensable partner to our clients and the preferred career destination for digital and technology experts. With more than 9,000 team members in over 15 countries, we combine global expertise with local insight to deliver innovative solutions. We operate across the Americas, Europe, and India, working with over 3,000 clients in many of today's highest-growth industries.

Together, we shape what’s next—working shoulder to shoulder to deliver impactful solutions for our clients and society. Our culture is built by the people who work at CTG, the values we hold, and the actions we take. It's a living, breathing thing that is renewed every day through the ways we engage with each other, our clients, and our communities. At CTG, you’ll find a workplace where you are encouraged to grow, supported in your ambitions, and empowered to shape your own career journey. For more information, visit www.ctg.com.

CTG will consider for employment all qualified applicants including those with criminal histories in a manner consistent with the requirements of all applicable local, state, and federal laws.

CTG is an Equal Opportunity Employer. CTG will assure equal opportunity and consideration to all applicants and employees in recruitment, selection, placement, training, benefits, compensation, promotion, transfer, and release of individuals without regard to race, creed, religion, color, national origin, sex, sexual orientation, gender identity and gender expression, age, disability, marital or veteran status, citizenship status, or any other discriminatory factors as required by law. CTG is fully committed to promoting employment opportunities for members of protected classes.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

CSIRT Analyst
CSIRT Analyst

Computer Task • United States

On-site
USD 85,000 - 120,000
CSIRT Analyst
CSIRT Analyst

Computer Task • Buffalo (NY)

On-site
USD 80,000 - 120,000
CSIRT Analyst: Incident Response & Threat Hunting Expert
CSIRT Analyst: Incident Response & Threat Hunting Expert

Computer Task • Northern (KY)

Hybrid
USD 90,000 - 130,000
Cyber Defense Analyst: Incident Response & Threat Hunting
Cyber Defense Analyst: Incident Response & Threat Hunting

Computer Task • United States

On-site
USD 85,000 - 120,000
CSIRT Analyst - MDR, DFIR & Threat Hunting
CSIRT Analyst - MDR, DFIR & Threat Hunting

Computer Task • Buffalo (NY)

On-site
USD 80,000 - 120,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Security Operations Center Analyst
Security Operations Center Analyst

TECHEAD • Richmond (VA)

Hybrid
USD 80,000 - 100,000
Cyber Security Analyst
Cyber Security Analyst

Synergy Business Consulting, Inc. • Tampa (FL)

On-site
USD 75,000 - 105,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Lockton • North Kansas City (MO)

On-site
USD 110,000 - 160,000
CTI Cybersecurity Analyst - Sr
CTI Cybersecurity Analyst - Sr

TMC TECHNOLOGIES • Huntsville (AL)

On-site
USD 110,000 - 140,000