
Cybersecurity Analyst
Posted Jul 20

Posted Jul 20
This is a fully remote position, open to applicants in United States.
• Oversee and evaluate security events using Splunk Enterprise Security (ES).
• Develop, manage, and optimize Splunk searches, correlation rules, alerts, and dashboards.
• Perform incident response activities from detection to containment, eradication, recovery, and closure.
• Investigate endpoint security incidents using Microsoft Defender for Endpoint.
• Conduct endpoint policy management and incident investigations.
• Evaluate AWS cloud security telemetry through GuardDuty, Security Hub, and other relevant cloud security services.
• Identify threats, vulnerabilities, suspicious behaviors, and cloud misconfigurations.
• Carry out alert triage, incident scoping, and escalation activities in accordance with established playbooks.
• Suggest updates and enhancements to operational procedures and incident response playbooks.
• Assist in threat hunting efforts and detection engineering initiatives aligned with MITRE ATT&CK methodologies.
• Conduct phishing investigations, alert enrichment, and forensic review tasks.
• Execute root cause analysis and document corrective measures post-security incidents.
• Monitor incidents and operational tasks using case management systems.
• Engage in tabletop exercises and operational readiness initiatives.
• Collaborate with Security Operations teams, Incident Response personnel, and federal stakeholders.
• Prepare reports and convey findings to both technical and non-technical audiences.
• Perform additional job-related duties as assigned.
• Three (3) to five (5) years of experience in cybersecurity operations, SOC analysis, incident response, or related security fields.
• Proven hands-on experience with Splunk Enterprise Security, including search development, dashboard creation, and correlation rule tuning.
• Experience using Microsoft Defender for Endpoint for security investigations and policy management.
• Working knowledge of AWS cloud security technologies, including GuardDuty, Security Hub, or similar tools.
• Demonstrated experience managing incidents across the entire incident response lifecycle.
• Familiarity with the MITRE ATT&CK framework and common tactics, techniques, and procedures employed by threat actors.
• Knowledge of incident response methodologies and frameworks such as NIST 800-61.
• Strong analytical, investigative, and problem-solving skills.
• Exceptional written and verbal communication abilities.
• Experience supporting federal government clients or working in highly regulated environments.
• Capacity to work independently while effectively collaborating with cross-functional teams.
• Medical
• Dental
• Vision
• 401(k)
• Paid Time Off
• Life Insurance
• Disability Coverage
• Other benefits as provided
The Home Depot
Lennar
Golden 1 Credit Union
NuHarbor Security
Get handpicked remote jobs straight to your inbox weekly.