Investigate security signals, coordinate response, and improve defensive coverage in a mission-focused operations environment.
What you'll do
- Triage and investigate alerts using endpoint, network, identity, and cloud telemetry.
- Document findings, escalate incidents, and support containment and recovery.
- Tune detections and develop repeatable investigation playbooks.
What helps
- 3+ years in a SOC, incident response, or cyber defense role.
- Experience with SIEM, EDR, log analysis, and common attacker techniques.
- Security+ or equivalent baseline certification preferred.