> Markdown version of [/jobs/ext/2026155-cyber-defense-senior-analyst-remote](https://www.wearedevelopers.com/jobs/ext/2026155-cyber-defense-senior-analyst-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Defense Senior Analyst (Remote) - **Company:** Experian plc - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Proxy Servers, Antivirus Softwares, Apple Mac Systems, Application Firewall, Application Performance Management, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Computer Engineering, Data Security, Linux, Digital Forensics, Monitoring of Systems, Web Servers, Information Security Management, Intrusion Detection and Prevention, NetFlow, Network Forensics, Packet Analyzer, Phishing, Security Information and Event Management, Software Vulnerability Management, Data Logging, Scripting, Google Cloud, Mitre Att&ck, QRadar, Malware, Firewalls (Computer Science), Information Technology, Cybercrime, Fireeye, Cortex XSOAR Platform, Splunk, Security Orchestration, Automation & Response - **Published:** August 11, 2026 - **Apply:** https://jobs.smartrecruiters.com/Experian/744000138173245-cyber-defense-senior-analyst-remote-?oga=true&trid=8dc3fc18-7d27-474f-af15-47b783076ace ## About the Role * 3+ years of information security experience working within a Security Operations Center or Cyber Security Incident Response Team. * Bachelor's Degree in Computer Science, Computer Engineering, Information Systems, Information Security, or a related field. 6+ years of experience working within a Security Operations Center, Incident Response Team, law enforcement, and/or military experience may be accepted in lieu of this requirement. * Demonstrate working knowledge of the Incident Response Life Cycle, MITRE ATT&CK Framework, Cyber Kill Chain, and other cybersecurity frameworks. * Demonstrated knowledge of common intrusion methods and cyber-attack tactics, techniques, and procedures (TTPs), as well as common industry practices to investigate and respond to threats, including phishing, malware, network attacks, suspicious activity, and data security incidents. * Demonstrated proficiency in determining appropriate methods to contain, eradicate, and recover from a variety of security incidents. Provide recommendations to prevent incidents from recurring. * Possesses an understanding of common Operating Systems (Windows, Linux, Mac OS), Networking (Firewalls, Proxies, NetFlow, etc.), Cloud Infrastructure (AWS, Azure, GCP), and Security Technologies (Anti-Virus, Intrusion Prevention, Web Application Firewalls, etc.) * Ability to review and interpret device and application logs from a variety of sources (e.g., Firewalls, Proxies, Web Servers, System Logs, Splunk, Packet Captures, etc.) to identify root cause and determine next steps for containment, eradication, and recovery. * Experience with common Incident Response and Security Monitoring applications such as SIEM (e.g., Qradar, Splunk), EDR (e.g., FireEye HX, CrowdStrike Falcon, Microsoft Defender, etc.); experience with Security Orchestration, Automation, and Response (SOAR) technologies such as Palo Alto XSOAR and Google Secops (Chronicle) are a plus. * Continuously build advanced cybersecurity expertise across cloud security (Azure/AWS), incident response, threat detection, system and network forensics, SIEM/monitoring tools, vulnerability management, malware analysis, and scripting/automation. * One or more professional, currently-held certifications related to Digital Forensics, Incident Response, or Ethical Hacking highly preferred (e.g., GCIH, GMON, GCED, GSOC, CEH, GCFE, GCFA, CFCE, ENCE). * Bonus: Information security management certifications (CISSP, CISM) or vendor-specific certifications. ## Description This role operates in a 10x4 Wednesday - Saturday weekly schedule as part of a 24x7 global monitoring function. The frontline team provides global 24x7 security operations and monitoring for cybersecurity events impacting Experian, and is a division of Experian's Cyber Fusion Center (CFC), which is organized under the Experian Global Security Office (EGSO). As a Cyber Defense Senior Analyst, you will perform in-depth analysis, triage, and response to security threats by following documented policies, processes, and playbooks to meet Service Level Objectives (SLOs). This role is critical in ensuring the handling of potential threats and plays a part in improving security operations. You will report to the Director of Cyber Defense Security Operations. You'll have the opportunity to: * Perform daily security operations by monitoring, triaging, and conducting response activities for security events and alerts associated with cyber threats, intrusions, and compromises. * Analyze events using security tooling and logging, such as SIEM, EDR, and assess the potential risk/severity level of cyber threats. Escalate higher-risk events to dedicated incident response and management teams in the CFC, according to established processes. * Collaborate with external teams for incident resolution and escalations, driving incident handling. * Notify team Lead(s) of concerns related to operations, such as anomalous changes in metrics, notable open incidents, quality concerns, or observed risks; support with resolution if appropriate. * Manage and complete assigned caseload throughout the incident response lifecycle, including analysis, containment, eradication, recovery, and lessons learned; maintain standards of quality to resolve events. * Maintain all case documentation, including notes, analysis findings, containment steps, and cause for each assigned security incident. * Perform incident updates or make contact with end-users promptly and document them, and complete case hand-off processes, such as completing/verifying shift logs. * Apply subject matter expertise in security operations processes to help improve relevant playbooks, Standard Operating Procedures (SOPs), and training materials. * Assist the team Leads and management on use case development by suggesting enhancements or tuning of use cases to improve the security posture of Experian. * Participate in paid overtime when operational needs may require additional support. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)