Related skills
aws gcp siem edr iam๐ Description
- Lead L2 escalations and Sev2+ incidents; act as technical escalation point
- Hands-on hunting in SIEM; pull host artifacts via EDR; trace IAM in cloud logs
- Forensic timelines with chain-of-custody; collaborate across teams
- Containment decisions: endpoint isolation, token revocation, network blocks
- Lead cloud IR across AWS and GCP; IAM & CSPM context
- Threat hunting and detection contribution; improve detections
๐ฏ Requirements
- 6+ years hands-on incident response; at least 3 years at senior or staff level
- Expert EDR proficiency (CrowdStrike Falcon, SentinelOne); remote triage and rule authorship
- Deep AWS IR: CloudTrail forensics, IAM chain analysis, EC2/Lambda investigations
- Strong Windows forensics: Prefetch, MFT, Shimcache, event logs, registry hives
- Hands-on SIEM experience (Google Chronicle, Splunk, Microsoft Sentinel)
- MITRE ATT&CK fluency and IdP forensics (Okta, Entra ID)
Meet JobCopilot: Your Personal AI Job Hunter
Automatically Apply to Engineering Jobs. Just set your
preferences and Job Copilot will do the rest โ finding, filtering, and applying while you focus on what matters.
Help us maintain the quality of jobs posted on Empllo!
Is this position not a remote job?
Let us know!