Job Description
About the Role
We are looking for a Senior Cybersecurity Specialist to join a global Cyber Defense team and play a key role in protecting enterprise systems and data from sophisticated cyber threats. This is a hands-on position focused on complex incident response, threat hunting, detection engineering, and security investigations, with opportunities to lead major incidents and provide technical guidance to the SOC team.
Key Responsibilities:
-
Lead the investigation, containment, and response of complex and high-severity cyber incidents.
-
Perform advanced root cause, attack chain, malware, and forensic analysis using endpoint, SIEM, cloud, and threat intelligence data.
-
Conduct proactive threat hunting and identify emerging threats and attack techniques.
-
Develop and enhance detection rules, security use cases, and monitoring capabilities.
-
Work with CrowdStrike, Microsoft Defender, SIEM, EDR/XDR, and other security technologies.
-
Map threats and detections to MITRE ATT&CK and support threat modelling activities.
-
Lead incident response activities with SOC, Cloud, Infrastructure, Identity, and IT teams.
-
Develop and improve incident response playbooks, procedures, and security processes.
-
Act as a senior escalation point during major security incidents and provide technical guidance to SOC analysts.
-
Support purple-team, tabletop, and adversary simulation exercises to strengthen security controls.
-
Identify security gaps and drive improvements across detection and incident response capabilities.
Key Requirements:
-
Bachelor's Degree in Cybersecurity, Information Security, Computer Science, or a related field.
-
5+ years of hands-on experience in Security Operations, Incident Response, Threat Hunting, or a related cybersecurity function.
-
Strong experience handling complex cyber incidents within enterprise environments.
-
Strong knowledge of MITRE ATT&CK, Cyber Kill Chain, NIST, ISO 27001, and CIS Controls.
-
Advanced knowledge of Windows, Active Directory, Entra ID, networking, and enterprise security environments.
-
Hands-on experience with CrowdStrike, Microsoft Defender, SIEM, EDR/XDR, and cloud security technologies.
-
Working knowledge of Azure, AWS, and Microsoft 365 security.
-
Experience with PowerShell, Python, KQL, or similar scripting/automation tools.
-
Experience leading technical investigations and mentoring SOC analysts.
-
Relevant certifications such as CISSP, GCIA, GCIH, GCFA, GCFE, SC-200, or CrowdStrike certifications are an advantage.