We are looking for highly motivated and skilled CSIRT Investigators to join our dynamic security team in the United States. You will be at the forefront of identifying and investigating security incidents, and contributing to the continuous improvement of our incident response capabilities. This role requires a strong technical background, participation in on-call rotations, excellent analytical skills, and a proactive approach to cybersecurity. This position is an individual contributor role reporting to the Sr. Manager of CSIRT. Responsibility Leverage AI and machine learning tools to enhance the efficiency of log analysis, alert triage, and threat hunting Monitor for and investigate security incidents involving AI/ML models, such as adversarial attacks, prompt injection, and model evasion Collaborate with detection engineering to develop and tune AI-based detection logic to improve SOC visibility Research and adopt emerging AI-driven security technologies to evolve CSIRT’s proactive defense capabilities Perform initial triage and in-depth analysis of security alerts generated from our SIEM and other security monitoring tools Correlate events from various log sources to identify potential security incidents Determine the scope, severity, and potential impact of detected threats Conduct technical investigations into cybersecurity incidents, including malware analysis, phishing attacks, web application compromises, and insider threats Utilize digital forensics techniques on data and endpoints to gather evidence and understand incident timelines and methods Support incident containment, eradication, and recovery efforts under the guidance of the CSIRT Manager Document incident findings, actions taken, and lessons learned Assist in the development and refinement of threat detection rules to improve SOC visibility Participate in proactive threat hunting activities to uncover hidden threats within the enterprise environment Stay informed about the latest threat intelligence and emerging attack techniques Work with SIEM and SOAR platforms to optimize alert processing and incident workflows Contribute to the creation and refinement of automated solutions for efficient incident response and reporting Identify opportunities for automation to streamline security operations Collaborate effectively with other security teams, IT, and business units during incident response Provide clear and concise updates on incident status to the CSIRT Manager Contribute to post-incident reports and analysis Maintain working relationships with law enforcement when required