Remote · Senior · Remote
Applicants who checked fit first are 3.1× more likely to hear back
Your score for this role already exists
ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.
No credit card · 1 tap with Google
MEDIUM
UltraViolet Cyber is reviewing applications at a steady pace. Expect a standard response time as they evaluate the current pool.
First 72 hours
Still inside it - posted 2h agoEarly applicants get seen before the pile builds.
Not a repost
The first time we've seen this listing - it hasn't been closed and reopened.
You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.
Works as part of a Cyber Defense team that works 24/7 on rotational shifts.
Continuously monitor and respond to advanced threats and evolving attack vectors across multiple environments
Perform in-depth investigation and triage of security alerts to determine root cause, impact, and relevance.
Correlate alerts and telemetry from SIEM and log sources like EDR, IPS, Firewall and threat intelligence platforms to identify real threats.
Handle detections targeting cloud infra/services/applications.
Provide recommendations for containment, mitigation, and recovery to client or internal response teams.
Contribute to the development and fine-tuning of detection rules, analytics, and use cases to enhance threat visibility and strength overall defense posture.
Collaborate closely with Threat Intelligence, SOAR, and Engineering teams for enrichment and contextual analysis.
Document investigations, findings, and recommendations in accordance with SOC SOPs and reporting standards.
Serve as a subject matter expert on detection and response methodologies, including SIEM, SOAR, threat intelligence, log analysis, network and EDR telemetry, and other response techniques.
Develop and maintain accurate documentation which includes SOPs, playbooks, runbooks and SOC operational procedures.
Mentor and guide junior analysts, foster a culture of continuous learning and operational excellence and ensure adherence to operational quality benchmarks and SLAs.
4+ years of experience in incident response, SOC Tier 2 or equivalent.
Strong understanding of adversary tradecraft (MITRE ATT&CK, Cyber Kill Chain, etc.).
Deep understanding of cloud security concepts.
Experience with EDRs, SIEMs, SOARs and log pipelines.
Solid grasp of Windows, Linux, and cloud security.
Familiarity with scripting languages for analysis.
In-depth understanding of network protocols, endpoint artifacts, memory, and log analysis.
Excellent problem-solving and analytical thinking.
Ability to work under pressure during incidents and with minimal supervision.
Strong documentation and communication skills, especially when dealing with stakeholders.
Collaborative, yet capable of deep focus and individual contribution.
Free · no signup
Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.
No spam. Just jobs and resources.
Why people use ASAI
Scored, not searched. Every role ranked against your actual profile.
Alerts as often as hourly. Reach new roles while the pile is still small.
Skill gaps, spelled out. See exactly which requirements you don't meet yet.
Verified jobs, only. Say no to ghost jobs. Your time deserves respect.
Keep browsing