
Threat Analyst 2
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in India.
• Analyze escalated security alerts and incidents across endpoint, network, cloud, and identity environments.
• Conduct thorough investigations to ascertain root causes, attack scope, lateral movements, and potential impacts.
• Assist in ransomware investigations by examining attacker behavior, credential misuse, persistence methods, and malware activity.
• Deobfuscate dubious scripts, malware samples, and other indicators to detect malicious behaviors.
• Engage in proactive threat hunting based on established hypotheses and emerging threat intelligence.
• Examine suspicious authentication actions, privilege escalations, and identity misuse.
• Carry out investigations on both Windows and Linux systems, involving log and process analysis.
• Correlate data across EDR, SIEM, cloud logs, and identity management platforms.
• Document investigative outcomes and offer actionable remediation suggestions to clients.
• Collaborate with senior analysts during high-severity or intricate incidents.
• Contribute to the tuning of detection mechanisms and enhancement of response playbooks.
• Participate in a rotational schedule that supports a 24x7x365 Managed Detection and Response (MDR) environment.
• Utilize enterprise, log analysis, and endpoint collection systems to investigate, identify, and mitigate cyber threats.
• Aid in monitoring, detection, and response services.
• 3–5 years of experience in a Security Operations Center (SOC), Managed Detection and Response (MDR), Incident Response, or a similar cybersecurity operations role.
• Experience in investigating endpoint and network security alerts using EDR and SIEM solutions.
• Working knowledge of ransomware attack methodologies and common intrusion tactics.
• Practical experience in investigating Linux and Windows systems.
• Experience in analyzing obfuscated scripts and malware behavior, including deobfuscation techniques.
• Familiarity with adversarial tactics and techniques, as well as practical exposure to the MITRE ATT&CK framework.
• Experience with analyzing Windows Event Logs, Linux logs, and fundamentals of Active Directory.
• Basic understanding of cloud and identity security investigation processes.
• Ability to analyze network traffic, including TCP/IP, DNS, and HTTP/S protocols.
• Proficiency in scripting, particularly with PowerShell; knowledge of Python or other languages is essential.
• Strong documentation abilities and meticulous attention to investigative details.
• Security certifications such as Security+, CySA+, or GCIH, or equivalent, are advantageous.
• Bachelor’s degree in Information Technology, Computer Science, or a related field, or equivalent professional experience.
• Excellent analytical and troubleshooting capabilities.
• Capacity to manage multiple investigations in a fast-paced environment.
• Effective written and verbal communication skills.
• Legal authorization to work in India without employer sponsorship.
• Remote-first working model.
• Employee-driven diversity and inclusion networks.
• Annual charity and fundraising initiatives.
• Volunteer days.
• Global employee sustainability programs.
• Global fitness and trivia competitions.
• Global well-being days.
• Monthly well-being webinars and training sessions.
• Adjustments in the recruitment and selection process for accessibility.
St. Charles Health System
Mars
Velocity, A Managed Solutions Company
Fennemore
Get handpicked remote jobs straight to your inbox weekly.