Senior Detection & Response Analyst

1 month ago
Full-time
Senior
Cybersecurity
Toyota Tsusho Systems

Toyota Tsusho Systems

Toyota Tsusho Systems (TTS) is the global ICT company of the Toyota Tsusho Group, offering innovative IT solutions to drive business growth and create new ventures. As a member of the Toyota Group, TTS specializes in cybersecurity, digital transformati...

IT Services
51-250
Founded 2011

Description

  • Serve as the point of escalation for security incidents and provide expert feedback on monitoring improvements.
  • Act as shift lead as needed and guide Incident Detection team members through prioritizing, identifying, analyzing, and remediating threats.
  • Ensure daily work completed by ID Analysts meets quality and timeline expectations.
  • Triage security incidents and perform in-depth analysis using threat intelligence, intrusion detection systems, firewalls, and other boundary protection tools.
  • Maintain awareness of the broader threat landscape, including malware, botnets, phishing, DDoS, and physical threats.
  • Provide 24x7 coverage for RSOC services and participate in an on-call rotation.
  • Support Agentic SOC development by providing tuning feedback and feature requests to engineering.
  • Train and mentor team members within the Incident Detection Team.
  • Assist with containment and remediation during incidents and track cases in the internal ticketing system.
  • Support Incident Response efforts by working with IR teams, stakeholders, and customers to drive remediation.
  • Conduct threat hunting based on internal and external threat intelligence.
  • Create and update daily and monthly reports and contribute to process documentation and playbooks.

Requirements

  • 4+ years of experience in Security Operations monitoring.
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (preferred).
  • Experience with Security Operations processes, procedures, and services.
  • Experience with security tools such as Sentinel, Splunk, ATP, Symantec Endpoint, TrendMicro Antivirus, McAfee Web Gateway, Checkpoint Firewalls, Bluecoat, Sourcefire, and Active Directory.
  • Advanced knowledge of network monitoring and network exploitation techniques.
  • Strong technical background across security, network, infrastructure, cloud, and applications.
  • Knowledge of risk assessment tools, technologies, and methods.
  • Experience with common attack vectors, including advanced adversaries.
  • Knowledge of common web application attacks such as SQL injection, cross-site scripting, invalid inputs, and forceful browsing.
  • Knowledge of network-level protocols and applications such as DNS, HTTP, and SMB.
  • Technical certifications such as GCIA, GCFA, GCIH, or CASP are a plus.
  • Tines or other automation experience is highly valued.
  • Proficient with Microsoft Office and documentation tools, including Word, Excel, and PowerPoint.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Threat Researcher

GreyNoise 51-250 Internet Software & Services

GreyNoise Intelligence is hiring a Threat Researcher to investigate emerging cyber threats and produce actionable intelligence that helps security practitioners detect, disrupt, and impose costs on adversaries.

Embedded Systems SQL
1 day, 8 hours ago

Associate Principal Cyber Threat Intelligence Analyst

Dragos 251-1K Professional Services

Dragos is hiring an OT Cyber Threat Intelligence Analyst to support a Singapore government security team with threat hunting, intelligence analysis, and incident response for critical infrastructure environments.

LLM SIEM
2 days, 9 hours ago

Security Operations Analyst II

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Security Operations Analyst II to join its fully remote Security Operations team in Canada and help triage alerts, investigate incidents, and improve detection coverage.

AWS DNS GCP SIEM TCP/IP TLS
3 days, 9 hours ago

CyberSecurity Specialist

Avertium 251-1K IT Services

Avertium is hiring a Cyber Security Specialist to support 24x7 SOC monitoring and incident response for mid-market and enterprise clients.

Cybersecurity DNS Encryption HIPAA HTTP SIEM TCP/IP
3 days, 9 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers