
Senior Cybersecurity Ops Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Tennessee.
• Manage escalated cybersecurity cases while overseeing triage, investigation, containment, eradication, and recovery efforts.
• Perform incident investigations utilizing forensic analysis, SIEM, EDR, endpoint, identity, email, network, cloud, and other enterprise security telemetry.
• Assess incident scope, impact, root cause, and potential data exposure.
• Coordinate approved remediation actions such as account disablement, session revocation, email purge, endpoint isolation, IP or URL blocking, and access reviews.
• Create investigative timelines, case narratives, evidence summaries, technical findings, and response documentation.
• Collaborate with the ESOC and cybersecurity team to validate findings, communicate risks, coordinate responses, and resolve incidents.
• Identify gaps in detection, control, forensic visibility, response, and process improvements.
• Assist in purple team exercises, translating findings into enhanced monitoring, investigation, and response procedures.
• Lead tabletop exercises to validate response processes, escalation paths, communication workflows, analyst readiness, and interdepartmental coordination.
• Provide training, mentoring, and knowledge sharing to junior team members.
• Develop, maintain, and enhance incident response playbooks, forensic investigation guides, case templates, escalation procedures, and operational documentation.
• Support threat hunting and proactive analysis initiatives.
• Contribute to ESOC's continuous improvement efforts, AI and automation, case management, workflow refinement, documentation, and operational reporting.
• Address 24/7/365 operational needs during high-priority incidents or high-tempo events.
• Undertake additional responsibilities and operational tasks as assigned.
• Bachelor’s degree with 5+ years of relevant experience; or a master’s degree with 3+ years of relevant experience.
• An equivalent of 4+ years of experience may be accepted in place of a degree.
• 3+ years of experience in cybersecurity operations supporting enterprise security monitoring, incident response, forensic analysis, or cyber investigations.
• Practical experience with enterprise SIEM technologies, preferably Splunk.
• Hands-on experience with EDR or endpoint security platforms to investigate suspicious activities, endpoint behaviors, malware, account compromises, and incident scopes.
• Must have CySA+, SSCP, or an equivalent certification.
• Strong leadership abilities with a demonstrated capacity to lead and inspire a team effectively.
• Self-driven and quick to learn.
• Excellent verbal and written communication skills.
• Ability to multitask and collaborate to resolve complex technical challenges.
• US Citizenship is mandatory.
• CISSP, GCIH, or GCFA certifications are preferred.
• 4x10 work schedule, from 7:00 a.m. EST to 5:00 p.m. EST, Monday through Thursday.
• Remote work option available for qualified candidates within the United States.
• 24/7/365 operational coverage support as required.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.