- Company Name
- GAC Solutions
- Job Title
- Incident Response Specialist
- Job Description
-
**Job Title**
Incident Response Specialist
**Role Summary**
Lead advanced threat detection, investigation, and containment activities for enterprise and cloud environments. Manage SIEM/SOAR operations, conduct threat hunting, execute full‑cycle incident response, develop SOC playbooks, and provide forensic analysis to identify root causes and improve security posture.
**Expectations**
- Mastery of SIEM, EDR/XDR, incident‑handling frameworks, and threat‑intelligence integration.
- In‑depth knowledge of malware behaviors, attack techniques, and MITRE ATT&CK.
- Ability to operate under FedRAMP requirements and support secure Azure/M365 environments.
- Proven track record of producing clear, actionable post‑incident reports and recommending remediation actions.
**Key Responsibilities**
- Monitor SIEM/SOAR dashboards, triage and respond to security alerts.
- Conduct containment, eradication, and recovery for compromised assets.
- Perform forensic analysis of endpoints, logs, and network traffic to uncover root causes.
- Develop, maintain, and automate SOC playbooks and detection rules.
- Lead proactive threat hunting across endpoints, networks, and cloud services.
- Collaborate with engineering, cloud, and IT teams to remediate vulnerabilities.
- Document incident details and create post‑incident reports for stakeholders.
- Ensure compliance with FedRAMP and assist with secure cloud operations (Azure Defender, M365 Defender).
**Required Skills**
- SIEM expertise (Microsoft Sentinel, Splunk).
- SOAR and EDR/XDR proficiency.
- Digital forensics and log analysis.
- Threat hunting, incident‑response workflow design, and automation.
- Cloud security operations (Azure Defender, M365 Defender, identity investigations).
- Strong understanding of malware and attack techniques, MITRE ATT&CK mapping.
- Excellent communication for reporting and cross‑team collaboration.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Preferred certifications: GCIA, GCFA, GCIH, AZ‑500, SC‑200, CISSP.