- Lead cybersecurity incident response activities, including investigation, containment, eradication, recovery, documentation, and stakeholder coordination
- Monitor, analyze, and investigate security alerts and events across endpoint, network, cloud, and identity security platforms
- Conduct threat hunting and advanced security investigations to identify malicious activity and emerging threats
- Support and maintain enterprise security monitoring technologies, endpoint security controls, and security operations infrastructure
- Perform risk assessments and vulnerability analysis and recommend remediation actions
- Deploy, maintain, and optimize security technologies and controls supporting security operations and monitoring
- Develop and maintain incident response procedures, operational playbooks, standards, and technical documentation
- Provide security consulting and guidance to IT staff, business units, and project teams
- Mentor junior analysts and facilitate knowledge sharing across the Security Operations team
- Perform additional duties as assigned
Requirements
- Bachelor of Science and 3 to 5 years of experience, or equivalent combination of education and experience, required
- Experience investigating cybersecurity incidents and performing incident response activities
- Experience with security monitoring, endpoint detection and response, or SIEM technologies
- Knowledge of network security, operating system security, vulnerability management, and threat detection methodologies
- Strong analytical, troubleshooting, organizational, documentation, and communication skills
- Security Operations Center experience preferred
- Experience with CrowdStrike Falcon, Microsoft Defender, LogScale, Splunk, or similar technologies preferred
- Experience with forensic analysis, threat hunting, cloud security, and security automation preferred
- Relevant security certifications preferred
- Bachelor of Science in Cybersecurity, Computer Science, Information Systems, Information Technology, or a related field preferred
- Security+, CySA+, GCIH, GCIA, CISSP, or equivalent certifications
Core Competencies
Demonstrates expertise in leading cybersecurity incident response activities, including investigation, containment, and recovery, while providing security consulting and guidance. Proficient in security monitoring technologies and threat detection methodologies, with a strong focus on mentoring and knowledge sharing within security operations.
Highest-signal resume keywords
- Cybersecurity Incident Response
- Security Monitoring Technologies
- Threat Hunting
- Vulnerability Management
- Security Certifications
ATS Optimization Keywords
Hard Skills
- Incident Response
- Threat Detection
- Vulnerability Analysis
- Forensic Analysis
- Security Automation
Soft Skills
- Analytical Skills
- Troubleshooting
- Organizational Skills
- Documentation
- Communication Skills
Certifications & Qualifications
- Security+
- CySA+
- GCIH
- GCIA
- CISSP
Industry Keywords
- Cybersecurity
- Security Operations Center
- Endpoint Security
- Cloud Security
- Network Security
Tools & Technologies
- CrowdStrike Falcon
- Microsoft Defender
- LogScale
- Splunk
- SIEM Technologies