
Incident Response Analyst
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Handle investigation requests submitted by SOC Analysts who monitor security events through SIEM across various systems, including network and host-based IDS/IPS, network infrastructure logs, system logs, applications, and databases.
• Analyze intrusion attempts, differentiate false positives from genuine intrusions, and conduct thorough exploit analysis.
• Lead incident response efforts and threat hunting for confirmed High Priority security incidents until resolution is achieved.
• Utilize threat intelligence to identify and probe potential security threats.
• Create incident response and incident management playbooks that encompass threat triage, investigation, and resolution processes.
• Review and refresh playbooks to ensure they are up-to-date and effective.
• Work collaboratively with cross-functional teams to align playbooks with overarching security strategies and objectives.
• Engage in tabletop exercises and drills to assess and validate the effectiveness of playbooks.
• Monitor and analyze incidents to uncover opportunities for playbook enhancements.
• Track ongoing security threats and trends to maintain the relevance of playbooks.
• Investigate current vulnerabilities, advisories, incidents, and TTPs while collaborating with Security Engineering on suggested use cases.
• Actively monitor, hunt for, and respond to both known and emerging threats.
• Implement Thrive’s information security strategy internally and externally for over 400 clients.
• Analyze data from SOC, SIEM, and EDR platforms to determine if further investigation is necessary.
• Adhere to Thrive security standards and best practices while recommending potential improvements.
• Stay informed about security events and techniques to safeguard clients effectively.
• Extensive knowledge of SIEM (Security Information and Event Management).
• In-depth understanding of TCP/IP, computer networking, routing, and switching.
• Strong expertise in IDS/IPS, penetration testing, and vulnerability testing.
• Advanced knowledge of firewall and intrusion detection/prevention protocols.
• Proficient in Windows, UNIX, and Linux operating systems.
• Thorough understanding of network protocols and packet analysis tools.
• Comprehensive knowledge of EDR, anti-virus, and anti-malware technologies.
• Expertise in content filtering.
• Familiarity with email and web gateways.
• Strong understanding of malware, network, or system analysis.
• Professional experience in a system administration role managing multiple platforms and applications.
• Knowledge of best security practices.
• Ability to effectively collaborate and communicate security issues to clients, colleagues, and management.
• Excellent analytical and problem-solving abilities.
• Adaptable and resilient in fast-paced, evolving situations.
• Willingness to participate in an on-call rotation, including occasional nights and weekends.
• Technical expertise in networking, operating systems, and security technologies.
• Familiarity with SIEM, IDS/IPS, EDR, and forensic analysis tools.
• Understanding of incident response procedures and methodologies.
• Knowledge of MITRE ATT&CK and the Cyber Kill Chain frameworks.
• Familiarity with TCP/IP and application-layer protocols, such as HTTP, SMTP, and DNS.
• Experience in responding to and investigating cloud, system, or network intrusions.
• Expertise in forensics, malware analysis, and network intrusion response.
• Preferred: knowledge of common Windows and Linux/Unix system calls and APIs.
• Preferred: knowledge of programming languages.
• Preferred: understanding of internal file structures for malware-associated formats such as OLE, RTF, PDF, and EXE.
• Preferred: knowledge or experience in Detection Engineering.
• Comprehensive health, dental, and vision insurance.
• Retirement savings plan with company matching.
• Opportunities for professional development and training.
• Flexible work hours and remote work options.
• Dynamic and inclusive company culture.
Mercor
CBT
Compass Experience Labs
Bird's Eye Medical
Get handpicked remote jobs straight to your inbox weekly.