Investigate and analyze security alerts and incidents across endpoint, network, cloud, and identity environments.
Conduct proactive threat hunting, malware analysis, and deobfuscation of suspicious scripts.
Collaborate with senior analysts, document findings, and provide remediation recommendations.
The company operates a global Managed Detection and Response environment, protecting organizations from cyber threats. It has a remote-first culture with a collaborative team and opportunities for professional growth.
Analyze and respond to advanced threats ranging from commodity phishing to zero-day exploits.
Monitor and triage alerts from network security monitoring, EDR platforms, and other log sources.
Create detailed incident reports and collaborate with threat intelligence and incident response teams.
Volexity is a cybersecurity company specializing in threat intelligence and incident response. They have a growing, industry-leading security operations team and value diversity and equal opportunity.
Perform investigations into detected threats using EDR, Network, and Identity telemetry to analyze, contain, and remediate threats in customer environments
Identify, scope, and manage ongoing customer incidents, developing remediation plans and providing thorough reports
Collaborate with Detection Engineering, Intelligence, Research, and Product Management teams to develop new approaches to threat remediation
Zscaler provides a cloud-native Zero Trust Exchange platform that secures users, devices, and applications from cyberattacks and data loss. They foster a culture of transparency, collaboration, and customer obsession with a focus on impact and accountability.
Monitor and triage security alerts from SIEM, EDR, and other sources to identify threats.
Perform initial investigations to validate alerts, assess severity, and determine root cause.
Document findings and communicate with clients and internal teams for effective incident response.
Netrix Global provides holistic IT solutions to help businesses run and scale securely. The company is a top system integrator ranked in the CRN VAR500, with a culture focused on ownership, collaboration, and respect.
Identify innovative ways to detect Windows OS threats and develop cross-platform features leveraging telemetry from OS subsystems.
Collaborate with Product, Engineering, and Security teams to implement detection logic and address gaps in product coverage.
Apply AI to improve research quality and speed, and mentor team members to advance technical expertise.
Huntress is a cybersecurity company founded by former NSA operators that provides enterprise-grade cybersecurity to businesses of all sizes. They are a remote-first team securing over 5 million endpoints and 11 million identities, with a culture focused on collaboration and making a meaningful impact.
Monitor and respond to security alerts from SIEM, EDR/XDR, IDS/IPS, and other platforms.
Perform incident response, threat hunting, and log analysis to identify vulnerabilities and improve security controls.
Provide practical security guidance and participate in initiatives to ensure compliance with industry standards.
The company provides enterprise information security services for the real estate industry. They value integrity, kindness, and grit, and emphasize long tenure and career development.
Lead and mentor a remote team of SOC analysts while driving resolution for high-priority security incidents.
Architect sophisticated detection strategies using CrowdStrike Query Language (CQL) and oversee proactive threat-hunting operations.
Collaborate with cross-functional teams to strengthen security controls and document actionable remediation recommendations.
Arista Networks is a leader in data-driven, client-to-cloud networking for large data center, campus, and routing environments. The company is profitable with over $9 billion in revenue and a global, engineering-centric culture that values diversity, inclusion, and innovation.
Check Point protects over 100,000 organizations worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation. We are recognized by TIME, Newsweek, and Forbes for excellence and workplace culture, with smart, curious people who take ownership and solve complex problems.
Design, test, and optimize detection workflows including sourcing queries, collection methods, enrichment logic across data sources.
Partner with Product and Engineering to communicate customer feedback and emerging threat patterns.
Analyze recurring trends across alerts and customer environments to inform scalable platform improvements.
Doppel is building the future of social engineering defense using an AI-native platform to protect against phishing, impersonation, and fraud. Backed by Andreessen Horowitz and Bessemer Venture Partners, it is a rapidly growing Series C startup with deep cybersecurity expertise and a culture of clarity and collaboration.
You will hunt for and analyze adversary capabilities targeting ICS/OT networks.
You will develop tools and scripts for capability analysis and inform detection strategies.
Your work directly enhances Dragos' ability to defend against advanced threats.
Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The company is a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.
Lead multiple client-facing incident response engagements, guiding clients through the entire lifecycle from detection to recovery.
Conduct scoping calls and coordinate with cross-functional teams, legal counsel, and insurers to ensure high-quality service.
Produce clear reports on incident findings and share knowledge to foster continuous learning within the team.
