Source description
About the role
Conduct forensic acquisition and analysis from on-premises and cloud platforms (Entra ID/Azure AD, M365, AWS, GCP, SaaS) to identify compromise activity, persistence mechanisms, and data exfiltration.
Investigate and respond to incidents and attacks targeting cloud and hybrid identity.
Correlate cloud control-plane events and network telemetry (e.g., Azure Activity Logs, AWS CloudTrail, VPC Flow Logs) to reconstruct attacker timelines, validate IOCs, and identify post-compromise privilege escalation.
Develop and operationalize detection logic and automation using cloud-native tools (Microsoft Defender, Sentinel, AWS GuardDuty, GCP Chronicle) and scripting (PowerShell, Python, Bash), integrating threat intelligence feeds and indicators.
Produce technical reports, incident documentation, and containment recommendations integrating cloud, identity, and endpoint findings; support development of incident response playbooks and procedures for cloud and hybrid environments.
Support cloud development and automation projects to enhance threat emulation, investigative, and hunting capabilities.
Coordinate with internal teams, government staff, and external stakeholders to validate alerts and investigate preliminary findings.
More at ARSIEM
Related open roles
Network Based Systems Analyst III
United States · Onsite
Network Based Systems Analyst III
United States · Onsite
Security Specialist
Remote · United States
Incident Manager III
United States · Onsite
382 - Analytic Developer
United States · Onsite
378 - Information System Security Engineer
United States · Onsite
