Detection & Response Analyst

Toyota Tsusho Systems

Plano (TX)

On-site

USD 90,000 - 130,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Toyota Tsusho Systems US, Inc. is seeking a Detection and Response Analyst to join our 24/7 Cyber Fusion Center in Plano, Texas. The role focuses on monitoring alerts, analyzing security events, and identifying indicators of compromise to prevent cyberattacks.

You will rotate shifts, leverage SIEM platforms, participate in threat hunting, and collaborate with multiple cybersecurity teams to drive remediation and improvements.

Qualifications

  • Minimum 3 years of cybersecurity experience focused on incident detection/response and SOC.
  • BA/BS in CS, Information Security, or IS or equivalent work experience.
  • Ability to communicate remediation actions to non-technical stakeholders.
  • Experience with SIEM and ticketing systems.
  • Familiarity with threat intelligence and incident response playbooks.
  • Certifications such as Security+, CYSA+, CASP+, GCFA, GCIH, GCFE are preferred.

Responsibilities

  • Monitor 24x7 Cyber Fusion Center and handle day/night shifts.
  • Query logs and correlate data across log sources using SIEM.
  • Detect and respond to security incidents with detection/response platforms.
  • Triage security incidents and perform analysis using IDS, firewalls, and other protections.
  • Escalate incidents per playbooks and SOPs.
  • Support incident response and remediation activities.
  • Contain threats during incidents and track details in the ticketing system.
  • Mentor and train team members; contribute to knowledge sharing.
  • Develop repeatable, improved processes and documentation.
  • Collaborate with other cybersecurity teams.

Skills

Cybersecurity experience
Customer communication
SIEM tools
Incident investigations
Cross-team collaboration
Security tools
Security certifications

Education

BA/BS in Computer Science, Information Security, or Information Systems

Tools

Splunk
MS Sentinel
Endpoint protection

Job description

About TTS-US:

Founded in 2011, Toyota Tsusho Systems US, Inc. (TTS-US) is a Toyota group company, that develops IT solutions wherever global businesses operate. Transforming into a technology and mobility company, TTS-US with it's 8 TTS affiliates worldwide is establishing a secure and resilient Toyota global value chain. The creative capacity to forge such limitless business opportunities is one of the strengths of Toyota Tsusho Systems.

Summary:

As part of the Incident Detection team, the Detection and Response Analyst will play an essential role in supporting our 24/7 Cyber Fusion Center, monitoring and responding to alerts to help prevent and mitigate cyberattacks. The Detection and Response Analyst conducts in-depth analysis of security events and requires the ability to identify indicators of compromise (IOCs), perform intrusion and root cause analysis, and proactively take actions to mitigate potential damage to our cyber ecosystem.

Essential Functions:
  • Work in 24x7 Cyber Fusion Center to provide monitoring and detection/response services. Work various 10-hour shifts, including weekends and work both day and night shifts. Shifts rotate quarterly.
  • Leverage SIEM to query logs and correlate across multiple log sources.
  • Detect and respond to security incidents by leveraging detection/response platforms.
  • Triage security incidents and perform in-depth analysis using cyber threat intelligence, intrusion detection systems, firewalls and other boundary protection devices.
  • Escalates cybersecurity events according to playbooks and standard operation procedures (SOPs).
  • Support Incident Response efforts as needed, including providing counsel, working with the IR team, as well as other involved stakeholders within the organization and customers to drive forward remediation activities.
  • Assist with containment and remediation of threats during incidents. Use internal ticketing system to track investigated incidents and capture relevant details.
  • Support Agentic SOC development through providing feedback, tuning, and feature requests for our engineering team to support accurate machine speed response.
  • Conduct threat hunting activities based on internal and external threat intelligence.
  • Assist with service requests from customers and internal teams.
  • Identify, recommend, coordinate, and deliver timely knowledge to support teams.
  • Report all information to the supervisor and upper management with updates as requested and respond to requests for information and assistance, including project progress and problems, particularly as needed to change in schedule, resources and scopes
  • Contribute to the creation of documentation to standardize processes and procedures, including playbooks to improve internal processes and procedures.
  • Work with team to establish repeatable and constantly improving processes.
  • Serve as mentor and provide training to other team members as needed.
  • Other tasks and responsibilities as assigned by leadership.
  • At least 3 years of cybersecurity experience with a focus on Incident Detection, Incident Response and/or Security Operations.
  • BA/BS in Computer Science, Information Security, or Information Systems or equivalent related work experience.
  • Experience interfacing with internal and external customers, providing remediation actions to non-technical audiences.
  • Working knowledge of enterprise-level security technologies such as SIEM and ticketing systems.
  • Experience in a highly collaborative environment with a focus on project delivery and desired business outcomes.
  • Experience with SIEM platforms, enterprise intrusion prevention systems, endpoint detection and response tools, and other security products.
  • Experience supporting large scale incident investigations.
  • Experience interfacing with a variety of cybersecurity teams (such as red team, cyber threat intelligence, data loss prevention, etc).
  • Security certifications such as: Security+, CYSA+, CASP+, GCFA, GCIH, GCFE
Competencies:
  • Strong technical background in security, network, infrastructure, AI, cloud, applications.
  • Understanding of AI, AI Security, and it’s practical applications.
  • Knowledge of risk assessment tools, technologies, and methods.
  • Firm grasp of networking and hacking concepts.
  • Expertise in designing secure networks, systems, and application architectures.
  • Knowledge around common web application attacks including SQL injection, cross-site scripting, invalid inputs, and forceful browsing.
  • Proficient knowledge of how common protocols & applications work at the network level, including DNS, HTTP, and SMB.
  • Proficient with SIEM technologies (Security Information and Event Management e.g., Splunk/MS sentinel or other SIEM TOOL).
  • Detail-orientated and analytical skills.
  • Problem-solving skills
  • Proficient with Microsoft Office & documentation skills (Word, Excel, PowerPoint)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection & Response Analyst
Detection & Response Analyst

Toyota Tsusho Systems US, Inc. • Plano (TX)

On-site
USD 90,000 - 115,000
Senior Detection & Response Analyst
Senior Detection & Response Analyst

Toyota Tsusho Systems US, Inc. • Plano (TX)

On-site
USD 120,000 - 180,000
24/7 Cyber Detection & Response Analyst
24/7 Cyber Detection & Response Analyst

Toyota Tsusho Systems US, Inc. • Plano (TX)

On-site
USD 90,000 - 115,000
Sr. Automation & Cybersecurity Engineer
Sr. Automation & Cybersecurity Engineer

Toyota Tsusho Systems US, Inc. • Plano (TX)

On-site
USD 120,000 - 180,000
Sr. Incident Response Analyst
Sr. Incident Response Analyst

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Security Incident Response Engineer
Security Incident Response Engineer

United States Digital Space LLC • United States

Hybrid
USD 125,000 - 165,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Assistant Manager - Security Engineering Project Delivery
Assistant Manager - Security Engineering Project Delivery

Toyota Tsusho Systems Corporation • Plano (TX)

On-site
USD 80,000 - 100,000
Manager, Threat Detection Engineer
Manager, Threat Detection Engineer

Jobtailor • Washington

On-site
USD 140,000 - 190,000
24/7 Detection & Response Analyst - Cyber Fusion
24/7 Detection & Response Analyst - Cyber Fusion

Toyota Tsusho Systems • Plano (TX)

On-site
USD 90,000 - 130,000