Surefire Cyber redefines incident response by delivering swift, strong responses to cyber incidents like ransomware and data theft. Founded by industry veterans, the company focuses on client-centric solutions and has a collaborative culture prioritizing efficiency and transparency.
Monitoring customer environments on the ERM intelligence platform and producing actionable intelligence alerts and reports.
Investigating urgent issues affecting customers, such as cyber attacks and incidents, including threat actors, attack tools, and techniques.
Resolving Tier 1 technical issues customers may experience on the ERM intelligence platform.
Cyberint is a cybersecurity company that provides external risk management solutions to reduce external cyber threats. The company culture emphasizes teamwork and continuous learning.
Manage a high-functioning cybersecurity research team focused on threat detection and prevention.
Collaborate with Product, Marketing, and SOC teams to develop and prioritize the threat operations roadmap.
Proactively identify risks, support team development, and ensure alignment with the company mission.
Huntress is a remote-first cybersecurity company founded in 2015 by former NSA operators, providing enterprise-grade security to businesses of all sizes. They now secure over 5 million endpoints and 11 million identities, backed by a 24/7 human-led SOC and a culture of collaboration and impact.
Lead detection engineering innovation by reimagining how unlimited AI capacity transforms SOC workflows.
Partner with engineering teams to encode expert detection knowledge into product, designing scoring rubrics for AI-generated content.
Stay current on emerging threats and conduct original research to develop novel AI-assisted detection approaches.
Dropzone's mission is to scale cybersecurity beyond human limits by augmenting security engineers with AI specialists. We are an award-winning, venture-backed company disrupting the $200B+ cybersecurity market with a team experienced in cybersecurity, AI/ML, and SaaS.
Build and maintain SIEM for log collection and detection rules across corporate and production environments.
Design and deploy canary tokens and early warning mechanisms to detect threats before they reach critical assets.
Investigate security incidents end-to-end, including malware analysis, exfiltration assessment, and timeline reconstruction.
Quora operates two platforms: a global knowledge sharing platform with over 300M monthly unique visitors, and Poe, a platform for chatting and building with AI language models. The company is privately held, remote-first, and fosters a culture of transparency, collaboration, and experimentation.
Monitor security events and provide technical analysis on alerts
Lead information security incidents as Incident Commander, developing response strategies and coordinating across teams
Champion Samsara's cultural principles while delivering security guidance for incident response and insider threat initiatives
Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, a platform that enables organizations to harness IoT data for actionable insights and improved operations. They are a recently public company with a culture that encourages rapid career development and a focus on digitizing large sectors of the global economy.
Analyze operational performance data to identify trends, inefficiencies, and improvement opportunities in cybersecurity operations.
Collaborate with security teams and leaders to optimize workflows, enhance efficiency, and drive continuous improvement.
Define and monitor performance metrics, develop dashboards, and integrate AI tools to improve data interpretation and decision-making.
The employer is a cybersecurity partner company that improves security operations through data-driven insights. They offer a remote-first environment with a comprehensive employee experience, supporting professional growth and well-being.
Lead and mentor the Detection Engineering & Automation team, driving delivery and professional growth.
Own the full detection lifecycle, from use-case design to implementation, optimization, and retirement.
Develop SIEM/EDR rules, detection-as-code pipelines, and SOAR automation playbooks to reduce alert fatigue.
This role is listed on behalf of a partner company, which manages all applications and next steps. The company is a remote-first organization focused on building advanced cyber defense capabilities, with a collaborative culture and a proactive security program.
Own and lead building out the Insider Trust Team’s infrastructure to engineer and automate end-to-end detection and investigation workflows.
Develop, measure, and tune detection rules in Sigma to ensure effective and sustainable operations.
Drive projects with a focus on Insider Risks, ranging from access abuse and intellectual property theft, to novel risks emerging within the blockchain/Web3 space.
We are the team behind Chainlink, the industry-standard oracle platform bringing capital markets onchain and powering the majority of DeFi. We have enabled tens of trillions in transaction value and secure the vast majority of DeFi, with a culture of security and innovation.
Lead and mentor a team of Incident Response analysts during active security incidents.
Serve as the primary customer-facing lead during investigations and crisis situations.
Coordinate incident triage, containment, eradication, and recovery efforts.
Check Point Software Technologies is the world's leading vendor of cyber security, facing the most sophisticated threats and attacks. The company has been recognized by Time Magazine, Newsweek, and Forbes as a top employer, with a global team of driven and innovative employees.