CallTek

CallTek

CallTek provides Technology as a Service (TaaS) solutions, offering support services that empower technology operators and service providers to enhance their operations with comprehensive infrastructure, procurement, and lifecycle support tailored to v...

Internet Software & Services
51-250
Founded 2004

Description

  • Lead in-depth investigations of escalated cases from L1, including hypothesis-driven analysis, evidence validation, scoping, impact assessment, and timeline building.
  • Correlate telemetry across endpoint, Windows/Linux, Active Directory, firewall, proxy, DNS, IDS, and cloud logs when applicable.
  • Recommend and coordinate containment actions such as host isolation, credential resets, IOC blocks, and temporary control changes under change control and governance.
  • Determine incident severity and communicate findings clearly to technical stakeholders and executive audiences in English.
  • Identify detection gaps and improve detections by reducing false positives, closing false negatives, and proposing new rules and use cases.
  • Ensure evidence integrity and maintain proper documentation throughout investigations and handoffs.
  • Coordinate incident handoffs and collaboration with IR, IT Ops, Network, and Cloud teams.
  • Produce post-incident deliverables including probable root cause, lessons learned, and preventive actions.

Requirements

  • 2–5 years of experience in SOC, IR, Blue Team, or equivalent incident-handling work.
  • Solid networking fundamentals, including TCP/IP, DNS, HTTP/S, VPN, and NAT.
  • Experience with EDR investigations, including process trees, persistence, LOLBins behavior, and containment workflows.
  • Experience triaging Windows and Active Directory activity, including authentication patterns and suspicious logons.
  • Experience with Linux triage and analysis.
  • Experience analyzing network security controls and logs from firewall, IDS, proxy, and DNS tools.
  • Ability to produce defensible scoping and timelines based on evidence.
  • High documentation standards and the ability to perform under pressure.
  • Threat hunting experience and familiarity with MITRE ATT&CK mapping.
  • Exposure to detection engineering, including Sigma/YARA at a basic or intermediate level, use-case design, and SIEM correlation strategy.
  • Basic forensics knowledge, including acquisition concepts, triage artifacts, and memory/disk fundamentals.
  • Blue Team or incident response certifications such as GCIH, GCIA, BTL2, or SC-200 are preferred.
  • Strong spoken and written English at B2-High/C1 level, with the ability to lead technical calls and write incident summaries.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Technology Operations Support Analyst

Facet 251-1K Capital Markets

Facet is hiring an IT/Security Operations Analyst to support internal users, manage access and endpoint operations, and help secure the company’s systems in a fast-growing fintech environment.

Cybersecurity JIRA macOS Salesforce
16 hours, 48 minutes ago

Security Analyst, Bug Bounty

Stripe 5K-10K Diversified Financial Services

Stripe is hiring a Security Analyst for its Vulnerability Management team to triage bug bounty reports, coordinate remediation, and improve the effectiveness of its vulnerability response process.

AWS Burp Suite GCP Python Ruby
1 day, 15 hours ago

Associate, Vulnerability Assessment

Coalfire 251-1K Internet Software & Services

Coalfire is hiring a Vulnerability Assessment Associate to identify, analyze, and report security vulnerabilities across systems, networks, and applications while supporting remediation and risk reduction efforts for clients.

AWS Azure Bash Cybersecurity GCP HIPAA PowerShell Python SOC
1 day, 16 hours ago

Information Security Analyst

Media.Monks 5K-10K Media

Monks is hiring an Information Security Analyst to protect customer and company data and support the organization’s security and compliance posture across a global business.

AWS Azure Cybersecurity Encryption GCP Linux macOS OpenID Connect SAML
1 day, 16 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers