This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Conduct end-to-end investigations into malicious activity on workstations, servers, and cloud environments, including scoping, timeline analysis, root-cause identification, and documentation in support of Rapid7’s Incident Response team
Own complex investigations that require delegation, cross-team collaboration, and direct customer communication, serving as the escalation point for advanced and high-severity incidents
Partner with Cybersecurity Advisors to communicate investigation findings, respond to client Requests for Information, and deliver clear remediation and mitigation recommendations
Prepare detailed Incident Reports mapped to MITRE ATT&CK, incorporating forensic, malware, and root-cause analysis for every investigation you complete
Share threat intelligence with peers and contribute new detection opportunities to Rapid7’s Threat Intelligence and Detection Engineering teams to continuously strengthen our collective defenses
Participate in customer engagement opportunities and team projects that drive positive outcomes for the MDR service and the customers we protect
Triage alerts using Rapid7’s InsightIDR SIEM, identify potential compromises, and escalate findings to customers as needed
Requirements
A customer-first mindset
Strong written and verbal communication skills
A passion for continuous learning and growth in the cybersecurity field
Accountability for your work and investigations
3-4 years of experience in a cybersecurity-related role, with SOC and/or SIEM analysis experience preferred
Proficiency with analyzing forensic artifacts to determine root cause across Windows environments
Understanding of core operating system concepts across Windows, macOS/Darwin, and Linux
A solid grasp of how threat actors operate
Experience with static and/or dynamic malware analysis
Familiarity with MITRE ATT&CK Framework and its application to investigation reporting and threat analysis