Sr Cyber Defense Ops Specialist
Listed on 2026-03-01
-
IT/Tech
Cybersecurity, Security Manager
Role Description
We are seeking a Level 2 Cybersecurity Analyst to support Cyber Defense Operations within a large enterprise environment. This role is responsible for advanced security event investigation, incident response support, and threat analysis, as well as contributing to the continuous improvement of detection and response capabilities. The analyst will collaborate with Level 1 analysts, threat intelligence teams, and incident response stakeholders to ensure timely identification, containment, and remediation of security threats across the enterprise.
Key Responsibilities- Investigate and analyze escalated security alerts and incidents from Level 1 analysts.
- Perform root cause analysis and assess business and technical impact of security events.
- Conduct proactive threat hunting and anomaly detection across enterprise systems and networks.
- Collaborate with incident response teams to support containment, eradication, and recovery activities.
- Correlate external threat intelligence with internal telemetry to identify emerging threats and attack patterns.
- Contribute to the development of detection use cases and provide recommendations for tuning SIEM and monitoring rules.
- Recommend enhancements to incident response playbooks and operational runbooks.
- Provide technical guidance and mentorship to junior analysts.
- Participate in post-incident reviews and contribute to lessons learned and continuous improvement initiatives.
- Represent Cyber Defense Operations in cross-functional security, risk, and compliance activities as required.
- Strong understanding of network, endpoint, and security monitoring concepts.
- Knowledge of threat actor tactics, techniques, and procedures (TTPs).
- Familiarity with the MITRE ATT&CK framework and threat intelligence methodologies.
- Awareness of regulatory and compliance frameworks such as NIST, ISO, and PCI-DSS.
- Proficiency in log analysis, packet capture analysis, and malware investigation.
- Strong analytical, troubleshooting, and problem-solving skills.
- Experience with scripting or automation using languages such as Python, Power Shell, or Bash.
- Effective written and verbal communication skills for both technical and non-technical stakeholders.
- Ability to work independently and collaboratively in a fast-paced, incident-driven environment.
- Bachelor’s degree in Cybersecurity, Computer Science, or a related discipline, or equivalent professional experience.
- 2–5 years of experience in cybersecurity operations, security monitoring, or incident response.
- Industry-recognized security certifications (e.g., CySA+, GCIH, GCIA, CEH, or equivalent) preferred.
- Hands‑on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar) and endpoint detection and response (EDR) tools (e.g., Crowd Strike, Microsoft Defender).
- Willingness to participate in a rotating on‑call schedule or provide extended coverage during critical security incidents.
- SIEM Platforms:
Splunk, Arc Sight, Microsoft Sentinel, QRadar - EDR/XDR Solutions:
Crowd Strike, Microsoft Defender, Sentinel One - Network Security Technologies:
Palo Alto, Cisco, Check Point, Firepower - Data Protection Technologies:
Symantec DLP, Triton, Guardium - Threat Intelligence and SOAR platforms
- Cloud security monitoring in AWS, Azure, or GCP environments
- Hours:
11pm- 9am - Days:
Wednesday - Saturday
Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance.
Equal Employment OpportunityCitizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).