This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are looking for people with a passion for investigation and forensic analysis to join our MDR SOC team at Rapid7. As an Incident Handler II, you will work side by side MDR SOC analysts and MDR Incident Responders to investigate incidents ranging from commodity malware to sophisticated threat actors.
Job Responsibility
Conduct investigations into a variety of malicious activity on workstations, servers, and in the cloud
Investigate all levels of incidents, including Incident Response engagements in which you will provide analysis assistance to Rapid7's Incident Responders, including scoping, timeline analysis, finding IAV, and helping update documents as needed
Own complex investigations that may need various levels of delegation, customer communication, documentation, and collaboration across teams
Be an escalation point for complex and advanced incidents
Communicate with Cybersecurity Advisors regarding investigation findings, Requests For Information from clients, and remediation and mitigation recommendations
Directly communicate with customers regarding investigation findings or to assist in driving an investigation forward as needed
Prepare Incident Reports for each minor incident investigation you complete, which follow MITRE's ATT&CK Framework and include your own forensic, malware, and root-cause analysis
Communicate with other analysts to share new intelligence regarding tactics, techniques, and trends utilized by threat actors
Provide continuous input to Rapid7's Threat Intelligence and Detection Engineering team regarding new detection opportunities
Assist in customer engagement opportunities pertaining to the function of your role in the MDR service as necessary
Participate in projects that directly relate to your role in an effort to increase positive customer outcomes
Utilize Rapid7's world-class software to triage and investigate alerts to identify potential compromises in customer environments as necessary
Requirements
3-4 years of experience in a cybersecurity related position (SOC and/or SIEM analysis experience preferred)
Dedication to putting each customer's needs and concerns at the forefront of all decision making
Understanding of core operating system concepts in Windows, MacOS/Darwin, and Linux - this includes at least an understanding of common internal system tools and directory structures
Proficiency with analyzing forensic artifacts to determine root cause analysis in investigation - Windows largely preferred, but bonus points for experience with Linux, AWS, Azure, and GCP
A fundamental understanding of how threat actors utilize tactics such as lateral movement, privilege escalation, defense evasion, persistence, command and control, and exfiltration
Effective verbal communication skills that foster collaboration between the MDR SOC and the Incident Response team
Strong written communication skills
Some experience with static and dynamic malware analysis
Passion for continuous learning and growth in the cybersecurity world