Senior Cyber Defender
Job description
About the role
As a , you will play a pivotal role in safeguarding our clients' digital assets and ensuring their cybersecurity posture remains robust against evolving threats. This position requires a deep understanding of cybersecurity principles, hands-on experience in threat detection and response, and the ability to collaborate effectively with cross-functional teams. You will be at the forefront of our security operations, leveraging your expertise to identify vulnerabilities and implement strategies that enhance our security framework.
Key facts
What you'll do
- Lead and manage the Security Operations Center (SOC) team, ensuring timely detection, analysis, and response to security incidents.
- Develop and implement incident response plans, ensuring that all team members are trained and prepared for potential security breaches.
- Conduct thorough investigations of security incidents, utilizing forensic tools and methodologies to determine the root cause and impact.
- Collaborate with IT and development teams to integrate security best practices into system design and deployment processes.
- Monitor security alerts and events from various sources, including SIEM tools, firewalls, and intrusion detection systems, to identify potential threats.
- Perform vulnerability assessments and penetration testing to identify weaknesses in systems and applications, providing actionable recommendations for remediation.
- Stay updated on the latest cybersecurity trends, threats, and technologies, sharing insights with the team to enhance overall security posture.
- Prepare and present detailed reports on security incidents, trends, and recommendations to senior management and stakeholders.
- Mentor and train junior SOC analysts, fostering a culture of continuous learning and improvement within the team.
- Participate in the development and maintenance of security policies, standards, and procedures to ensure compliance with industry regulations and best practices.
- Engage in threat hunting activities to proactively identify and mitigate potential security risks before they can be exploited.
- Collaborate with external partners and vendors to enhance security capabilities and share threat intelligence.
Requirements
- Minimum of 5 years of experience in cybersecurity, with a focus on incident response and threat detection.
- Strong knowledge of security frameworks such as NIST, ISO 27001, and CIS Controls.
- Proficiency in using security tools such as SIEM, IDS/IPS, firewalls, and endpoint protection solutions.
- Experience with scripting languages (e.g., Python, PowerShell) for automation and analysis tasks.
- Familiarity with cloud security principles and technologies, particularly in AWS or Azure environments.
- Excellent analytical and problem-solving skills, with the ability to think critically under pressure.
- Strong communication skills, both written and verbal, to effectively convey complex security concepts to non-technical stakeholders.
- Relevant certifications such as CISSP, CISM, CEH, or similar are highly desirable.
- Experience working in a SOC environment is a plus.
Nice to have
- Knowledge of compliance standards such as GDPR, HIPAA, or PCI-DSS.
- Familiarity with threat intelligence platforms and frameworks (e.g., MITRE ATT&CK).
- Experience with security automation and orchestration tools.
- Understanding of malware analysis and reverse engineering techniques.
- Previous experience in a leadership role within a cybersecurity team.
Skills & tools
- Security Information and Event Management (SIEM) tools
- Intrusion Detection and Prevention Systems (IDPS)
- Endpoint Detection and Response (EDR) solutions
- Vulnerability assessment tools
- Forensic analysis software
- Cloud security tools and practices
- Scripting and automation (Python, PowerShell)
Practical notes
- The position is fully remote, allowing for flexibility in work hours and location.
- Candidates must be eligible to work in the United States, with visa sponsorship available for qualified individuals.
- The company promotes a culture of continuous learning, offering opportunities for professional development and training.
- Ontinue values diversity and inclusion, encouraging applicants from all backgrounds to apply.
If you are passionate about cybersecurity and are looking to take your career to the next level with a dynamic and innovative team, we encourage you to apply for the Senior Cyber Defender position at Ontinue. Join us in our mission to protect organizations from cyber threats and make a meaningful impact in the cybersecurity landscape.