Cyber Threat Analyst

Cellebrite
Tysons, VA, United States
3 days ago
Apply on www.disabledperson.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Active Directory Amazon Web Services Microsoft Azure Computer Forensics Linux File System Permissions Networking Hardware Python (Programming Language) Network Security Network Protocols Parsing Windows PowerShell
+9 more
Security Information and Event Management TCP/IP Software Vulnerability Management Scripting Mitre Att&ck Multi-Cloud Cyber Threat Analysis Cybercrime Cortex XSOAR Platform

Job description

We are expanding our Threat Ops team and looking for a Cyber Threat Analyst to join our first line of defense. Our team investigates and responds to security incidents, creates alerting rules, administrates various security products and is responsible for integration and automation security projects., * Monitor and respond to security events, execute response related actions including documentation, manage the event to its fast resolution.

  • Continuously monitor SIEM alerts to improve and tune the identification and response rule. Create new rules based on trending cyber-attack methods and business threats strategy.
  • Threat Hunting perform hunting activities
  • Vulnerability Management Generate reports using vulnerability scanning tools and collaborate with stakeholders to ensure progress
  • Generate reports for IT administrators, business managers, and security leaders to evaluate the efficiency of the security policies and controls.
  • Advise and implement necessary changes required to counter the attack or improve security standards. This to include automating processes.
  • Document incidents to contribute to incident response and disaster recovery plans.
  • Perform internal and external security audits.

Requirements

  • Minimum 5 years experience as a Tier 2 Cyber Threat Analyst
  • Certifications: Security+ or CEH
  • Proven experience with SIEM (Rules, Parsing, Correlation, Investigation) - MUST.
  • Proven experience with Playbook implementation (e.g. Palo Alto XSOAR) - MUST.
  • Proven experience with Threat Hunting - MUST.
  • Familiarity with methodologies, such as Cyber Kill Chain and MITRE ATT&CK. - MUST
  • Experienced with multi-cloud platforms (Azure, AWS) - MUST.
  • Strong knowledge of the TCP/IP topology, network protocols, active directory, and File permissions.
  • Experienced with network and security systems (network device, security device, endpoint devices, EDR, FW, OS- Windows, Linux, Mac) - Advantage
  • Experience with writing incident response reports.
  • Scripting: Powershell, Python -Advantage
  • Excellent communication skills to engage with stakeholders at all levels.
  • Team player, very organized and structured, attention to detail
  • Must be a US Citizen with the ability to obtain a clearance.
  • This is a Remote position, but prefer candidates in the Eastern timezone

About the company

Cellebrites (Nasdaq: CLBT) mission is to enable its global customers to protect and save lives by enhancing digital investigations and intelligence gathering to accelerate justice in communities around the world. Cellebrites AI-powered Digital Investigation Platform enables customers to lawfully access, collect, analyze and share digital evidence in legally sanctioned investigations while preserving data privacy. Thousands of public safety organizations, intelligence agencies and businesses rely on Cellebrites digital forensic and investigative solutionsavailable via cloud, on-premises and hybrid deploymentsto close cases faster and safeguard communities.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.disabledperson.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:56 min

Open-sourcing a complex parsing library for game data

Johan Hutting Johan Hutting · World Congress 2024

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:36 min

Managing complex operation sequence weights using recursive parsing

Florian Rappl · LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · World Congress 2022

Videos

See all

Related articles

See all