
Analyst I, Falcon Complete
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Canada.
• Manage, investigate, and react to security alerts across endpoint, identity, email, network, and cloud settings.
• Carry out tactical analyses of EDR telemetry, logging sources, and forensic artifacts to identify the root cause and extent of breaches.
• Create specific remediation suggestions.
• Examine suspicious activities within Microsoft 365, including BEC and AITM attacks.
• Mitigate threats and provide actionable advice to clients.
• Conduct basic malware analyses to assist in security incident investigations.
• Enhance and refine incident detection methodologies and countermeasures.
• Act as the main point of contact for clients during incident response efforts.
• Deliver clear, concise, and professional written and verbal communications, recommendations, and findings.
• Safeguard organizations against advanced threats using CrowdStrike’s virtual security operations center.
• This role is available to candidates residing in the PST and MST time zones.
• Experience in incident handling, awareness of the threat landscape, computer forensic analysis, malware analysis, operating system fundamentals, systems administration, foundational network analysis, identity platform knowledge, email security awareness, third-party log analysis, incident remediation, network operations, and architecture/engineering, programming/scripting, or AI fundamentals.
• Practical incident response experience across a wide array of security events, including managing multiple concurrent incidents across hosts and customer environments.
• Familiarity with attack vectors, threat actor TTPs, and frameworks such as MITRE ATT&CK.
• Experience utilizing forensic analysis tools in incident response investigations.
• Basic skills in static and dynamic malware analysis.
• Strong comprehension of Windows, Mac, and/or Linux operating systems, including Windows internals.
• Hands-on experience managing networks and resolving connectivity, authentication, and configuration challenges.
• Familiarity with network protocols and analysis tools.
• Experience with identity and access management platforms like Okta, Microsoft Entra ID, and Active Directory.
• Background in investigating Microsoft 365 security incidents, including BEC and AITM attacks.
• Understanding of enterprise log sources and SIEM investigation and triage.
• Basic knowledge of containment and incident remediation strategies.
• Familiarity with secure network architecture and practical network troubleshooting.
• Experience with scripting languages such as Python, PowerShell, or Bash.
• Experience leveraging AI technologies to improve decision-making, streamline workflows and processes, enhance efficiency, and drive business results.
• Capability to perform technical tasks independently.
• Must be willing to work a 4x10 schedule, including one weekend day.
• Open only to U.S. citizens and Green Card holders.
• BA or BS / MA or MS degree in a specified or related field; candidates without a degree but possessing relevant work experience and/or training will be considered.
• Expected to maintain legal eligibility to work in Canada.
• Subject to background checks, including criminal record, credit, and/or reference checks.
• Leading market compensation and equity awards.
• Comprehensive physical and mental wellness programs.
• Competitive vacation and holiday time for relaxation.
• Paid parental and adoption leave.
• Opportunities for professional development available to all employees, regardless of level or role.
• Employee Networks, local community groups, and volunteer opportunities to foster connections.
• Dynamic office culture with top-tier amenities.
• Variable/incentive compensation.
• Equity options.
• Comprehensive benefits package.
Highmark Health
Brown & Brown Insurance
ASRC Federal
Rithum
Get handpicked remote jobs straight to your inbox weekly.