We are seeking a deeply technical cybersecurity professional who can personally investigate complex security incidents while developing software and automation that improve detection and response capabilities.
This is a hands-on individual-contributor position—not primarily a SOC management, governance, or compliance role. The successful candidate will spend most of their time conducting technical investigations, developing detections, writing code, automating security workflows, and strengthening incident-response processes.
The ideal candidate can independently investigate security activity across endpoints, identities, networks, cloud platforms, and applications; determine the scope and root cause of an incident; execute containment and remediation actions; and develop reliable tools and automation using Python, PowerShell, APIs, and security platforms.
Key Responsibilities
- Lead hands-on investigations of malware, compromised accounts, phishing, lateral movement, unauthorized access, data exfiltration, insider threats, and cloud security incidents.
- Analyze endpoint, network, identity, cloud, application, email, firewall, authentication, SIEM, and EDR telemetry.
- Determine incident scope, root cause, affected systems, attacker activity, business impact, and required remediation.
- Build detailed incident timelines and document investigative findings, evidence, decisions, and response actions.
- Perform proactive threat hunting across enterprise environments.
- Develop and tune SIEM detections, correlation rules, investigation queries, alerts, dashboards, and enrichment workflows.
- Write maintainable Python and/or PowerShell code to automate investigation, evidence collection, enrichment, containment, and reporting.
- Build integrations between security platforms using REST APIs, webhooks, JSON, and other structured data.
- Develop and maintain SOAR workflows and automated incident-response actions.
- Review existing detections and response processes to identify visibility gaps and opportunities for automation.
- Create clear, technically detailed incident-response playbooks that analysts can consistently execute.
- Work with security, infrastructure, cloud, application, and software engineering teams to remediate vulnerabilities and security weaknesses.
- Provide technical guidance during major incidents while remaining directly involved in the investigation.
- Conduct post-incident reviews and translate lessons learned into improved detections, tools, playbooks, and controls.
- Mentor other analysts and share technical knowledge without moving away from hands-on investigative work.
Required Qualifications
- At least five years of hands-on experience in incident response, digital forensics, threat hunting, detection engineering, security engineering, or advanced SOC operations.
- Demonstrated experience serving as a primary technical investigator for significant cybersecurity incidents.
- Strong Python development experience and proficiency with PowerShell, Go, Java, C#, or another relevant programming language.
- Experience developing security tools, scripts, integrations, or automation—not simply using existing security platforms.
- Understanding of software engineering practices, including Git-based version control, testing, code reviews, reusable design, structured logging, documentation, and error handling.
- Advanced experience working with SIEM, EDR, identity, cloud-security, email-security, and network-security technologies.
- Strong knowledge of Windows and Linux operating systems, endpoint behavior, authentication activity, process execution, network communications, and common forensic artifacts.
- Experience investigating compromised credentials, malicious processes, persistence mechanisms, lateral movement, command-line activity, suspicious network connections, and data-access events.
- Ability to develop complex SIEM queries and detection logic using tools such as Microsoft Sentinel, Splunk, QRadar, or similar platforms.
- Experience integrating systems through REST APIs and working with structured data such as JSON.
- Strong understanding of the incident-response lifecycle, MITRE ATT&CK framework, common attacker techniques, and containment and remediation strategies.
- Ability to communicate complex technical findings clearly to both technical teams and business stakeholders.
- Strong written English and experience producing detailed incident reports, investigative documentation, and response playbooks.
Preferred Qualifications
- Experience with Microsoft Sentinel, Microsoft Defender, CrowdStrike, Carbon Black, Splunk, or similar platforms.
- Experience developing SOAR playbooks and automated response workflows.
- Familiarity with Azure, AWS, Microsoft 365, Entra ID, Active Directory, and cloud logging.
- Experience with malware analysis, memory analysis, disk forensics, email investigations, or network forensics.
- Experience building internal security applications, enrichment services, case-management integrations, or investigation tools.
- Experience working with DevOps or CI/CD pipelines.
- Relevant certifications such as CISSP, GCIH, GCFA, GCIA, GNFA, OSCP, SC-200, or equivalent practical experience.
What We Are Looking For
We are looking for someone who can clearly explain:
- A complex incident they personally investigated from initial alert through containment and recovery.
- The evidence and forensic artifacts they personally analyzed.
- How they determined the scope and root cause of the incident.
- A security tool, integration, or automation they personally designed and coded.
- How their work improved investigation quality, response speed, or detection coverage.