





Tier-1 brand and metro location increase competition despite specialized SOC/IR skillset.
Specialized SOC/IR and DFIR skills limit cross-industry transferability, so background sensitivity is high.
Requires advanced SOC/DFIR/SIEM/EDR expertise and cloud incident handling, enforcing strict technical filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead advanced triage and incident response activities including log analysis, threat validation, malware analysis, containment, eradication, recovery, and documentation.
Serve as escalation point for alerts from SIEM, EDR, and other security tools to enable rapid detection and response to cybersecurity threats.
Develop and maintain incident response SOPs, lead efforts to improve alert fidelity, detection logic, automation opportunities, and support threat hunting initiatives.
Advanced experience in Security Operations, Incident Response, Threat Detection, DFIR, and Malware Reverse Engineering.
Strong expertise with log analysis, EDR platforms, SIEM technologies such as Splunk or Sentinel.
Hands-on incident response experience including containment, eradication, recovery in on-prem, cloud, or hybrid environments.
Work Experience Required: Not explicitly mentioned in the JD.
Experienced in leading complex incident investigations including lateral movement and cloud incident handling.
Strong understanding of network security, OS internals (Windows, Linux), MITRE ATT&CK framework, and forensics methodologies.
Capable of developing IR playbooks, collaborating across technical and business teams during high-severity incidents, and mentoring junior analysts.