31 Aug
|
Insight Global
|
Vapi
31 Aug
Insight Global
Vapi
Key Responsibilities:
- Lead the investigation and response of major cybersecurity incidents, including ransomware, phishing, insider threats, malware, credential compromise, and data breaches.
- Perform incident triage, analysis, containment, eradication, recovery, and post-incident activities.
- Conduct root cause and impact analysis to identify attack vectors, affected systems, and business impact.
- Analyze security alerts, logs, network traffic, endpoint telemetry, cloud activity, and threat intelligence to determine the scope of incidents.
- Utilize SIEM, EDR, NDR, cloud security, email security, and identity security tools to investigate and respond to security events.
- Correlate data from multiple security technologies to identify malicious activity, reconstruct attack timelines, and uncover threat actor behavior.
- Perform threat hunting activities and identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs).
- Serve as the technical lead during major incidents and coordinate response efforts across cybersecurity, infrastructure, cloud, application, legal, privacy, compliance, and business teams.
- Provide transparent incident communications, status updates, executive briefings, and ensure proper documentation and regulatory reporting.
- Develop, maintain, and optimize incident response playbooks, runbooks, and standard operating procedures.
- Design and implement automation and SOAR workflows to improve investigation efficiency, response consistency, and SOC effectiveness.
- Create and improve detection rules, use cases,
and response processes while driving continuous improvements through lessons learned, threat intelligence, and incident trend analysis.
Minimum Qualifications:
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related field.
- 10+ years of experience in cybersecurity, including significant experience in Security Operations Center (SOC) and Incident Response functions.
- Proven experience leading investigations of major cybersecurity incidents and security breaches.
- Strong understanding of incident response methodologies, attacker tactics, and forensic investigation techniques.
- Experience working in enterprise or global environments with complex security infrastructures.
- Ability to coordinate technical and non-technical stakeholders during high-pressure incident situations.
- Experience working in one of the SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, LogRhythm, etc.)
- Experience working in one of the Endpoint Detection and Response platforms (Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, etc.)
- Experience with query languages and scripting (KQL, SPL, Python, PowerShell, Bash/Shell scripting)
- Experience with API integrations and workflow automations
- Preferred Certifications:
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Enterprise Defender (GCED)
- CISSP
- Certified SOC Analyst (CSA)
- Microsoft Security Operations Analyst Associate
SANS Incident Response training or equivalent
NOTE : This role is a NIGHT SHIFT.
📌 Cyber Security Engineer (Vapi)
🏢 Insight Global
📍 Vapi