Cybersecurity Incident Handler
About the role
We are seeking a highly skilled and motivated Cybersecurity Incident Handler with a specialized focus on Incident Coordination, Analysis, Threat Containment, and Response. In this critical role, you will be the cornerstone for actively monitoring, detecting, and responding to security events that threaten our enterprise.
Responsibilities
Your Core Responsibilities Will Include:
- Advanced Incident Handling & Response: Serve as the primary driver for investigating escalated security incidents.
- Incident-Driven Splunk Querying & Correlation: Utilize Splunk as an investigative powerhouse during active incidents.
- Hybrid Environment Incident Investigation: Investigate security events and anomalous behaviors across a complex, hybrid infrastructure.
- Network Artifact & Traffic Analysis: Apply a strong understanding of network security principles and core networking protocols to analyze network packet captures, firewall logs, and security appliance detections during incident investigations.
- Endpoint & Email Threat Remediation: Review endpoint telemetry from Endpoint Detection and Response (EDR) solutions and analyze email security logs to contain and remediate active threats.
- Playbook Execution & Containment Actions: Execute established incident response playbooks to contain active threats, limit damage, and coordinate remediation efforts.
Requirements
The minimum education and experience for the lowest career level in the job posting range are:
- Bachelor's degree in engineering/science/information technology discipline.
- OR Master's degree in engineering/science/information technology discipline.
- OR Applicants without a bachelor's degree may be considered based on a combination of at least 8 years of completed education and/or relevant experience.
Qualifications
Who You Are:
- An End-to-End Incident Handler: You don't just close isolated alerts; you have lived through the entire lifecycle of real-world attacks.
- A Dedicated Incident Investigator: You excel at digging into logs, connecting disparate data points, and identifying the root cause of complex security incidents.
- A Collaborative Security Partner: You’re a strong team contributor who enjoys collaborating with security engineering, systems administration, and desktop support teams to resolve active incidents.
- A Proactive Problem Solver: You possess an exceptional ability to anticipate potential security challenges within systems and networks, actively identifying logging gaps and suggesting detection rule optimizations.
- An Efficient Communicator: You can clearly document incident timelines and explain technical security events to both technical peers and non-technical stakeholders.
Skills
Preferred Skills And Expertise:
- Proven experience tracking and investigating security incidents through the entire attack lifecycle.
- Hands-on experience writing queries and analyzing data in Splunk (or other major enterprise SIEM platforms) to investigate incident-related data.
- Demonstrated experience triaging, investigating, and containment-handling of escalated cybersecurity incidents.
- Solid understanding of network security principles, including networking protocols, firewall concepts, and network traffic flow.
- Familiarity with both Windows and Linux operating systems, including system event logs, registry structures, and basic command-line navigation.
Benefits
At Pantex, we believe that extraordinary talent thrives when supported by a balanced life. Discover the flexibility that empowers you to excel, coupled with a benefits package designed for your total peace of mind from comprehensive health coverage and robust retirement planning, to opportunities for continuous learning through education reimbursement.