Overview
SOSi is seeking a Senior Cyber Incident Handling Analyst in Wiesbaden, Germany. The ideal candidate will possess senior-level expertise in managing the full lifecycle of cyber security incidents. This role involves monitoring for malicious activity, triaging events, and leading the coordination between technical teams and leadership to ensure incidents are contained, remediated, and documented in support of theater-level mission requirements.
Essential Job Duties
- Monitor and analyze Intrusion Detection Systems (IDS) and Security Information and Event Management (SIEM) platforms to detect malicious and anomalous activity.
- Lead the evaluation of security events to determine if a formal incident has occurred, assessing the potential impact on theater operations.
- Analyze data from various enterprise sources, including logs and packet captures, to draw definitive conclusions regarding past and future security incidents.
- Coordinate high-pressure response efforts between technical engineering teams and non-technical stakeholders to ensure a unified and effective defense posture.
- Maintain expert-level knowledge of hacker Tactics, Techniques, and Procedures (TTPs) and the current threat landscape to better anticipate and respond to exploits.
- Ensure every incident is meticulously documented from initial detection through final resolution, maintaining a clear record for after-action reporting and compliance.
- Articulate investigative findings and incident status updates to both technical audiences and executive leadership.
- Support continuous theater-level surveillance by participating in 24x7x365 shift operations, ensuring seamless hand-offs (pass-downs) between watch floors to maintain a persistent defensive posture.