Padmi
ARSIEM logo
ARSIEM

Microsoft 365 development · Power Platform and SharePoint

Host Based Systems Analyst III

United States · OnsitePosted 9 months ago
SecurityStaff+Full Time
Apply at ARSIEM

Opens the source posting on jobs.lever.co

Source description

About the role

View original

Conduct forensic acquisition and analysis from on-premises and cloud platforms (Entra ID/Azure AD, M365, AWS, GCP, SaaS) to identify compromise activity, persistence mechanisms, and data exfiltration.

Investigate and respond to incidents and attacks targeting cloud and hybrid identity.

Correlate cloud control-plane events and network telemetry (e.g., Azure Activity Logs, AWS CloudTrail, VPC Flow Logs) to reconstruct attacker timelines, validate IOCs, and identify post-compromise privilege escalation.

Develop and operationalize detection logic and automation using cloud-native tools (Microsoft Defender, Sentinel, AWS GuardDuty, GCP Chronicle) and scripting (PowerShell, Python, Bash), integrating threat intelligence feeds and indicators.

Produce technical reports, incident documentation, and containment recommendations integrating cloud, identity, and endpoint findings; support development of incident response playbooks and procedures for cloud and hybrid environments.

Support cloud development and automation projects to enhance threat emulation, investigative, and hunting capabilities.

Coordinate with internal teams, government staff, and external stakeholders to validate alerts and investigate preliminary findings.

More at ARSIEM

Related open roles

View all roles