Defensive Security Analyst
Manages SOC systems to detect, contain, and eradicate threats. Develops detection strategies, performs forensics and hunt operations, requiring SOC experience, scripting skills (Python, PowerShell, Bash), and TS/SCI clearance.
About the job
Core Responsibilities
- Build, run, and own infrastructure and automation to detect, contain, and eradicate security threats.
- Develop alerting and detection strategies to identify malicious or anomalous behavior.
- Develop comprehensive and accurate reports and presentations for both technical and executive audiences.
- Develop new and novel defensive techniques to identify or counteract changes in adversary techniques and tactics.
- Dissect network, host, memory, and other artifacts originating from multiple operating systems and applications.
- Perform enterprise-wide operations to uncover sophisticated and undetected threats.
- Partner closely with other members of the Information Security team to lead changes in the company's network defense posture.
- Provide expertise in a supporting capacity for incident response activities and digital forensics state preservation, including the capture and preservation of system logs, volatile memory captures, and hard drive (physical or virtual) image captures.
- Conduct host forensics, network forensics, log analysis, and malware triage in support of hunt operations.
- Interface with client contact(s) and staff in a constructive and professional manner.
- Utilize common forensic and incident response tools.
What We Value
- Knowledge of operating and maintaining a SIEM.
- Knowledge of cloud architectures, particularly AWS.
- Experience in penetration testing.
- Ability to quickly learn new technologies and have an ongoing desire to stay current with the latest technologies.
- Ability to train others on the use of forensic and incident response techniques and tools.
What We Require
- TS/SCI Clearance.
- Established experience in operating in SOC environment, either through relevant experience or qualifications.
- Experience with programming or scripting languages such as PowerShell, Python, and Bash.
Skills
SIEM, AWS, PowerShell, Python, Bash, Incident Response, Digital Forensics, Malware Analysis, Log Analysis, Penetration Testing
Similar jobs
Security Engineering jobsSecurity Engineer on the Cyber Threat Intelligence team responsible for developing threat intel tooling, conducting threat hunting, analyzing malware, and operationalizing intelligence into detections and response workflows.
Designs and incubates technical defenses against complex abuse and fraud across Stripe’s payment, onboarding, identity, and Connect surfaces. Requires 3+ years of security or software engineering experience, strong production programming and SQL skills, and expertise in API safeguards and automated testing.
The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.