Incident Response Analyst

Resourcesoft, Inc.
Harrisburg, PA, United States
about 1 month ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Information Technology Consulting Query Languages Intrusion Detection and Prevention Network Packet Network Security Security Information and Event Management Scripting Cyber Threat Analysis Information Technology

Job description

Perform ongoing network and security event monitoring to protect enterprise information technology assets. Conduct deep-dive security investigations for escalated alerts to determine root cause and system impact. Build and optimize SIEM queries, custom detection rules, and alert correlation logic. Execute proactive threat-hunting campaigns to isolate indicators of compromise and system anomalies. Analyze advanced telemetry, system logs, and network packet captures during active incident responses. Create, update, and improve standardized SOC playbooks and operational procedures. Document security incidents, containment activities, and lessons learned in central ticketing systems. Founded in 1999, Resourcesoft, Inc. is a leading Technology Consulting and Professional Services organization. Headquartered in Marlborough, MA, the company serves the technology needs of its clients nationwide. Resourcesoft has often been recognized by prominent rating agencies for its exemplary growth and stability. With over two decades of industry experience, the Company has evolved as a front runner in enabling project optimization. We partner with leading organizations to provide technology solutions within the financial, insurance, education, government, publishing, healthcare and pharmaceutical domains. We take pride in mentoring a workforce that is well positioned to respond to the emerging IT trends and needs. With the employees at the crux of every business endeavor, our success is driven by our expertise in pairing the right talent with the best jobs in the technology sector. We forge long term, personalized relationships with our employees to advance their career to the next level. We engage them in technology centric client projects that provide opportunities for them to evolve, innovate and deliver world class products and services. Our career opportunities offer challenging assignments and exposure to emerging and cutting edge technologies. We are committed to providing our employees with the tools necessary to accelerate their career progression, while maintaining a healthy, work-life balance. We are deeply committed to providing a workplace ambience that is both challenging and fulfilling.

Requirements

3 or more years of experience in security operations center (SOC) environments and incident response. Proficiency in SIEM query languages and security scripting tools. Experience with analyzing advanced system logs, network packet captures, and endpoint telemetry. Experience in proactive threat hunting and identifying indicators of compromise (IOCs). Experience with detection engineering, rule tuning, and correlation logic optimization. Experience in executing SOC playbook processes and standard operating procedures. Excellent verbal and written communication skills.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:07 min

Attaching programs to network events via kernel hooks

Mohammed Aboullaite Mohammed Aboullaite · World Congress 2024

3:05 min

Fetching platform telemetry data with query languages

Daisy Muyldermans · LIVE

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

4:23 min

Boosting security operations center productivity with intelligent data analysis

Chris Wysopal Chris Wysopal +2 · World Congress 2024

Videos

See all

Related articles

See all