n
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related field.
n
- 10+ years of experience in cybersecurity, including significant experience in Security Operations Center (SOC) and Incident Response functions.
n
- Proven experience leading investigations of major cybersecurity incidents and security breaches.
n
- Solid understanding of incident response methodologies, attacker tactics, and forensic investigation techniques.
n
- Experience working in enterprise or global environments with complex security infrastructures.
n
- Ability to coordinate technical and non-technical stakeholders during high-pressure incident situations.
n
- Experience working in one of the SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, LogRhythm, etc.)
n
- Experience working in one of the Endpoint Detection and Response platforms (Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, etc.)
n
- Experience with query languages and scripting (KQL, SPL, Python, PowerShell, Bash/Shell scripting)
n
- Experience with API integrations and workflow automations
n
- Preferred Certifications:
n
- GIAC Certified Incident Handler (GCIH)
n
- GIAC Certified Forensic Analyst (GCFA)
n
- GIAC Certified Enterprise Defender (GCED)
n
- CISSP
n
- Certified SOC Analyst (CSA)
n
- Microsoft Security Operations Analyst Associate
n
- SANS Incident Response training or equivalent
n