Published Date
1 week ago
Work Arrangement
Remote • Remote — USA
Open Positions
4 openings
Experience Level
Entry / Mid-level
About the opportunity
Triage endpoint alerts, investigate indicators of compromise (IOCs), and hunt for adversary activity using Falcon telemetry.
Key Focus Areas:
• Triaging and investigating endpoint detection and response (EDR) alerts.
• Analyzing Windows Event logs, PowerShell traces, and network connections for anomalous behavior.
• Mapping attacks against MITRE ATT&CK techniques and writing detection rules.
• Incident response reporting, isolation protocols, and containment procedures.
What you will do
- check_circle Monitor and triage security alerts across cloud, identity, and endpoint sensors.
- check_circle Investigate suspicious process executions, PowerShell scripts, and network beacons.
- check_circle Map adversary tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework.
- check_circle Prepare actionable incident response reports and recommend containment actions.
What we are looking for
- arrow_circle_right Knowledge of operating system internals (Windows, Linux), networking fundamentals, and security protocols.
- arrow_circle_right Hands-on experience with SIEM, EDR (CrowdStrike Falcon, Sentinel, or Defender), and log analysis.
- arrow_circle_right Familiarity with basic scripting in Python or PowerShell for log parsing and workflow automation.
- arrow_circle_right Relevant industry certifications (Security+, CySA+, CEH, or BTL1) are an advantage.
Skills & Tech Stack
Why candidate applications stand out
Verified Technical Credentials
Applications include direct proof-of-work repositories and instructor verification endorsements.
Fast-Track Hiring Visibility
Direct internal referral channels through enterprise partners bypass automated resume discard filters.