CSIRT Analyst

Computer Task

United States

On-site

USD 85,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CTG is seeking a CSIRT Analyst to strengthen the blue team and help organizations under attack. You will handle alerts escalated by the SOC, conduct DFIR readiness assessments, and participate in weekly threat hunting using advanced MDR tools.

The role requires 3–5 years in a similar position, hands-on forensics experience, and a degree or equivalent. Proactive, with a can‑do mindset and experience with MDR tools and SIEM/xDR is preferred.

Qualifications

  • 3–5 years of experience in a similar CSIRT/IR role.
  • Hands-on disk, memory and log acquisition for forensics.
  • Bachelor or master degree or equivalent through experience.
  • Proactive, can-do mindset with team orientation.
  • Experience with MDR tools: CrowdStrike, Defender, SentinelOne, etc.
  • Knowledge of Security Monitoring with SIEM technologies.
  • Passion for Security Monitoring, DFIR, Threat Intelligence, Threat Hunting.

Responsibilities

  • Handle security alerts/incidents escalated by SOC Analysts (Tier 2).
  • Collaborate with team to investigate and resolve security events.
  • Conduct DFIR assignments and readiness assessments.
  • Participate in weekly Threat Hunting using TTPs.
  • Perform compromise assessments to identify scope and impact.
  • Collect Threat Intelligence (IOCs and TTPs).
  • Contribute to Detection Engineering in SIEM/XDR.
  • Engage in Purple Teaming with Red Team to test defenses.
  • Create playbooks in SOAR and co-write DFIR processes.

Skills

Threat Hunting
Incident Response
Digital Forensics
Threat Intelligence
Security Monitoring
SIEM
XDR
Purple Teaming

Education

Bachelor or Master degree or equivalent

Tools

CrowdStrike Falcon
Defender for Endpoint
SentinelOne
Vectra
Darktrace
Identity Protection

Job description

Do you have a passion for Cyber Security, especially advanced Managed Detection & Response (MDR)? Does Incident Response, Digital Forensics, Threat Hunting, Threat Intelligence and everything related to Cyber Security feel like second nature to you? Are you a Cyber Defender at heart, driven to strengthen the blue team and help organizations that are under attack? If you answered yes to all of these questions, you might be the perfect fit for our CSIRT Analyst role!

  • You handle security alerts/incidents that have been escalated by the SOC Analysts (Tier 2)
  • You will handle security alerts and incidents together with your team
  • You conduct DFIR assignments, including DFIR readiness assessments
  • You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
  • You will perform compromise assessments to identify potential compromises and their scope
  • You collect Threat Intelligence (IOCs and TTPs)
  • You will contribute to Detection Engineering in SIEM, xDR.
  • Together with the Red Team you will do Purple Teaming exercises to test and improve defenses
  • You contribute to the creation of playbooks in SOAR
  • You will co-write processes and procedures related to DFIR, Threat Intelligence, Threat Hunting.
  • You will be part of our Incident Response on call service.
What you need to succeed:
  • At least 3-5 years of experience in a similar position.
  • Significant hands‑on experience in disk, memory and log acquisition in a forensically sound manner, parsing and deep forensic analysis of extracted artifacts and professional post‑incident report writing
  • A bachelor or master degree or equivalent through experience.
  • A hands‑on and proactive mindset with a 'can do' mentality.
  • Experience and/or interest in working with the following MDR tools: EDR (CrowdStrike Falcon, MS Defender for Endpoint, Sentinel One, ...), NDR (Vectra, Darktrace, ...), xDR (CrowdStrike Identity Protection, MS Defender for Office/Clouds Apps/Identity/...).
  • Knowledge of Security Monitoring with SIEM technologies.
  • A passion about the following security capabilities: Security Monitoring, Digital Forensics, Incident Response, Threat Intelligence, Threat Hunting.
About CTG

CTG, a Cegeka company, delivers IT and business solutions that enhance clients’ digital agility, empowering them to seize new opportunities and overcome any challenge. Backed by more than 60 years’ experience and a commitment to being a reliable, results‑driven partner, we work shoulder to shoulder with clients to shape digital together. Our vision is to be an indispensable partner to our clients and the preferred career destination for digital and technology experts. With more than 9,000 team members in over 15 countries, we combine global expertise with local insight to deliver innovative solutions. We operate across the Americas, Europe, and India, working with over 3,000 clients in many of today’s highest‑growth industries.

Together, we shape what’s next - working shoulder to shoulder to deliver impactful solutions for our clients and society. Our culture is built by the people who work at CTG, the values we hold, and the actions we take. It's a living, breathing thing that is renewed every day through the ways we engage with each other, our clients, and our communities. At CTG, you’ll find a workplace where you are encouraged to grow, supported in your ambitions, and empowered to shape your own career journey. For more information, visit www.ctg.com.

CTG will consider for employment all qualified applicants including those with criminal histories in a manner consistent with the requirements of all applicable local, state, and federal laws.

CTG is an Equal Opportunity Employer. CTG will assure equal opportunity and consideration to all applicants and employees in recruitment, selection, placement, training, benefits, compensation, promotion, transfer, and release of individuals without regard to race, creed, religion, color, national origin, sex, sexual orientation, gender identity and gender expression, age, disability, marital or veteran status, citizenship status, or any other discriminatory factors as required by law. CTG is fully committed to promoting employment opportunities for members of protected classes.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CSIRT Analyst
CSIRT Analyst

Computer Task • Buffalo (NY)

On-site
USD 80,000 - 120,000
Senior SOC Analyst
Senior SOC Analyst

Computer Task • Buffalo (NY)

Hybrid
USD 110,000 - 120,000
Health insurance
401K
Paid time off
Cyber Defense Analyst: Incident Response & Threat Hunting
Cyber Defense Analyst: Incident Response & Threat Hunting

Computer Task • United States

On-site
USD 85,000 - 120,000
CSIRT Analyst - MDR, DFIR & Threat Hunting
CSIRT Analyst - MDR, DFIR & Threat Hunting

Computer Task • Buffalo (NY)

On-site
USD 80,000 - 120,000
CSIRT Analyst
CSIRT Analyst

Page Mechanical Group, Inc. • Mississippi

On-site
USD 70,000 - 80,000
Medical plan options
Dental and vision coverage
401(k) retirement savings plan
+2
Security Operations Center Analyst
Security Operations Center Analyst

TECHEAD • Richmond (VA)

Hybrid
USD 80,000 - 100,000
CTI Cybersecurity Analyst - Sr
CTI Cybersecurity Analyst - Sr

TMC TECHNOLOGIES • Huntsville (AL)

On-site
USD 110,000 - 140,000
Senior Cyber Security Engineer / CSET
Senior Cyber Security Engineer / CSET

Scientific Research Corporation • Orlando (FL)

On-site
USD 100,000 - 140,000
Cyber Detection & Response Analyst
Cyber Detection & Response Analyst

Control Risks • San Francisco (CA)

Hybrid
USD 120,000 - 140,000
Medical Benefits
401(k) Retirement
Hybrid work
+1
Security Analyst II - SOC
Security Analyst II - SOC

Cyderes • Kansas City (MO)

On-site
USD 60,000 - 100,000