Computer Security Incident Response Team Analyst (CSIRT)

Computer Task Group, Inc
Anchorage, AK, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$110,000.0 - $140,000.0
Working hours
Shift work
Languages
English
Job source

Tech stack

Cyber Security Digital Forensics Identity and Access Management Intrusion Detection and Prevention Red Team (Cyber Security) Security Information and Event Management Cyber Threat Analysis Cybercrime Blue Team (Cyber Security)

Job description

Do you have a passion for Cyber Security, especially advanced Managed Detection & Response (MDR)? Does Incident Response, Digital Forensics, Threat Hunting, Threat Intelligence and everything related to Cyber Security feel like second nature to you? Are you a Cyber Defender at heart, driven to strengthen the blue team and help organizations that are under attack? If you answered yes to all of these questions, you might be the perfect fit for our CSIRT Analyst role!

  • You handle security alerts/incidents that have been escalated by the SOC Analysts (Tier 2)
  • You will handle security alerts and incidents together with your team
  • You conduct DFIR assignments, including DFIR readiness assessments
  • You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
  • You will perform compromise assessments to identify potential compromises and their scope
  • You collect Threat Intelligence (IOCs and TTPs)
  • You will contribute to Detection Engineering in SIEM, xDR, …
  • Together with the Red Team you will do Purple Teaming exercises to test and improve defenses
  • You contribute to the creation of playbooks in SOAR
  • You will co-write processes and procedures related to DFIR, Threat Intelligence, Threat Hunting, …
  • You will be part of our Incident Response on call service.

Requirements

Do you have experience in Threat intelligence?, Do you have a Master’s degree?, * You have at least 3-5 years of experience in a similar position

  • You have a bachelor or master degree or equivalent through experience
  • You have a hands-on and proactive mindset with a ‘can do’ mentality
  • You have experience and/or interest in working with the following MDR tools: EDR (CrowdStrike Falcon, MS Defender for Endpoint, Sentinel One, …), NDR (Vectra, Darktrace, …), xDR (CrowdStrike Identity Protection, MS Defender for Office/Clouds Apps/Identity/…)
  • As an analyst or engineer, you already have a good knowledge of Security Monitoring with SIEM technologies.
  • You are passionate about the following security capabilities: Security Monitoring, Digital Forensics, Incident Response, Threat Intelligence, Threat Hunting, …
  • You speak and write English fluently.

Excellent verbal and written English communication skills and the ability to interact professionally with a diverse group are required.

Benefits & conditions

3.63.6 out of 5 stars Anchorage, AK 99503 Hybrid work $110,000 - $140,000 a year - Full-time, Pulled from the full job description

  • 401(k)
  • Health insurance
  • Vision insurance
  • Dental insurance, * 401(k)
  • Dental insurance
  • Health insurance
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker · LIVE

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all