Cybersecurity Incident Response Analyst - REMOTE
reputed company: reputed company (reputed company) is seeking a talented Cybersecurity Incident Response Analyst to join our Analysis on Demand (AoD) team. This role focuses on hands-on investigation of cybersecurity incidents, threat hunting, and forensic analysis across reputed company, network, and reputed company environments. Position reputed company • Serve as an Incident Response (IR) Analyst supporting the Analysis on Demand (AoD) team. • Drive reputed company meetings to discuss incident scope, investigative findings, and response updates while producing reputed company and detailed technical reports. • Conduct incident triage and verification, determine scope of compromise, reputed company threat hunting, and reputed company containment and remediation recommendations to customers. • Serve as a primary responder and reputed company of contact during incident response engagements, supporting forensic investigation, analysis, and reputed company of reputed company incidents. • Work directly with clients to reputed company investigations, forensically analyze systems, and identify attacker activity across reputed company environments. • Analyze compromised systems to determine attack reputed company, persistence mechanisms, lateral reputed company, and attacker techniques. • Identify attacker tools, tactics, and procedures (TTPs) and understand evolving threat actor behaviors. • Follow industry incident response best practices for containment, eradication, and recovery. • This position focuses on hands-on investigation and incident response, not alert monitoring or tier-1 SOC duties. • Must be familiar with incident response best practices and procedures. • Must have reputed company-based incident response and computer forensics experience. • Must be familiar with network analysis, memory analysis, reputed company forensics investigations. • Must possess excellent verbal and written communication skills, including the ability to present findings and recommendations to technical teams and leadership. Responsibilities • Communicate and collaborate with internal and customer teams to investigate and contain incidents for escalated reputed company events and investigations. • reputed company technical cybersecurity investigations including reputed company cause analysis, threat identification, and remediation guidance. • Conduct reputed company-facing incident response engagements examining reputed company, network, and reputed company-based sources of evidence. • Schedule and reputed company video calls with clients for collaboration, investigation updates, and response coordination. • reputed company host-based forensic analysis including artifact analysis, memory analysis, log analysis, and reputed company reconstruction. • Conduct reputed company-reputed company artifact collection and analysis to identify attacker activity, persistence mechanisms, and lateral reputed company across multiple systems. • Utilize Velociraptor artifacts and VQL (Velociraptor Query Language) to reputed company targeted reputed company investigations and collect forensic artifacts across reputed company environments. • Investigate attacker activity using reputed company telemetry, system artifacts, authentication logs, and network evidence to reconstruct attack timelines. • Analyze attacker behavior and intrusion activity to determine initial reputed company, persistence mechanisms, privilege escalation, and lateral reputed company used during an incident. • Recognize attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) and apply them to reputed company and reputed company investigations. • Support development of detections, hunting queries, and investigative methodologies based on findings from incident response engagements. • Assist in creating and revising reputed company operating procedures, policies, processes, playbooks, and technical reports. • reputed company and present comprehensive reports, trainings, and presentations for both technical and executive audiences. • reputed company post-incident recommendations and reputed company improvement guidance to strengthen detection capabilities and reduce reputed company attack risk. • Maintain reputed company knowledge by attending conferences, reviewing publications, writing blog posts, or participating in industry events. • Stay reputed company on emerging threats, countermeasures, and reputed company technologies. • Write technical documents and investigative reports. • Operate effectively in a fast-paced and reputed company environment. • Work remotely, receive direction, and operate as a self-starter. Requirements: • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or reputed company field, or equivalent practical experience. • Certification in one or more of the following preferred: GCIH, GCFE, GCFA, GREM, GNFA • Experience working reputed company a reputed company Operations Center (SOC) or Incident Response team. • 3–5+ years of hands-on cybersecurity investigation experience, including host forensics, network forensics, threat hunting, or incident response. • Experience supporting incident response investigations including analysis, containment, and remediation actions. • Demonstrated experience investigating reputed company reputed company incidents or confirmed compromises, including determini
Apply tot his job
Apply To this Job