Information Security Advisor
Overview
In this role you will spearhead advanced investigations within a 24/7/365 Security Operations Center, driving containment and remediation of complex incidents. You will collaborate with SOC leads, engineers, and threat intel teams to enhance detection and response, leveraging MITRE ATT&CK and multi-source data. You will mentor junior staff and help refine SOC processes to strengthen the organization’s cybersecurity posture. This is a hands-on, cross-functional role with direct impact on incident readiness and leadership briefings. You’ll work on high-impact threats across endpoints, cloud, and OT, shaping proactive security strategies.
ResponsibilitiesLead advanced incident detection, investigation, and analysis using SIEM/EDR/IDS/IPS and firewall dataCoordinate complex incident response activities across SOC, forensics, and engineering teamsConduct proactive threat hunting analyzing telemetry and behavioral data for IOCs and anomaliesCollaborate with forensics teams to ensure proper evidence handling and artifact analysisDevelop and refine SOC processes, playbooks, detection rules, and automation workflowsPerform threat intelligence collection and contextualization to produce actionable recommendationsMentor and train SOC analysts through tabletop exercises and real-time guidanceCollaborate with engineering, IT, and cloud teams to address identified vulnerabilitiesMaintain documentation and reporting of investigations, timelines, and post-incident reviews
Key requirementsMinimum 8 years of experience in IT and/or information securityDoD 8140 certification or ability to obtain within 6 monthsActive Secret clearance with eligibility for Top-Secret if requestedMaster’s degree in relevant IT/cybersecurity fieldsStrong experience with incident response, threat hunting, and forensicsMentoring and coachingCross-functional collaborationExecutive-level communicationSIEM, EDR, IDS/IPS data correlationMITRE ATT&CK framework usageThreat hunting and anomaly detection