JOBSEARCHER

Cyber Security Analyst

Overview In this role, you defend ADP’s global applications and data by leading incident responses and threat investigations. You will work within the Critical Incident Response Center to quickly triage alerts, determine risk, and coordinate containment and remediation with cross-functional teams. The position emphasizes hands-on security analytics, malware and forensics work, and collaboration with multiple security and business units. You will leverage advanced security tooling to improve detections and reduce false positives, helping protect client data and ADP’s brand at scale. This is a chance to shape security operations in a large enterprise and impact data protection across the organization. ResponsibilitiesInvestigate security alerts from multiple sources and apply containment and mitigation measuresLead complex investigations with cross-functional teams in large enterprise environmentsOwn alert investigations, mentor junior analysts, and drive investigations to resolutionPerform event monitoring and log analysis in a centralized queueEnrich and correlate IOCs to identify additional incidentsCollaborate with GSO teams and internal stakeholders during investigationsReview threat intel and identify indicators of attacks targeting ADPConduct malware analysis, packet-level and host forensic analysisAnalyze network events across devices and technologies from various vendorsCapture artifacts and document analyses, containment, and remediation stepsEscalate and coordinate with external teams and manage incident prioritizationDevelop and maintain new detection rules and improve alerting to reduce false positivesParticipate in purple team exercises and ad-hoc projectsManage multiple alerts and investigations concurrently Key requirementsBachelor's degree in Computer Systems Engineering (or equivalent)6+ years of security analysis and incident response experienceStrong Windows and Unix/Linux experienceSolid understanding of TCP/IP, networking, and enterprise infrastructureExperience with computer security incident handling, forensics, and vulnerabilitiesProficiency with security tools (SIEM, IDS/IPS, EDR/XDR, MFA, PKI, AD, etc.)Malware analysis and debugging/debugging scripting experienceSQL familiarity for queries and data manipulationAbility to collaborate across cross-functional teams and communicate clearlystrong analytical and communication skillsability to lead and mentor junior analystscross-functional collaborationIncident ResponseMalware AnalysisLog Analysis