Associate Analyst
Responsibilities:
Investigate and respond to security incidents across network, endpoint, email, and cloud environments to ensure timely containment, eradication, and recovery.
Conduct in-depth analysis by correlating events, alerts, and logs from tools such as SIEMs, EDRs, and firewalls to identify suspicious or malicious activity.
Develop, maintain, and execute incident response playbooks to ensure consistent, effective, and repeatable handling of security threats.
Perform deep-dive investigations to determine the root cause of security incidents and ensure accurate documentation of findings.
Collaborate with internal teams including threat intelligence, detection engineering, and infrastructure to ensure coordinated and comprehensive incident resolution.
Analyze indicators of compromise (IOCs) and attacker techniques post-incident to improve detection, prevention, and response capabilities.
Assist in post-incident reviews and reporting to identify process gaps, drive improvements, and strengthen overall incident response posture.
Prepare and deliver reports to senior leadership as needed, covering playbook usage, root cause analysis, standard procedures, and remediation outcomes.
Facilitate effective communication with stakeholders during and after security incidents to ensure alignment, transparency, and clarity.
Stay up to date on the latest cybersecurity threats, vulnerabilities, and attacker trends to continuously improve detection and response strategies.
Qualifications:
Proficient in Incident Management, Detection and Response.
Extensive knowledge on network, endpoint, threat intelligence, as well as the functioning of specific applications or underlying IT infrastructure.
Understanding of possible attack activities such as network, phishing, scanning, DDOS, malicious code activity etc.
Threat Hunting Understanding of attacker techniques that leverage email and cloud-service tactics.
Experience dealing with advanced persistent threats (APTs) and hu...