Cyber Security Services Incident Response Analyst
Indexed description
As a CSS IR Analyst, you will manage security incidents, develop incident response processes, and enhance security configurations tailored to client needs. Your expertise will be crucial in reducing false positives and identifying security gaps within the client's IT infrastructure.
Work Schedule: Two rotating 8.5-hour shifts within the 8:00 a.m.-8:00 p.m. EET coverage window.
Job responsibilities:
- Own assigned security alerts, incidents, and escalated tickets by conducting triage, cross-source investigations, and response activities across endpoints, identities, email, networks, cloud environments, and other relevant data sources using available security telemetry and investigation platforms.
- Analyze endpoint activity to identify indicators of compromise and adversary behaviors, including malicious execution, persistence, privilege escalation, and lateral movement.
- Investigate suspicious user and identity activity by analyzing Microsoft Entra ID authentication logs, sign-in activity, access patterns, anomalies, and other identity-related telemetry.
- Use SentinelOne Singularity Data Lake and SDL PowerQuery to perform advanced searches, correlate events, analyze threats, and support security investigations.
- Develop and validate investigation hypotheses using structured incident response, threat hunting, and forensic analysis methodologies.
- Execute containment, eradication, and recovery activities while coordinating with relevant technology owners and stakeholders to validate findings, contain threats, and restore affected services in accordance with approved incident response procedures and playbooks.
- Document investigative actions, evidence, analysis, decisions, communications, containment measures, and recovery activities throughout the incident lifecycle.
- Prepare detailed P1 and P2 incident reports covering the incident timeline, root cause, impact assessment, actions taken, current status, and lessons learned.
- Provide metrics and analysis on mean time to acknowledge, investigate, and resolve incidents by severity and lifecycle stage.
- Provide feedback on detection logic, alert quality, false positives, telemetry gaps, and monitoring improvement, recommending rule-tuning adjustments and new detection use cases based on emerging threats, vulnerabilities, observed activity, and attack patterns.
- Produce weekly operational reports on alert volumes and status, operational trends, investigation outcomes, false-positive rates by detection source.
- Participate in security operations meetings and present incident findings, operational trends, detection performance, service-level results, and improvement recommendations.
- Identify security gaps, recommend mitigation measures, and support SOAR automation workflows by providing operational feedback and identifying suitable automation opportunities to enhance operational efficiency.
- Contribute to the development, maintenance, and refinement of standard operating procedures, incident response playbooks, investigation guides, workflows, and process documentation.
- Support monthly security tool and log-source health checks by validating data availability, alert coverage, and investigation readiness.
- Collaborate with security analysts, incident responders, threat hunters, technology owners, and stakeholders across multiple teams and time zones to implement security best practices.
- Provide technical guidance, coaching, and mentoring to junior analysts, fostering a collaborative and learning-focused environment.
Education:
- Preferred: Bachelor's degree in computer science, Information Technology, Engineering, or a related field.
- Minimum education requirement: High school studies completed with Baccalaureate diploma.
- Excellent English communication skills, both verbal and written, for professional communication and documentation.
- Minimum 3 years of experience in cybersecurity operations, including hands-on experience investigating and responding to security incidents across endpoints, network, cloud, and other technology environments.
- Demonstrated experience working in a Security Operations Center, Global Security Operations Center, Managed Security Service, or similar 24/7 operational environment.
- Strong understanding of cybersecurity principles, incident response methodologies, structured threat hunting and basic digital forensics.
- Strong knowledge of industry frameworks and best practices, including NIST incident response guidance and structured threat hunting methodologies.
- Hands-on proficiency with SentinelOne Singularity Data Lake (SDL), including PowerQuery for investigation, event correlation, and threat analysis.
- Proficiency with Microsoft Entra ID and security technologies such as SIEM, SEG, EDR, XDR, and NDR.
- Familiarity with SOAR platforms and security automation concepts.
- Ability to develop a nd maintain standard operating procedures, incident response playbooks, workflows, and technical documentation.
- Hands-on certifications in incident response, forensics, threat hunting, or malware analysis - for example GCIH, GCFA, GCDA, GREM, ECIH, CySA+, eCTHP, CDSA, or OSCP. Equivalent practical evidence (published research, open-source detection contributions) is weighted equally.
- Ability to perform effectively during crises, make sound decisions, recommend effective solutions, and manage competing priorities during security incidents.
- Ability to work effectively in a complex global environment involving multiple entities, varying levels of IT maturity, and diverse regulatory requirements.
- Strong communication and collaboration skills, enabling effective interaction with a diverse range of technical and non-technical stakeholders and internal teams.
- A customer-focused mindset dedicated to delivering exceptional service.
- A collaborative mindset with an interest in internal operations and process improvement.
- Strong organizational, attention to detail, analytical thinking and a proactive approach to problem-solving.
- Ability to quickly adapt to changes, new requirements, or sudden shifts in direction.
- A commitment to continuous learning and improvement, staying abreast of industry best practices, emerging technologies, and methodologies.
- Absolute discretion and integrity in handling sensitive customer information and critical infrastructure data.
- Availability for on-call responsibilities, if required.
The preceding job description had been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties and responsibilities required of employees assigned to this job.
Diversity & Inclusion
Here at the Stefanini Group, we value plurality and equity, regardless of race, sexual orientation, disability, age, ancestry, religion, gender, and nationality. We understand and encourage the importance of being you!
About Us
We are the Stefanini group, a global tech consulting company of Brazilian origin that believes in the power of people to transform businesses through technology.
We are present in over 40 countries and operate with the purpose of co-creating solutions TOGETHER WITH OUR CLIENTS that accelerate results and improve the experience of people and organizations.
Here, we like to say that technology is not the end, but the means: what really matters are the people who drive it all.
Our mindset is AI First, meaning we invest in cutting-edge technology in everything we do, focusing on results for our clients.
We are a company, A GROUP, that breathes collaboration and offers a dynamic environment where you will learn by doing, grow alongside the team, and have space to contribute with ideas and projects.
More than just talking about digital transformation, we believe in real transformation that starts with people and impacts real businesses.
If you are looking for a place to develop, innovate, and be part of something bigger, the Stefanini Group is your place.
We want to inform you that there are currently scams targeting job seekers by falsely using our company's name, Stefanini. We sincerely apologize for any confusion or inconvenience this may have caused.
Please remember that legitimate job offers from Stefanini will always come through official channels, including direct communication with our trained recruiters. If you receive any unsolicited messages requesting payment or personal information, please disregard them.
If you suspect you've been targeted, please contact us immediately at [email protected] for verification.
Key Points to Remember:
- Legitimate job offers only follow interviews conducted with our hiring managers or clients.
- We will never ask for payment at any stage of the recruitment process.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search