Remote Cyber Security
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+20 more
Job description
We are seeking three highly motivated and experienced Cyber Security Specialist to support day, swing, and night shift operations within our 100% remote 24/7/365 Security Operations Center (SOC). You will monitor, analyze, investigate, and respond to threats across hybrid cloud and on-prem environments. This role is ideal for analysts with a strong investigative mindset, technical depth, and a passion for continuous learning., * Support EDR platform administration by managing agent health and deployment, maintaining integration with SIEM and other telemetry pipelines, coordinating policy updates, and partnering with SysAdmins to troubleshoot endpoint and infrastructure-level issues affecting EDR visibility.
- Conduct digital forensics during incident response by acquiring, preserving, and analyzing endpoint artifacts (e.g., memory, disk, registry, logs); assist with root cause analysis and ensure forensic evidence in accordance with legal and procedural requirements.
- Provide engineering-focused support on SOC architecture improvements to increase visibility, data fidelity, and detection capabilities across hybrid environments.
- Perform threat detection, log analysis, and anomaly identification across on-premises and cloud workloads (AWS required).
- Conduct initial incident response and assist with investigations into malware, phishing, lateral movement, privilege misuse, and data exfiltration.
- Apply threat intelligence to enrich alerts and uncover TTPs using the MITRE ATT&CK framework.
- Participate in threat hunting missions based on hypotheses, intel feeds, and environmental knowledge.
- Collaborate with engineering, system administrators, and cyber stakeholders to contain and remediate threats.
- Support compliance efforts by ensuring audit trails, access logs, and investigative artifacts are collected and preserved.
- Maintain situational awareness through active monitoring of CTI sources, advisories, and vulnerability disclosures.
- Provide summary reports and handoff briefings at the end of each shift.
- Document investigative activities, incident details, troubleshooting steps, and evidence in the case management system; create, update, and escalate tickets in accordance with established procedures and escalation guidelines.
- Provide after-hours operational support by monitoring incident intake channels, performing initial triage of operational and security events, coordinating with on-call resources, and ensuring timely escalation and handoff of incidents.
Requirements
- Perform advanced EDR analysis, including alert triage, threat detection, behavioral rule tuning, IOC investigation, and endpoint telemetry enrichment., * AWS proficiency in analyzing security events within AWS environments, including CloudTrail, VPC Flow Logs, GuardDuty, and IAM policies
- AWS Familiarity with compliance and audit frameworks: NIST CSF, 800-53, OMB M-21-31, CIS Benchmarks, STIGs
- Knowledge of vulnerability scanning tools (e.g., Tenable Nessus) and CVE exposure analysis
- Experience collaborating with cyber threat intelligence and/or red teams
- Experience in digital forensics, malware analysis, or purple team operations
- Experience with Case Management System (e.g., ServiceNow)
- Experience with SIEM (e.g., Splunk)
- Experience using SOAR platforms for alert triage and response automation
- Solid understanding of Windows and Linux operating system internals and log analysis
- Strong grasp of network protocols, TCP/IP, and common attack vectors
- Familiarity with scripting (e.g., PowerShell, Python, Bash) and automation workflows
- Experience with threat hunting, IOC analysis, or MITRE ATT&CK-based detection
- Understanding of identity and access management (IAM) risks in cloud environments
- Experience improving SOC processes, detection logic, architecture, or playbooks
- Ability to communicate findings clearly-verbally and in writing-to technical and non-technical audiences - Played a key role in managing a major security incident, including rapid triage, root cause analysis, coordinated containment actions, and cross-team communication.
- Demonstrated the ability to operate effectively under pressure, making sound technical decisions while balancing business impact and urgency.
- Skilled in reconstructing attack paths using log analysis, network forensics, endpoint telemetry, and cloud service investigations.
- Collaborated closely with engineering, IT, and leadership to ensure timely remediation and clear documentation throughout the incident lifecycle.
- Contributed to post-incident reporting, lessons learned, and improvements to detection rules, playbooks, and security controls based on incident findings.
- Proven capability to interpret complex threat behaviors and apply frameworks like MITRE ATT&CK to understand adversary techniques encountered during the incident.
- Strengthened SOC readiness by helping refine escalation procedures, communication channels, and response strategies following the major event., * Degree educated or equivalent, preferably in a computer science related subject
- AWS Certified
- GIAC Certified (e.g., GCIH, GCIA, GCFA, GNFA, GDAT)
- OffSec Certified
- 8-10 years experience
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Dev Digest 134 - Where pixels sing?
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks