Incident Response Analyst
Join a cybersecurity company to investigate and respond to security incidents, perform threat hunting, and develop detection engines. Collaborate with teams to enhance security posture and contribute to research.
Responsibilities
- Investigate and respond to security incidents across email, browser, and perimeter domains
- Handle investigation requests from customers
- Perform targeted phishing analysis and investigate new attack campaigns
- Conduct threat hunting based on attack patterns, behaviors, and indicators
- Build and improve detections for new attack types and trends
- Collaborate with development and research teams to provide incident-driven insights
- Develop detection engines for previously unknown attacks
- Write professional blog posts on incident investigations and attack trends
- Work rotating shifts as part of 24/7 operations
Requirements
- At least 3 years of experience in incident response or security operations
- Strong understanding of attack vectors: phishing, BEC, email spoofing, malware, ATO
- Knowledge of email protocols and security concepts: SMTP, SPF/DKIM/DMARC, headers, authentication
- Strong querying skills with SQL, SPL, KQL, or AQL
- Good knowledge of static and dynamic analysis techniques
- Familiarity with scripting languages like Python, JavaScript, Visual Basic to analyze malicious code
- Excellent written and verbal communication in English
- Team player with proactive, ownership-driven approach