Job description
Incident Response Cyber Defense Lead and participate in security incident investigations across cloud, on-premises, and hybrid environments, including high-severity events and major incidents. Coordinate investigation and reponse activites with engineering, platrom, indentity, network, application and other partner teams. Develop and maintain incident response playbooks, procedures and operational runbooks. Improve Cyber Defense capabilities through process optimization, automation, lessons learned and recommendations that reduce security exposure. Analyze attempted and successful compromises, perform proactive threat hunting and develop response and mitigation recommendations with partner teams. Participate in an on-call rotation supporting security services and incident response. Design and implement SOAR workflows, response automation, and operational tooling using PowerShell, Python, KQL, Logic Apps, Azure Functions, or equivalent technologies. 3+ years of experience in cybersecurity, Security Operations Center operations, incident response, Cyber Defense, Blue Team functions, large-scale computing, software development, or a related technical field; Experience investigating security incidents such as malware, credential compromise, unauthorized access, insider threats, or related malicious activity. These requirements include, but are not limited to the following specialized security screenings: CISSP, CISA, CISM, SANS, GCIA, GCIH, OSCP, PCCSE, PCNSE, PCSAE, CCNP Security, CCIE Security and/or Security+ certification. Any experience conducting investigations involving OT, manufacturing, critical infrasructure, energy or industrial enviroments is highly preferred (not mandatory) Hands-on experience with multiple scripting or automation languages.