Cyber Detection and Response Specialist
Core
Provides cyber security incident detection and response for computing, network, and application environments by investigating vulnerabilities, performing security data analytics, and responding to MSSP/SOC events.
Role type
Cyber Detection and Response Specialist (IC)
Builds
Managed Security Service Partner (MSSP) platform operations and customizations
Domain
Insurance industry cybersecurity
Required skills
SIEM content development, incident response, threat hunting, scripting/programming, log analysis, network security fundamentals, Windows/UNIX administration, security controls understanding
Preferred skills
SPLUNK, SANS, ISC2, CompTIA CySA certifications, experience with Arcsight/Qradar/Nitro, vendor product exposure (Splunk/F5/Palo Alto/Qualys)
Technologies
Splunk, Arcsight, Qradar, Nitro, F5, Palo Alto, Qualys, regex
Responsibilities
Review and investigate potential security vulnerabilities and incidents; perform security data analytics; respond to MSSP/SOC events; develop and customize MSSP platform; address critical/high/medium findings per incident response policy
Seniority
Mid-level, hands-on IC