CAA
Technology
CybersecurityIncidentResponseAnalyst
Neural analysis suggests this role is
optimal for Mid candidates.
“Cybersecurity Incident Response Analyst at CAA. Skills: Incident Response, Threat Detection, Threat Hunting, Forensics. Conduct Incident Response activities. Conduct SOC detection activities”
Industry & Context.
Root cause analysis
Periodic on-call
What They're Looking For.
Must Have
3 years in Information Technology, 2 years Incident Response experience, 2 years Threat Hunting experience, 2 years forensics experience, Bachelor's or Master's degree, Windows disk and memory forensics, Network traffic analysis, Log Analysis, Unix or Linux disk and memory forensics, Malware analysis, Fundamental operations of servers, Fundamental operations of operating systems, Fundamental operations of networks, Fundamental operations of firewalls, Fundamental operations of cloud applications, Fundamental operations of infrastructure, Expertise building workflows, Expertise building playbooks, NIST framework understanding, Continuous improvement loop understanding, Frameworks to test security effectiveness, Frameworks to validate security effectiveness, Measuring ability to respond to threats, Measuring ability to respond to attacks
Nice to Have
Cloud based forensics, Memory forensics, Static malware analysis, Dynamic malware analysis
What You'll Do.
Conduct Incident Response activities
Conduct SOC detection activities
Conduct SOC response activities
Coordinate with technical stakeholders
Coordinate with business stakeholders
Perform host based analysis
Perform cloud based analysis
Perform network based analysis
Perform memory analysis
Review security information
Provide recommendations
Ensure technical security controls meet goals
Implement process of continual review
Implement process of continual improvement
Ensure measurable effectiveness of controls
How You'll Work.
Team & Collaboration
Technical stakeholders; Business stakeholders; Information Security group; Internal IT department; Service oriented environment
Full Job Description
## **Job Description** **Who We Are** This is a hands-on security position working within the Information Security group and with the internal IT department at large. This position’s core focus is to ensure consistent, measurable end to end triage and closure of security related events. The successful candidate will work to assess, develop, and deploy detection capabilities ensuring enterprise systems and data are protected. **The Role** We are looking for candidates who have a passion for Cyber Security, Threat Detection, Threat Hunting, and Incident Response. You will be a key part of our efforts to build and support a defensible environment where we are able to detect, contain and respond quickly to threats and compromise in ways that serve to enable the business needs a highly collaborative organization. The environment is fast-paced and commonly on the leading edge of technology, including early adoption of various cloud services along with the challenges of integrating those services into our security practice. **Responsibilities** * Conduct day-to-day Incident Response activities as well as additional SOC related detection and response activities as required for a global environment * Design, engineer, and implement runbooks and playbooks for Incident Response * Coordinate with both technical and business stakeholders during the incident response process. * Perform host based, cloud based, network based, memory, or log analysis and/or forensics in support of Incident Response investigations. * Play an active role in CAA’s Security Incident Response efforts, working to identify and mitigate information security threats * Review security information, event logs, and reports, provide findings and recommendations * Use input from IRM leadership and key security metrics to ensure technical security controls are meeting desired objectives; implement a process of continual review and improvement to ensure the measurable effectiveness of CAA’s technical controls * Ot
Applying for this Cybersecurity Incident Response Analyst role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about CAA?
Real rants from real employees. Read before you apply.