Qualifications
Key Responsibilities
Detection & Triage:
Monitor alerts from tools such as SIEM, EDR, IAM, CSPM, CDR, etc.
Execute initial triage, enrichment, and correlation across multiple data sources.
Identify false positives and collaborate with detection engineering to refine rules.
Incident Response:
Lead the containment, eradication, and recovery efforts for incidents involving endpoints, cloud, and identity.
Document and communicate incidents through SOAR/Jira/ServiceNow workflows.
Conduct root cause analysis and recommend long-term preventive measures.
Threat Hunting & Analysis:
Proactively hunt for threats using hypotheses aligned with MITRE ATT&CK framework.
Investigate anomalies across telemetry sources such as CloudTrail, Okta, and GitHub.
Work in conjunction with threat intelligence to identify emerging tactics, techniques, and procedures (TTPs).
Automation & Process Improvement:
Develop and enhance playbooks using SOAR (Torq or equivalent).
Create custom enrichment scripts and automation tools (Python, Bash, etc.).
Propose new detection logic and operational enhancements.
Reporting & Metrics:
Track and report on operational metrics such as MTTD, MTTR, and incident classifications.
About the job
About the Role
Join Abnormal Security as a proactive Senior Cyber Defense Analyst in a dynamic, engineering-focused environment. In this role, you will play a crucial part in safeguarding our hybrid ecosystem by diligently monitoring, investigating, and responding to security alerts across various platforms including cloud, endpoint, identity, and application layers. Collaborate closely with detection engineers, cloud security, and IT teams to mitigate real-time threats effectively.
This position is far from a standard 'click-through-the-console' SOC role. We seek an individual who demonstrates critical thinking, relentless automation, and end-to-end incident ownership.
About Abnormal Security
Abnormal Security is at the forefront of cybersecurity, dedicated to protecting organizations from advanced threats through innovative technology and expert insights. We foster a collaborative and fast-paced work culture that empowers our team to make a significant impact.