Incident Response Analyst

Posted 3 days ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Handle investigation requests submitted by SOC Analysts who monitor security events through SIEM across various systems, including network and host-based IDS/IPS, network infrastructure logs, system logs, applications, and databases.

• Analyze intrusion attempts, differentiate false positives from genuine intrusions, and conduct thorough exploit analysis.

• Lead incident response efforts and threat hunting for confirmed High Priority security incidents until resolution is achieved.

• Utilize threat intelligence to identify and probe potential security threats.

• Create incident response and incident management playbooks that encompass threat triage, investigation, and resolution processes.

• Review and refresh playbooks to ensure they are up-to-date and effective.

• Work collaboratively with cross-functional teams to align playbooks with overarching security strategies and objectives.

• Engage in tabletop exercises and drills to assess and validate the effectiveness of playbooks.

• Monitor and analyze incidents to uncover opportunities for playbook enhancements.

• Track ongoing security threats and trends to maintain the relevance of playbooks.

• Investigate current vulnerabilities, advisories, incidents, and TTPs while collaborating with Security Engineering on suggested use cases.

• Actively monitor, hunt for, and respond to both known and emerging threats.

• Implement Thrive’s information security strategy internally and externally for over 400 clients.

• Analyze data from SOC, SIEM, and EDR platforms to determine if further investigation is necessary.

• Adhere to Thrive security standards and best practices while recommending potential improvements.

• Stay informed about security events and techniques to safeguard clients effectively.


⛳️ Requirements

• Extensive knowledge of SIEM (Security Information and Event Management).

• In-depth understanding of TCP/IP, computer networking, routing, and switching.

• Strong expertise in IDS/IPS, penetration testing, and vulnerability testing.

• Advanced knowledge of firewall and intrusion detection/prevention protocols.

• Proficient in Windows, UNIX, and Linux operating systems.

• Thorough understanding of network protocols and packet analysis tools.

• Comprehensive knowledge of EDR, anti-virus, and anti-malware technologies.

• Expertise in content filtering.

• Familiarity with email and web gateways.

• Strong understanding of malware, network, or system analysis.

• Professional experience in a system administration role managing multiple platforms and applications.

• Knowledge of best security practices.

• Ability to effectively collaborate and communicate security issues to clients, colleagues, and management.

• Excellent analytical and problem-solving abilities.

• Adaptable and resilient in fast-paced, evolving situations.

• Willingness to participate in an on-call rotation, including occasional nights and weekends.

• Technical expertise in networking, operating systems, and security technologies.

• Familiarity with SIEM, IDS/IPS, EDR, and forensic analysis tools.

• Understanding of incident response procedures and methodologies.

• Knowledge of MITRE ATT&CK and the Cyber Kill Chain frameworks.

• Familiarity with TCP/IP and application-layer protocols, such as HTTP, SMTP, and DNS.

• Experience in responding to and investigating cloud, system, or network intrusions.

• Expertise in forensics, malware analysis, and network intrusion response.

• Preferred: knowledge of common Windows and Linux/Unix system calls and APIs.

• Preferred: knowledge of programming languages.

• Preferred: understanding of internal file structures for malware-associated formats such as OLE, RTF, PDF, and EXE.

• Preferred: knowledge or experience in Detection Engineering.


🏝️ Benefits

• Comprehensive health, dental, and vision insurance.

• Retirement savings plan with company matching.

• Opportunities for professional development and training.

• Flexible work hours and remote work options.

• Dynamic and inclusive company culture.

People also viewed

Mercor9 hours ago

PDF Annotation & Transcription Expert – Japanese

JP flagJapan, +3 more countriesFreelanceUncategorized$33/hour
ApplyView job
CBT9 hours ago

German-Speaking Travel Support Advisor – Flights & Hotels

GR flagGreece OnlyFull-timeUncategorized€1,300/month
ApplyView job
Compass Experience Labs10 hours ago

Outbound Team Lead

US flagOhio OnlyFull-timeUncategorized$18/hour
ApplyView job
Bird's Eye Medical11 hours ago

Outreach and Referral Coordinator

US flagWashington OnlyFull-timeUncategorized$65k – $85k/year
ApplyView job
FUJIFILM Corporation12 hours ago

Clinical Specialist, Sonographer

US flagNew Jersey OnlyFull-timeUncategorized$90k – $125k/year
ApplyView job
T-Mobile12 hours ago

Field Technician

US flagTennessee OnlyFull-timeUncategorized$27 – $48/hour
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers