Incident Response Analyst:
Indexed description
As an Incident Response Analyst, you will:
- Investigate and respond to workspace security incidents across email, browser security and perimeter security domains.
- Handle investigation requests submitted by customers
- Perform targeted phishing analysis and investigation of new attack campaigns
- Conduct threat hunting based on attack patterns, behaviors, and indicators
- Build and improve detections based on new attack types, tactics, companies and trends
- Collaborate with development and research teams to provide incident-driven insights, and develop new detection engines for identifying previously unknown attacks
- Write professional blog posts based on incident investigations and attack trends, contributing to the company’s research-driven content and public visibility
- Work in rotating shifts as part of a 24/7 operation (including nights, weekends, and holidays)
- At least 3 years of experience in an Incident Response or Security Operation roles
- Strong understanding of attack vectors, including Phishing, BEC, Email spoofing and impersonation techniques, Malware, ATO and more
- Knowledge of email protocols and security concepts: SMTP, SPF/DKIM/DMARC, headers, authentication methods
- Strong querying skills using SQL, SPL, KQL or AQL
- Good knowledge with Static & Dynamic techniques
- Familiarity with and understanding of code and scripting languages such as Python, JavaScript, Visual Basic, or similar - with the ability to read, interpret, and analyze potentially malicious scripts
- Excellent written and verbal communication in English
- Team player with a proactive, ownership-driven approach
We will only notify shortlisted candidates.
Fortinet will not entertain any unsolicited resumes, please refrain from sending them to any Fortinet employees or Fortinet email aliases. Should any Agency submit any resumes to Fortinet, these resumes if considered, will be assumed to have been given by the Agency free of any related fees/charges.
Hybrid
Responsibilities
- Investigate and respond to workspace security incidents across email, browser security and perimeter security domains.
- Handle investigation requests submitted by customers
- Perform targeted phishing analysis and investigation of new attack campaigns
- Conduct threat hunting based on attack patterns, behaviors, and indicators
- Build and improve detections based on new attack types, tactics, companies and trends
- Collaborate with development and research teams to provide incident-driven insights, and develop new detection engines for identifying previously unknown attacks
- Write professional blog posts based on incident investigations and attack trends, contributing to the company’s research-driven content and public visibility
- Work in rotating shifts as part of a 24/7 operation (including nights, weekends, and holidays)
- At least 3 years of experience in an Incident Response or Security Operation roles
- Strong understanding of attack vectors, including Phishing, BEC, Email spoofing and impersonation techniques, Malware, ATO and more
- Knowledge of email protocols and security concepts: SMTP, SPF/DKIM/DMARC, headers, authentication methods
- Strong querying skills using SQL, SPL, KQL or AQL
- Good knowledge with Static & Dynamic techniques
- Familiarity with and understanding of code and scripting languages such as Python, JavaScript, Visual Basic, or similar - with the ability to read, interpret, and analyze potentially malicious scripts
- Excellent written and verbal communication in English
- Team player with a proactive, ownership-driven approach
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search