





Senior (12+ yrs) niche SOC/IR role with specific EDR/SIEM tool requirements reduces applicant competition.
Core IR and threat-intelligence skills transfer across industries, but leadership and tooling needs increase sensitivity.
Explicit 12+ years, leadership, and specific EDR/SIEM/IR expertise create strict shortlisting filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead end-to-end cyber incident response including detection, containment, eradication, recovery, and forensic investigations for high-severity events.
Develop and execute threat intelligence strategy, analyzing attacker behaviors and translating intelligence into detection use cases and defensive strategies.
Oversee detection engineering, threat hunting initiatives, and security monitoring across endpoints, networks, and cloud environments; lead and develop the security operations team.
Bachelor’s degree in Cybersecurity, IT, or related field (or equivalent experience).
12+ years experience in incident response, threat intelligence, or security operations; leadership experience preferred.
Proven ability leading high-impact incident response efforts and managing critical security events.
Hands-on experience with EDR tools (CrowdStrike Falcon, SentinelOne, Microsoft Defender), NDR/XDR platforms (ExtraHop, Cisco XDR), and SIEM/log analysis tools.
Experienced leader capable of commanding incident response during severe cyber events and coordinating cross-functional teams and stakeholders.
Deep expertise in attacker methodologies, malware analysis, MITRE ATT&CK framework, and threat intelligence integration into detection and response.
Operates effectively in high-pressure, dynamic security operations environments with focus on continuous program improvement and resilience.