Remotery

Senior Cyber Defense Analyst

atExperianRemoteUS flagUnited StatesFull-timeAnalystSenior$71.6k – $124.2k/year

Posted 19 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Execute daily security operations by observing, prioritizing, and conducting response measures for security events and alerts linked to cyber threats, intrusions, and breaches.

• Assess events using security tools and logging systems, such as SIEM and EDR, while evaluating the potential risk and severity of cyber threats.

• Elevate higher-risk incidents to specialized incident response and management teams in the CFC, in accordance with established protocols.

• Collaborate with external teams for effective incident resolution and escalations, facilitating incident handling processes.

• Inform team Lead(s) of any operational concerns, such as unusual changes in metrics, significant open incidents, quality issues, or perceived risks; assist in resolution if applicable.

• Oversee and manage assigned caseload throughout the incident response lifecycle, which includes analysis, containment, eradication, recovery, and post-incident review; uphold quality standards to resolve events.

• Preserve comprehensive case documentation, including notes, analysis findings, containment actions, and causation for each assigned security incident.

• Conduct incident updates or reach out to end-users swiftly and document these interactions, ensuring completion of case hand-off procedures, such as finalizing and verifying shift logs.

• Leverage subject matter expertise in security operations processes to enhance relevant playbooks, Standard Operating Procedures (SOPs), and training materials.

• Support team Leads and management in the development of use cases by suggesting enhancements or tuning of use cases to bolster Experian's security posture.

• Engage in paid overtime when operational demands necessitate additional support.


⛳️ Requirements

• A minimum of 3 years of experience in information security within a Security Operations Center or Cyber Security Incident Response Team.

• Bachelor’s Degree in Computer Science, Computer Engineering, Information Systems, Information Security, or a related discipline.

• Over 6 years of experience within a Security Operations Center, Incident Response Team, law enforcement, or military experience may be considered in lieu of this requirement.

• Proven understanding of the Incident Response Life Cycle, MITRE ATT&CK Framework, Cyber Kill Chain, and other cybersecurity frameworks.

• Demonstrated knowledge of common intrusion techniques and cyber-attack tactics, techniques, and procedures (TTPs), along with standard industry practices for investigating and responding to threats, such as phishing, malware, network attacks, suspicious activities, and data security incidents.

• Competence in identifying suitable methods for containing, eradicating, and recovering from various security incidents.

• Ability to provide recommendations to prevent recurrence of incidents.

• Familiarity with common Operating Systems (Windows, Linux, Mac OS), Networking (Firewalls, Proxies, NetFlow, etc.), Cloud Infrastructure (AWS, Azure, GCP), and Security Technologies (Anti-Virus, Intrusion Prevention, Web Application Firewalls, etc.).

• Skill in reviewing and interpreting device and application logs from diverse sources (e.g., Firewalls, Proxies, Web Servers, System Logs, Splunk, Packet Captures, etc.) to identify root causes and determine subsequent steps for containment, eradication, and recovery.

• Experience with standard Incident Response and Security Monitoring applications like SIEM (e.g., Qradar, Splunk), EDR (e.g., FireEye HX, CrowdStrike Falcon, Microsoft Defender, etc.); familiarity with Security Orchestration, Automation, and Response (SOAR) technologies such as Palo Alto XSOAR and Google Secops (Chronicle) is advantageous.

• Continuously enhance advanced cybersecurity expertise in areas like cloud security (Azure/AWS), incident response, threat detection, system and network forensics, SIEM/monitoring tools, vulnerability management, malware analysis, and scripting/automation.

• One or more professional certifications related to Digital Forensics, Incident Response, or Ethical Hacking are highly preferred (e.g., GCIH, GMON, GCED, GSOC, CEH, GCFE, GCFA, CFCE, ENCE).

• Bonus: Information security management certifications (CISSP, CISM) or vendor-specific certifications.


🏝️ Benefits

• Flexible Time Off: 20 Days

• Attractive compensation package and bonus plan

• Core benefits including medical, dental, vision, and a matching 401K

• Flexible work environment with options for remote, hybrid, or in-office work

• Flexible time off policy that includes volunteer time off, vacation, sick leave, and 12 paid holidays

People also viewed

Family Allergy & Asthma15 hours ago

Credentialing & Enrollment Analyst I

US flagFlorida, +6 more statesFull-timeAnalyst$50k – $55k/year
ApplyView job
Softplan15 hours ago

Junior Tax Analyst

BR flagBrazil OnlyFull-timeAnalyst
ApplyView job
Prime System Solutions15 hours ago

SQL Lead Analyst

PH flagPhilippines OnlyFull-timeAnalyst
ApplyView job
BizFirst LLC15 hours ago

Cost Analyst – Cost Modeling Subject Matter Expert

US flagUnited States OnlyFull-timeAnalyst
ApplyView job
Calyxo, Inc.15 hours ago

Manager, Complaint Analyst

US flagCalifornia OnlyFull-timeAnalyst$145k – $155k/year
ApplyView job
Five915 hours ago

Senior Professional Services Engagement Analyst

US flagUnited States OnlyFull-timeAnalyst$100k – $160k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers