About this role
- Monitor security alerts and events across the Cyderes security platform and customer environments
- Analyze, investigate, and respond to security events to drive effective customer outcomes
- Perform initial triage and determine the severity, scope, and potential impact of security incidents
- Investigate suspicious activity across endpoints, networks, identity systems, cloud environments, and security technologies
- Escalate confirmed or high-risk incidents to appropriate incident response or senior security resources
- Participate as a member of the incident response process and assist with containment and remediation activities
- Review security telemetry, logs, alerts, and other data sources to identify malicious or abnormal behavior
- Maintain accurate documentation of investigations, findings, actions taken, and customer communications
- Perform day-to-day operational security tasks and ensure established processes and service expectations are met
- Communicate clearly with customers and internal stakeholders regarding security events and recommended actions
- Identify opportunities to improve detection capabilities, operational processes, automation, and overall platform effectiveness
- Collaborate with other Cyderes teams including Managed Detection & Response, Threat Hunting, Incident Response, Engineering, and Customer Success
- Experience working within a Security Operations Center (SOC), Managed Security Service Provider (MSSP), or Managed Detection & Response (MDR) environment
- Experience with SIEM and log-management platforms such as Splunk, Elastic Stack, Microsoft Sentinel, Google Security Operations, or similar technologies
- Experience with Endpoint Detection and Response technologies such as CrowdStrike, Microsoft Defender, SentinelOne, or similar platforms
- Experience with cloud environments and technologies including AWS, Microsoft Azure, and Google Cloud Platform
- Experience supporting Microsoft 365, Entra ID/Azure AD, Proofpoint, or other enterprise security platforms
- Scripting or development experience with technologies such as Python, PowerShell, or JavaScript
- Advanced system administration experience with Windows PowerShell, Ansible, SaltStack, Chef, Puppet, or similar technologies
- Experience with Security Orchestration, Automation, and Response (SOAR) technologies such as Cortex XSOAR, Splunk SOAR, or comparable platforms
- Familiarity with incident response, threat hunting, digital forensics, or malware analysis
- Understanding of the MITRE ATT&CK framework and common adversary behaviors
- Relevant cybersecurity certifications are a plus
Tech stack
AWSAzurePythonJavaScript
Salary context
-60%
below median
Based on 24,000+ Engineering roles with disclosed salary ranges tracked on NewJob.