The role
0301Lead complex cyber incident investigations across enterprise, cloud, hybrid, and on-premises environments.
02Conduct end-to-end incident response activities including triage, scoping, containment, eradication, recovery, and post-incident reporting.
03Perform DFIR activities across Windows, cloud, identity, endpoint, network, and application environments.
04Conduct proactive threat hunting to identify adversary behaviors, emerging threats, and control gaps.
05Support the engineering, administration, and optimization of cyber security tools and platforms.
06Use AI-assisted tools, copilots, automation, and scripting to improve investigation efficiency, reporting, and analysis.
07Serve as a senior technical lead during significant cyber security investigations and incident response efforts.