Cyber Defense and Incident Response Analyst

The Guardian Life Insurance Company of America
Holmdel, United States of America
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 156K

Job location

Holmdel, United States of America

Tech stack

Artificial Intelligence
Software as a Service
Computer Security
Digital Forensics
Disaster Recovery
Log Analysis
Security Information and Event Management
Data Logging
Large Language Models
Mitre Att&ck
Malware
Cybercrime
Cyber Warfare

Job description

This role sits at the intersection of hands-on incident response, cyber defense and threat mitigation. You will be part of a highly collaborative cyber defense and incident response organization, responding to and investigating high-impact security incidents.

The ideal candidate is an analytical, curious, and resilient technical leader with a strong investigative mindset and a desire to reduce risk through decisive action. You bring deep knowledge of modern attack techniques and frameworks, communicate clearly under pressure, and naturally step in to respond to and lead incidents during critical situations. You thrive in partnership working closely with security, IT, legal, HR, communications, and business teams to drive effective identification, containment, investigation, response, and recovery., * Act as a technical lead, working as part of a collaborative team responding to actions across cybersecurity security teams while collaborating with legal, enterprise technology, engineering, and other internal teams.

  • Contribute to and refine test incident response plans, playbooks, quick-reference guides, and crisis communication procedures.
  • Partner with first-line SOC teams to build muscle memory, clarify containment authorities, and standardize response actions.
  • Coordinate with business continuity/disaster recovery teams to ensure an integrated response to large-scale cyber events.
  • Drive continuous improvement of logging, monitoring, detection coverage, and UBA capabilities, proactively identifying gaps.
  • Ensure incidents are tracked, reported, and reviewed, with high-quality after-action reports and meaningful metrics.
  • Collaborate across teams through cross-functional incident response training events, and debriefs to align on threats, trends, and lessons learned.
  • Lead risk mitigation initiatives and improvements to security control effectiveness.
  • Collaborate with cybersecurity leadership on strategy, roadmap development, vendor management, and talent planning.
  • Contribute to enterprise programs such as DLP and insider risk management.
  • Support internal and external audits, regulatory requests, and due diligence activities.
  • Continuously identify opportunities to enhance incident response maturity, automation, and cyber defense capabilities.
  • Drive our user behavior analytics (UBA) program working with the business to develop and improve appropriate logging monitoring. Develop standard operating procedures for our 1st line SOC based on threats/observed incidents.

Requirements

  • 5-7 years of overall cybersecurity experience, with a focus in digital forensics, incident response, SOC, or threat mitigation.
  • Broad and deep technical expertise across enterprise environments, including public cloud and SaaS platforms.
  • Experience with AI models, LLM's and implementing AI for Cyber detection response.
  • Eagerness to grow within the security leadership and obtain experience, ideally in incident response or cyber defense, with a player/coach mindset.
  • Strong command of incident response methodologies, digital forensics principles, and evidence handling.
  • Knowledge and experience in threat hunting, malware analysis, attacker techniques, and common vulnerabilities.
  • Practical experience working with NIST CSF, MITRE ATT&CK, and related security frameworks.
  • Hands-on experience with SIEM and log analytics platforms including logging, monitoring, insider threat, and UBA concepts.
  • Ability to translate cyber threat intelligence into actionable detections, mitigations, and response strategies.
  • Experience operating in regulated environments, preferably financial services or insurance, with understanding of U.S. privacy regulations.
  • Proven ability to lead, mentor, and develop high-performing technical teams.
  • Strong written and verbal communication skills, with experience engaging technical teams, executives, and cross-functional partners.
  • Analytical, curious, and resilient under pressure; able to think structurally and creatively during incidents.
  • BS or MS in cyber security, digital forensics, or equivalent experience and/or industry certifications preferred.
  • A continuous, lifelong learner with a desire to grow into broader cyber leadership.

Benefits & conditions

  • Three days a week at a Guardian office in New York, NY. or Holmdel, NJ
  • 20% travel to other Guardian Offices as needed

Salary Range:

$95,170.00 - $156,355.00

The salary range reflected above is a good faith estimate of base pay for the primary location of the position. The salary for this position ultimately will be determined based on the education, experience, knowledge, and abilities of the successful candidate. In addition to salary, this role may also be eligible for annual, sales, or other incentive compensation.

Our Promise

At Guardian, you'll have the support and flexibility to achieve your professional and personal goals. Through skill-building, leadership development and philanthropic opportunities, we provide opportunities to build communities and grow your career, surrounded by diverse colleagues with high ethical standards.

About the company

As part of Guardian's job application process, Guardian may use artificial intelligence tools ("AI Tools") to automate the sorting and filtering of information provided by applicants as part of its preliminary screening. This preliminary screening may be used to help identify applicant materials and resumes relative to their indication that the applicant meets the requirements for the specific job for which they are applying, as specified in the listing posted on Guardian's jobs website (Careers at Guardian at https://www.guardianlife.com/careers). At Guardian, we do not use AI Tools to substantially assist or replace human judgment or discretionary decision making in our hiring process. All hiring decisions will be made by Guardian colleagues. Please be aware that if you apply for a specific position with Guardian, you will have the choice of opting out of Guardian's use of AI Tools during the job application process. If you would like to request an alternative process that does not utilize AI Tools or would like to request a reasonable accommodation, within ten business days of your position application, you must email your request to MyHR@glic.com, making sure to provide your name and job requisition identification number. Guardian will retain your applicant materials and resume and all information therefrom in accordance with Guardian's document retention policy, a copy of which you may request via MyHR@glic.com. Additionally, at applicable times, Guardian will make public the most recent bias audit results for such AI tools, which may be found here.

Apply for this position