Senior Cybersecurity Specialist
What you'll need to apply
What this employer's standard application typically asks
About this role
Employer-provided description, formatted for easier reading.
Join our Cyber Defense Center as a Senior Security Operations Specialist and become part of a global team dedicated to safeguarding our organization's people, systems, and data.
As a member of our Security Operations Center (SOC) , you will lead the investigation and response to complex cyber threats, drive continuous improvement of detection and response capabilities, and act as a senior escalation point for the SOC team.
Using advanced security technologies, threat intelligence, and proactive threat hunting techniques, you will play a key role in protecting our global environment against sophisticated adversaries.
Responsibilities
- Investigate, validate, and respond to complex security incidents escalated by CrowdStrike Falcon Complete MDR Service, SOC analysts, users, and other IT departments.
- Lead investigations of advanced security incidents using CrowdStrike Falcon, Microsoft Defender, SIEM platforms, and other security technologies.
- Analyze alerts, suspicious activity, attack patterns, and threat actor behavior using endpoint telemetry, threat intelligence, cloud telemetry, and SIEM data.
- Perform advanced root cause analysis , determine attack scope and impact, and provide detailed findings and recommendations.
- Lead containment, eradication, and recovery activities for major security incidents.
- Conduct proactive threat hunting activities and initiate investigations based on intelligence, emerging threats, and hypothesis-driven analysis.
- Coordinate with Incident Response, Infrastructure, Cloud, Identity, and Business teams during major cyber incidents.
- Produce high-quality incident reports, executive summaries, lessons learned, and technical documentation.
- Collaborate with the Global SOC team and cybersecurity stakeholders to strengthen operational effectiveness and security monitoring maturity.
- Lead the development, optimization, and maintenance of incident response playbooks, use cases, and operating procedures.
- Stay up to date with emerging cybersecurity threats, attack techniques, adversary tradecraft, and security technologies.
- Develop and tune detection rules , analytics, and correlation logic to improve SOC visibility and effectiveness.
- Perform advanced threat modeling and map detections to the MITRE ATT&CK framework.
- Mentor junior and mid-level SOC analysts and provide technical guidance during investigations.
- Act as a senior escalation point for high-severity incidents and provide incident leadership during major cyber events.
- Identify security gaps , recommend strategic improvements, and drive implementation of detection and response enhancements.
- Support purple-team exercises, tabletop exercises, and adversary emulation activities to validate security controls.
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field.
- 5+ years of experience in Security Operations, Incident Response, Threat Hunting, or a related cybersecurity role.
- Proven experience investigating and managing complex cyber incidents in enterprise environments.
- Strong hands-on experience security monitoring operations, incident investigation, and enterprise detection technologies.
- Strong understanding of attack frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
- Strong understanding of security frameworks and standards such as NIST, ISO 27001, CIS Controls, and incident response best practices.
- Advanced knowledge of Windows operating systems, Active Directory, Entra ID , networking, and enterprise security architectures.
- Extensive experience with CrowdStrike , Microsoft Defender , SIEM planforms, EDR/XDR solutions and cloud security technologies.
- Experience developing detection logic, threat hunting hypotheses, and security monitoring use cases.
- Experience performing malware triage, attack chain analysis, and forensic investigations.
- Understanding of cloud security concepts across Microsoft Azure , AWS and Microsoft 365 environments.
- Experience with scripting or automation using PowerShell, Python, KQL, or similar technologies.
- CrowdStrike certifications such as CCFA, CCFR, or CCFH are considered an advantage.
- Advanced cybersecurity certifications such as GCIA, GCIH, GCFA, GCFE, CISSP, SC-200, or equivalent are considered an advantage.
- Strong analytical and problem-solving skills.
- Strong communication and collaboration skills.
- Ability to work independently and as part of an international team.
- Demonstrated ability to lead technical investigations and drive cross-functional collaboration during major security incidents.
- Passion for cybersecurity and a willingness to continuously learn and develop new skills.
- Fluent in English.
Ready to drive with Continental? Take the first step and fill in the online application.