More jobs:
Senior Cybersecurity Analyst
Job in
Thomson, McDuffie County, Georgia, 30824, USA
Listed on 2026-03-02
Listing for:
Consortium for Clinical Research and Innovation Singapore
Full Time
position Listed on 2026-03-02
Job specializations:
-
IT/Tech
Cybersecurity, Security Manager
Job Description & How to Apply Below
Detection Engineering
- Design and fine-tune high-fidelity detection rules across SIEMs (Splunk, Sentinel, Devo, QRadar) and EDR platforms.
- Build custom use cases based on MITRE ATT&CK and red team insights.
- Eliminate false positives, improve alert accuracy, and continuously optimize detection logic.
- Collaborate with red/purple teams to validate and evolve detection strategies.
- Proactively hunt for threats across hybrid environments using telemetry from SIEM, EDR, and NDR tools.
- Leverage threat intelligence and frameworks (MITRE, Diamond Model) to build and execute targeted hunting campaigns.
- Analyze and operationalize threat intel to inform detection rules and incident response.
- Lead end‑to‑end investigations—from triage to recovery—during security incidents.
- Conduct forensic analysis and produce detailed reports with root cause and mitigation plans.
- Develop playbooks, runbooks, and coordinate across teams and clients during major events.
- Mentor junior analysts and contribute to process automation and SOP development.
- Engage with customers through regular reviews, briefings, and incident updates.
- Drive continuous improvement through lessons learned, threat trends, and feedback loops.
- 8–10+ years in SOC/MSSP environments with deep SIEM (Splunk, QRadar, Sentinel, Devo) and EDR (Crowd Strike, Defender) expertise.
- Hands‑on experience with SOAR platforms, malware analysis, scripting (shell, Python), and basic Unix/Linux troubleshooting.
- Strong grasp of threat detection, cyber TTPs, and frameworks like MITRE ATT&CK.
- Excellent communication skills and the ability to lead cross‑functional collaboration.
- SANS certification (e.g., GCIH) strongly preferred.
- Experience with threat hunting, vulnerability assessments, or DFIR.
- Familiarity with cloud platforms (AWS, Azure, GCP) and network security tools.
- Exposure to threat intel platforms like MISP.
We regret that only shortlisted candidates will be notified. However, rest assured that all applications will be updated to our resume bank for future opportunities.
#J-18808-LjbffrPosition Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×