Long-Term Contract Job Description You will join our Operational Security team, a group of dedicated professionals who serve as our organization's initial line of defense. In this collaborative environment, you will work closely with senior analysts to monitor security alerts across our enterprise telemetry, investigate potential threats, and support critical incident response efforts. Our team thrives on shared expertise and hands-on experience with diverse technologies to protect our infrastructure. What You'll Do Monitor security alerts from various telemetry sources (SIEM, IDS/IPS, EDR) and escalate anomalies as necessary. Conduct initial triage, analysis, and classification of security incidents. Document investigative findings and assist in comprehensive incident response. Follow established incident response procedures and escalate to senior analysts when required. Gather threat intelligence to proactively enhance security monitoring capabilities. Create, maintain, and review internal documentation for processes and procedures. Implement cloud security reference architectures and guardrails rooted in Zero Trust and Least Privilege principles. Support vulnerability management by identifying potential security weaknesses across the enterprise. Conduct investigations and provide necessary triage, containment, and forensic support during cloud-based security incidents. Stay informed on emerging threats, vulnerabilities, and cybersecurity trends. Collaborate with cross-functional teams to ensure timely resolution of security incidents, providing guidance and recommendations. Participate in project work, including proof-of-concepts (PoCs) for new tools and optimizations of existing technologies. Qualifications Bachelor's degree in Cybersecurity, Computer Science, or a related technical field (or equivalent practical experience). A minimum of 5 years of progressive experience within Information Security, specifically including 2 or more years dedicated to Cloud security initiatives. Strong foundational understanding of both macOS and Windows environments.
Technical Skills:
Familiarity with SIEM tools, logging platforms, firewalls, antivirus, and EDR solutions. Core understanding of network protocols (TCP/IP, DNS) and security architecture. Basic scripting knowledge (Python, PowerShell, or Bash) is a plus. Experience with
SIEM & SOAR
administration is desirable but not essential. Demonstrated proficiency with a minimum of two major public cloud platforms (Google Cloud Platform and Azure preferred; AWS and OCI are advantageous).
Professional Skills:
Strong analytical problem-solving abilities, excellent communication skills, and the ability to thrive in a fast-paced environment.
Preferred Certifications:
CompTIA Security+, CySA+, BTL1, or Cloud Security certifications. Local/Regional candidates only. Local to area with a Flexible hybrid working arrangement