CSIRT Analyst

Computer Task Group, IncAnchorage, AK
Hybrid

About The Position

This role is for a passionate Cyber Security professional, particularly in advanced Managed Detection & Response (MDR). The ideal candidate will have a natural inclination towards Incident Response, Digital Forensics, Threat Hunting, and Threat Intelligence. This position involves strengthening the blue team and assisting organizations under attack. The CSIRT Analyst will handle escalated security alerts and incidents, conduct DFIR assignments, participate in threat hunting, perform compromise assessments, collect threat intelligence, contribute to detection engineering, engage in purple teaming exercises, assist in creating playbooks, and co-write processes and procedures. The role also includes participation in the Incident Response on-call service.

Requirements

  • At least 3-5 years of experience in a similar position
  • Significant hands-on experience in disk, memory and log acquisition in a forensically sound manner
  • Significant hands-on experience in parsing and deep forensic analysis of extracted artifacts
  • Significant hands-on experience in professional post-incident report writing
  • A bachelor or master degree or equivalent through experience
  • A hands-on and proactive mindset with a 'can do' mentality
  • Experience and/or interest in working with MDR tools: EDR (CrowdStrike Falcon, MS Defender for Endpoint, Sentinel One, ...), NDR (Vectra, Darktrace, ...), xDR (CrowdStrike Identity Protection, MS Defender for Office/Clouds Apps/Identity/...).
  • Knowledge of Security Monitoring with SIEM technologies
  • A passion about the following security capabilities: Security Monitoring, Digital Forensics, Incident Response, Threat Intelligence, Threat Hunting

Responsibilities

  • Handle security alerts/incidents escalated by SOC Analysts (Tier 2)
  • Handle security alerts and incidents together with the team
  • Conduct DFIR assignments, including DFIR readiness assessments
  • Participate in weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
  • Perform compromise assessments to identify potential compromises and their scope
  • Collect Threat Intelligence (IOCs and TTPs)
  • Contribute to Detection Engineering in SIEM, xDR
  • Perform Purple Teaming exercises with the Red Team to test and improve defenses
  • Contribute to the creation of playbooks in SOAR
  • Co-write processes and procedures related to DFIR, Threat Intelligence, Threat Hunting
  • Be part of the Incident Response on-call service
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service