Cyber Security Incident Response Team Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+2 more
Job description
The Cyber Security Incident Response Team (CSIRT) Analyst is responsible for monitoring, detecting, analyzing, and responding to cybersecurity threats across the enterprise environment. The role focuses on proactive threat detection, incident investigation, SIEM monitoring, threat hunting, and coordination with global security and infrastructure teams to contain and remediate security incidents. The analyst will leverage enterprise security technologies including SIEM, EDR/XDR, threat intelligence platforms, and security monitoring tools to identify malicious activity, investigate anomalies, and support continuous improvement of the organizationās security posture. Role Description:
The ideal candidate will have experience in a variety of technologies essential to identifying threats to the Stellantis environment, specifically SIEM Microsoft Sentinel, and use those skills to perform the following:
Daily use of SIEM Tool, to analyze data flows and identify potential threats and anomalies. Ability to provide a detailed analysis of logs from security infrastructure (Firewall, IPS, etc). Provide internal threat hunting and policy abuse management based on information gathered in SIEM. Understand how to gather threat intelligence data. Recognize potential successful and unsuccessful intrusion attempts and compromises. Log incidents and track them via incident management tool (Resilient). Provide suggestions for Microsoft Sentinel optimization and source log parsing., Define Sentinel use cases, dashboards, filters etc. as needed.
Requirements
Have a solid understanding of enterprise environments including networking, web services, database, operating systems, etc. Experience with MITRE Attack is a plus. Provide documentation as needed, such as playbooks, to be shared with other team members. Ability to work from high level direction and then collaborate with the rest of the CSIRT and other Products within CDOC team., BS/BA degree in Computer Science, Data Science, Engineering, Information Science, Statistics, Information Systems, or other relevant disciplines from an accredited university or recognized higher education institution. Equivalent international qualifications such as a BSc, MSc, or Diplome dāingenieur (Europe), or regionally accredited degrees (North America) are also acceptable. Minimum 3 years of overall experience working as a Security Analyst in enterprise environments. Minimum 2 years of hands-on experience with SIEM Sentinel, including configuration, tuning, and incident investigation. Strong understanding of SIEM (Security Information and Event Management) concepts, architecture, and operational workflows. Proven experience supporting and maintaining SIEM platforms in complex, large-scale enterprise infrastructures. Excellent analytical and problem-solving skills, with the ability to troubleshoot and resolve security-related issues effectively. Strong communication skills, with the ability to clearly articulate technical concepts to both technical and non-technical stakeholders, including management and cross-functional teams., Have a solid understanding of enterprise environments including networking, web services, database, operating systems, etc. Experience with MITRE Attack is a plus. Provide documentation as needed, such as playbooks, to be shared with other team members. Ability to work from high level direction and then collaborate with the rest of the CSIRT and other Products within CDOC team. At Stellantis, we assess candidates based on qualifications, merit, and business needs. We welcome applications from all people without regard to sex, age, ethnicity, nationality, religion, sexual orientation, disability, or any characteristic protected by law. We believe that diverse teams reflect our identity as a global company, enabling us to better address the evolving needs of our customers and care for our future.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role ā technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 191: Malware interviews, EU ā¤ļø Open Source and Skilled Agents