Successful candidates will have experience in one or more of the following areas:
• Incident Handling: hands-on experience conducting and coordinating incident response across a broad range of security events, including the ability to manage multiple simultaneous incidents across hosts and customer environments. Experience investigating threats including host/user compromises, network breaches, organized crime, and advanced persistent threats.
•Threat Landscape Awareness: strong working knowledge of attack vectors, threat actor tactics, techniques, and procedures (TTPs), with demonstrated experience applying frameworks such as MITRE ATT&CK to active investigations.
• Computer Forensic Analysis: hands-on experience using forensic analysis tools in incident response investigations to determine the extent and scope of compromise.
• Malware Analysis: demonstrated ability to perform basic static and dynamic malware analysis to understand the nature and behavior of malicious code.
• Operating System Fundamentals: strong understanding of Windows, Mac, and/or Linux operating systems with emphasis on Windows internals such as the file system, registry, scheduled tasks, and running processes.
•Systems Administration: hands-on experience administering networks and resolving connectivity, authentication, and configuration issues across small to large enterprise environments.
• Network Analysis Fundamentals: strong working knowledge of network protocols and analysis tools, with experience analyzing network traffic to support incident investigations.
•Identity Platform Awareness: experience working with identity and access management platforms such as Okta, Microsoft Entra ID, Active Directory, and similar enterprise technologies.
•Email Security Awareness: experience investigating Microsoft 365 security incidents, including business email compromise (BEC) and adversary-in-the-middle (AITM) attacks.
• Third-Party Log Analysis: working knowledge of log sources across cloud platforms, network devices, identity providers, email platforms, and other enterprise technologies, with experience conducting investigation and triage within a SIEM platform.
• Incident Remediation: basic understanding of surgical remediation actions needed to contain threats across compromised hosts, including third-party platform containment measures.
• Network Operations and Architecture/Engineering: working knowledge of secure network architecture and hands-on experience troubleshooting and navigating network environments.
• Programming/Scripting: experience with scripting languages such as Python, PowerShell, or Bash to support investigation workflows or automate repetitive tasks.
• AI Fundamentals: experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.
• Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.
Additionally, all candidates must possess the following qualifications:
• Capable of completing technical tasks without supervision.
• Desire to grow and expand both technical and soft skills.
• Ability to foster a positive work environment and attitude.
• Must be willing to work 4x10 schedule, including a day on the weekend.
BA or BS / MA or MS degree in Computer Science, Computer Engineering, Math, Information Security, Information Assurance, Information Security Management, Intelligence Studies, Cybersecurity, Cybersecurity Policy, or a related field. Applicants without a degree but with relevant work experience and/or training will be considered.
This role may require the candidate to periodically undergo and pass alcohol and/or drug test(s) during the course of employment.