Cyber Incident Responder
Core
Respond to escalated cyber security incidents through preparation, investigation, remediation, and post-incident activities to prevent, detect, and respond to threats.
Role type
Senior IC Cyber Incident Responder
Builds
Incident response capabilities and security posture enhancements
Domain
Cybersecurity / Incident Response
Deliverable
client delivery
Required skills
Malware reverse engineering, SIEM analysis (Splunk), EDR usage (Microsoft Defender), Cloud security (AWS/Azure), Automation scripting (Python/PowerShell/Bash), Network protocols, OS internals, Incident management documentation
Preferred skills
GCIH or GREM certification
Technologies
Splunk, Microsoft Defender for Endpoints, AWS, Azure, Python, PowerShell, Bash
Responsibilities
Respond to escalated cyber security incidents and capture essential details; Analyse security logs and data to detect malicious activities including malware reversal; Coordinate and investigate events based on playbooks and SOPs; Utilize sensor data and correlated logs to establish context and scope; Collaborate with teams to contain and eradicate threats; Develop and implement incident response plans and procedures; Identify trends, potential new technologies, and emerging threats
Seniority
Senior, hands-on IC