Security Analyst, Managed Detection & Response
Remote (US)
At-Bay
At-Bay is a cyber insurance provider designed from the ground up to help businesses meet digital risk head-on.Security Analysts provide first-line security monitoring services to At-Bay’s Managed Detection & Response customers with specific responsibilities including:
- Operation and tuning of security monitoring tools including Endpoint Detection & Response (EDR), network monitoring, email security, Data Loss Prevention (DLP), Security Information and Event Management (SIEM), security automation tools, and others as needed
- Identification and analysis of anomalous activity in customer technology environments
- Triage of event data to identity potential indicators of compromise
- Escalation of potentially malicious activity to engage incident responders where necessary
- Participation in incident investigation, containment, remediation, and recovery activities where necessary
- Developing and maintaining customer relationships to facilitate delivery of MDR services
- Developing and delivering reports on identified activity to customer stakeholders as needed
Key skills
- Previous EDR, MDR, XDR, security monitoring, or incident response experience
- Strong oral and written communications skills
- Previous hands-on experience performing security operations including several of the following:
- Security monitoring using a variety of endpoint and network tools
- Deployment, tuning, and operation of security tools from vendors such as CrowdStrike, SentinelOne, and others
- Deployment, tuning, and operation of SIEM or other tools used to aggregate and analyze security-relevant data
- Triage and analysis of potential indicators of compromise
- Performing rapid response to contain and/or remediate potentially malicious activity
- Development and analysis of cyber threat intelligence
- Participation in investigations involving digital evidence
- Intrusion detection / cyber threat hunting
- Malware analysis
- Previous hands-on experience working in information technology operations (e.g., Network Operations Center, Security Operations Center, Incident Response Team, etc.)
Minimum requirements
- Bachelor’s degree or equivalent
- Minimum of 2 years of experience in cybersecurity operations, incident response, or another security discipline
- Willingness to travel as needed to perform job functions
Preferred requirements
- Significant undergraduate or graduate coursework in computer science, computer engineering, information systems, or cybersecurity
- Preferred candidates will have a mix of cybersecurity experience including either security operations or security engineering / architecture
- Knowledge of cloud environments including knowledge of cloud security products and services offered by major cloud service providers (e.g., AWS, Azure, Google)
- One or more industry cybersecurity certifications (e.g., GCIH, Security+, CISSP, etc.)
Work location
- USA, nationwide
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Automation AWS Azure CISSP Cloud Computer Science CrowdStrike EDR GCIH Incident response Intrusion detection Malware Monitoring SIEM SOC Threat intelligence XDR
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open IT Security Analyst jobs
- Open Senior Information Security Analyst jobs
- Open Consultant SOC / CERT H/F jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Security Operations Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Ingénieur DevSecops H/F jobs
- Open Staff Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Architect jobs
- Open Chief Information Security Officer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open o365 Security Architect jobs
- Open Senior Security Analyst jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Product Security Engineer jobs
- Open Security Researcher jobs
- Open Cyber Security Architect jobs
- Open GCP-related jobs
- Open SOC-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open Governance-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open CISM-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open Threat intelligence-related jobs
- Open IAM-related jobs
- Open Malware-related jobs
- Open Java-related jobs
- Open Security Clearance-related jobs
- Open Vulnerability management-related jobs
- Open CISA-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Security assessment-related jobs
- Open Forensics-related jobs
- Open APIs-related jobs
- Open SQL-related jobs
- Open CI/CD-related jobs
- Open EDR-related jobs