Lead the analysis and response to security anomalies, intrusion attempts, and breaches; perform root-cause analysis, containment, and comprehensive post-incident reporting.
Conduct advanced threat hunting to identify undetected threats using data from endpoints, servers, cloud environments, and network traffic.
Act as the senior escalation point for the SOC, providing expert analysis on complex security tickets.
Continuously improve incident response policies, playbooks, and SOC operational processes.
Analyze and mitigate web-based security events using CDN security solutions (e.g., Akamai, Cloudflare).
Collaborate effectively with internal engineering and business teams through clear, technical, and executive-level communication.
Participate in an on-call rotation to respond to urgent security incidents or emerging threats.
Requirements
You have 8+ years in Information Security, with at least 5+ years specifically dedicated to Cyber Security Incident Response (CSIRT) or Digital Forensics.
Experienced in host-based investigations across Windows, Linux, and various network/security appliances.
A professional with hands-on experience analyzing security events within AWS, Azure or other major Cloud environments.
Knowledgeable of analyzing events from EDR, HIPS, DLP, IPS/IDS, and SaaS solutions (e.g., Google Worksapce, O365, Email Security).
Proficient in managing and analyzing logs from Web Security solutions like Akamai or Cloudflare.
Skilled in querying SIEM solutions and analyzing "big data" or high-volume logs to identify patterns of compromise.
Able to automate response workflows and script in Python, Bash, or PowerShell.
Graduate in Computer Science, Cybersecurity, or equivalent practical experience.
Experience operating SIEM platforms and developing custom detection use cases.
Deep understanding of container security and orchestration (Kubernetes, Docker).
Advanced knowledge of network traffic/packet analysis and network forensics.
Relevant industry certifications such as GCIH, GCFA, GNFA, CISSP, or OSCP.
Tech Stack
AWS
Azure
Cloud
Cyber Security
Docker
Kubernetes
Linux
Python
Benefits
Health insurance for the whole family, flexible working environment and well-being support and tools
Extra days off, sabbatical program and days for you to give back for the community