Senior Detection & Response Analyst

1 hour, 22 minutes ago
Full-time
Senior
Cybersecurity
Toyota Tsusho Systems

Toyota Tsusho Systems

Toyota Tsusho Systems (TTS) is the global ICT company of the Toyota Tsusho Group, offering innovative IT solutions to drive business growth and create new ventures. As a member of the Toyota Group, TTS specializes in cybersecurity, digital transformati...

IT Services
51-250
Founded 2011

Description

  • Serve as the point of escalation for security incidents and provide expert feedback on monitoring improvements.
  • Act as shift lead as needed and guide Incident Detection team members through prioritizing, identifying, analyzing, and remediating threats.
  • Ensure daily work completed by ID Analysts meets quality and timeline expectations.
  • Triage security incidents and perform in-depth analysis using threat intelligence, intrusion detection systems, firewalls, and other boundary protection tools.
  • Maintain awareness of the broader threat landscape, including malware, botnets, phishing, DDoS, and physical threats.
  • Provide 24x7 coverage for RSOC services and participate in an on-call rotation.
  • Support Agentic SOC development by providing tuning feedback and feature requests to engineering.
  • Train and mentor team members within the Incident Detection Team.
  • Assist with containment and remediation during incidents and track cases in the internal ticketing system.
  • Support Incident Response efforts by working with IR teams, stakeholders, and customers to drive remediation.
  • Conduct threat hunting based on internal and external threat intelligence.
  • Create and update daily and monthly reports and contribute to process documentation and playbooks.

Requirements

  • 4+ years of experience in Security Operations monitoring.
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (preferred).
  • Experience with Security Operations processes, procedures, and services.
  • Experience with security tools such as Sentinel, Splunk, ATP, Symantec Endpoint, TrendMicro Antivirus, McAfee Web Gateway, Checkpoint Firewalls, Bluecoat, Sourcefire, and Active Directory.
  • Advanced knowledge of network monitoring and network exploitation techniques.
  • Strong technical background across security, network, infrastructure, cloud, and applications.
  • Knowledge of risk assessment tools, technologies, and methods.
  • Experience with common attack vectors, including advanced adversaries.
  • Knowledge of common web application attacks such as SQL injection, cross-site scripting, invalid inputs, and forceful browsing.
  • Knowledge of network-level protocols and applications such as DNS, HTTP, and SMB.
  • Technical certifications such as GCIA, GCFA, GCIH, or CASP are a plus.
  • Tines or other automation experience is highly valued.
  • Proficient with Microsoft Office and documentation tools, including Word, Excel, and PowerPoint.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Screening Analyst

Qonto 1K-5K Banks

Qonto is hiring a Screening Analyst to support its Financial Crime team in protecting customers and ensuring compliant operations across European markets.

Swift
53 minutes ago

Detection and Response Engineer

Coalfire 251-1K Internet Software & Services

Coalfire is hiring a Detection and Response Engineer to support client SIEM monitoring, threat hunting, and purple team activities within its Defensive Services team.

Ansible AWS Azure Cybersecurity GCP GitHub GitLab HIPAA SIEM Splunk Terraform
1 hour, 38 minutes ago

Risk Investigator - Third Party/ATO Fraud

Mercury 251-1K Banks

Mercury is hiring a Fraud Investigator to lead account takeover investigations within its Account Fraud team, coordinating response and recovery for high-risk customer security incidents.

1 hour, 53 minutes ago

SOC Analyst

ClearCapital.com, 1-10 Real Estate

Clear Capital is hiring a SOC Analyst to protect its on-premises and cloud environments through security monitoring, incident response, threat hunting, and vulnerability advisory work.

Active Directory DNS Linux macOS OAuth SAML SIEM
2 hours, 8 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers