Remote Cyber Security
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+20 more
Job description
We are seeking three highly motivated and experienced Cyber Security Specialist to support day, swing, and night shift operations within our 100% remote 24/7/365 Security Operations Center (SOC). You will monitor, analyze, investigate, and respond to threats across hybrid cloud and on-prem environments. This role is ideal for analysts with a strong investigative mindset, technical depth, and a passion for continuous learning., * Support EDR platform administration by managing agent health and deployment, maintaining integration with SIEM and other telemetry pipelines, coordinating policy updates, and partnering with SysAdmins to troubleshoot endpoint and infrastructure-level issues affecting EDR visibility.
-
Conduct digital forensics during incident response by acquiring, preserving, and analyzing endpoint artifacts (e.g., memory, disk, registry, logs); assist with root cause analysis and ensure forensic evidence in accordance with legal and procedural requirements.
-
Provide engineering-focused support on SOC architecture improvements to increase visibility, data fidelity, and detection capabilities across hybrid environments.
-
Perform threat detection, log analysis, and anomaly identification across on-premises and cloud workloads (AWS required).
-
Conduct initial incident response and assist with investigations into malware, phishing, lateral movement, privilege misuse, and data exfiltration.
-
Apply threat intelligence to enrich alerts and uncover TTPs using the MITRE ATT&CK framework.
-
Participate in threat hunting missions based on hypotheses, intel feeds, and environmental knowledge.
-
Collaborate with engineering, system administrators, and cyber stakeholders to contain and remediate threats.
-
Support compliance efforts by ensuring audit trails, access logs, and investigative artifacts are collected and preserved.
-
Maintain situational awareness through active monitoring of CTI sources, advisories, and vulnerability disclosures.
-
Provide summary reports and handoff briefings at the end of each shift.
-
Document investigative activities, incident details, troubleshooting steps, and evidence in the case management system; create, update, and escalate tickets in accordance with established procedures and escalation guidelines.
-
Provide after-hours operational support by monitoring incident intake channels, performing initial triage of operational and security events, coordinating with on-call resources, and ensuring timely escalation and handoff of incidents.
Requirements
-
Perform advanced EDR analysis, including alert triage, threat detection, behavioral rule tuning, IOC investigation, and endpoint telemetry enrichment., * AWS proficiency in analyzing security events within AWS environments, including CloudTrail, VPC Flow Logs, GuardDuty, and IAM policies
-
AWS Familiarity with compliance and audit frameworks: NIST CSF, 800-53, OMB M-21-31, CIS Benchmarks, STIGs
-
Knowledge of vulnerability scanning tools (e.g., Tenable Nessus) and CVE exposure analysis
-
Experience collaborating with cyber threat intelligence and/or red teams
-
Experience in digital forensics, malware analysis, or purple team operations
-
Experience with Case Management System (e.g., ServiceNow)
-
Experience with SIEM (e.g., Splunk)
-
Experience using SOAR platforms for alert triage and response automation
-
Solid understanding of Windows and Linux operating system internals and log analysis
-
Strong grasp of network protocols, TCP/IP, and common attack vectors
-
Familiarity with scripting (e.g., PowerShell, Python, Bash) and automation workflows
-
Experience with threat hunting, IOC analysis, or MITRE ATT&CK-based detection
-
Understanding of identity and access management (IAM) risks in cloud environments
-
Experience improving SOC processes, detection logic, architecture, or playbooks
-
Ability to communicate findings clearly-verbally and in writing-to technical and non-technical audiences * Played a key role in managing a major security incident, including rapid triage, root cause analysis, coordinated containment actions, and cross-team communication.
-
Demonstrated the ability to operate effectively under pressure, making sound technical decisions while balancing business impact and urgency.
-
Skilled in reconstructing attack paths using log analysis, network forensics, endpoint telemetry, and cloud service investigations.
-
Collaborated closely with engineering, IT, and leadership to ensure timely remediation and clear documentation throughout the incident lifecycle.
-
Contributed to post-incident reporting, lessons learned, and improvements to detection rules, playbooks, and security controls based on incident findings.
-
Proven capability to interpret complex threat behaviors and apply frameworks like MITRE ATT&CK to understand adversary techniques encountered during the incident.
-
Strengthened SOC readiness by helping refine escalation procedures, communication channels, and response strategies following the major event.
Education/Experience:
-
Degree educated or equivalent, preferably in a computer science related subject
-
AWS Certified
-
GIAC Certified (e.g., GCIH, GCIA, GCFA, GNFA, GDAT)
-
OffSec Certified
-
8-10 years experience
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Walking Into The Era of Supply Chain Risks
Dev Digest 134 - Where pixels sing?
Understanding and Mitigating Common Web Vulnerabilities