Published Date
3 weeks ago
Work Arrangement
Hybrid • Raleigh, NC
Open Positions
3 openings
Experience Level
Senior
About the opportunity
Direct 24/7 global threat detection, SIEM correlation tuning, and incident triage for Cisco Talos telemetry.
What you will do
- check_circle Investigate Tier 3 escalations involving zero-day exploits, living-off-the-land techniques, and lateral movement.
- check_circle Author and optimize detection rules in Splunk, Elastic, and Cisco SecureX using Sigma and YARA rules.
- check_circle Automate repetitive Tier 1/2 response workflows with Python and modern SOAR solutions.
- check_circle Conduct threat hunting exercises across network telemetry and firewall flow logs.
What we are looking for
- arrow_circle_right 4+ years working in a 24/7 Security Operations Center (SOC) with at least 1 year in a Tier 3 or lead capacity.
- arrow_circle_right Certifications: CySA+, GCIH, GCIA, or CISSP.
- arrow_circle_right Proficiency with SIEM platforms, network protocol analysis (Wireshark, Zeek), and EDR administration.
Skills & Tech Stack
Why candidate applications stand out
Verified Technical Credentials
Applications include direct proof-of-work repositories and instructor verification endorsements.
Fast-Track Hiring Visibility
Direct internal referral channels through enterprise partners bypass automated resume discard filters.