Sr Incident Responder (Remote)
Lensa is a career site that helps job seekers find great jobs in the US. We are not a staffing firm or agency. Lensa does not hire directly for these jobs, but promotes jobs on LinkedIn on behalf of its direct clients, recruitment ad agencies, and marketing partners. Lensa partners with DirectEmployers to promote this job for NBCUniversal. Clicking "Apply Now" or "Read more" on Lensa redirects you to the job board/employer site. Any information collected there is subject to their terms and privacy notice.
NBCUniversal is one of the world's leading media and entertainment companies. We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our theme parks and consumer experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, MSNBC, CNBC, NBC Sports, Telemundo, NBC Local Stations, Bravo, USA Network, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through Universal Filmed Entertainment Group and Universal Studio Group, and have world-renowned theme parks and attractions through Universal Destinations & Experiences. NBCUniversal is a subsidiary of Comcast Corporation. Our impact is rooted in improving the communities where our employees, customers, and audiences live and work. We have a rich tradition of giving back and ensuring our employees have the opportunity to serve their communities. We champion an inclusive culture and strive to attract and develop a talented workforce to create and deliver a wide range of content reflecting our world. Comcast NBCUniversal has announced its intent to create a new publicly traded company ('Versant') comprised of most of NBCUniversal's cable television networks, including USA Network, CNBC, MSNBC, Oxygen, E!, SYFY and Golf Channel along with complementary digital assets Fandango, Rotten Tomatoes, GolfNow, GolfPass, and SportsEngine. The well-capitalized company will have significant scale as a pure-play set of assets anchored by leading news, sports and entertainment content. The spin-off is expected to be completed during 2025. NBCUniversal’s Cyber Threat Operations team is responsible for providing cyber threat intelligence, event monitoring, response, and threat hunting for all areas of NBCUniversal in a highly collaborative, fast paced, and agile fashion. As a member of the Cyber Response team, a candidate can expect to utilize their technical expertise to assess, contain, and remediate cyber threats. The Sr Incident Responder is also an escalation point for security alerts from the security event analysts, and a candidate would be expected to mentor and share knowledge with others in the organization. The ideal candidate would have a working knowledge of current and relevant security technologies and how to apply them to cyber incident response actions. A clear investigative methodology with a focus on preserving evidence and analyzing data to form conclusions that will steer response directions. Experience responding to multi-faceted security events and incidents and assisting with the coordination of subsequent response efforts prioritizing mission critical elements. Responsibilities The role involves regular interaction with various groups and leadership within the organization to accomplish job responsibilities. Working closely with the Cyber Response Manager the Sr Incident Responder will manage workflows, escalations, and advance technical processes to build program maturity and growth. The successful candidate will be responsible for participating in the following activities:- Responsible for day-to-day operational tasks related to the ongoing support of Threat Operations.
- Forensically analyze escalated security events from the SOC and conduct response actions following NIST and SANS Incident Response Frameworks.
- Oversee and triage ticket queues focusing on prioritization, potential impact, and escalations.
- Responsible for analyzing threat data from multiple sources and identifying security incidents and events of importance for direct escalation to Incident Commander(s).
- Perform root cause and forensic log analysis for security incidents to determine enterprise risk, impact, and effective remediations needed across multiple technology platforms (Cloud, Hosts, Networks, Applications, Email)
- Function as Incident Handler for security incidents to drive containment and remediation action items for various platforms, environments, and technologies
- Provide detailed timeline analysis to showcase evidence-based conclusionson entry vectors, lateral movement, and campaign correlation
- Identify, articulate, and explain attack vectors, threat tactics, and attacker techniques to technical and non-technical stakeholders including senior leadership
- Collaborate with internal teams, external partners, and vendors to resolve active Cyber Incidents
- Keep detailed notes on all analysis activity, documented in the case management system to validate process adherence.
- Contribute to the strategic creation and updating of new and existing SOAR playbooks and runbooks and response process documentation.
- Provide On-Call support for escalated events for 1 week on rotation with other Incident Responders
- Involvement with Cyber initiatives and projects that influence incident response capabilities
- Bachelor’s Degree/Masters Degree in an IT related field and/or equivalent work experience
- Minimum 5 years working in Cyber Defense with experience in Incident Response, Security Operations Center (SOC), detection engineering, or similar functions.
- Previous experience supporting or leading incident response functions.
- Experience using industry-standard security toolsets in a layered defense model
- Working knowledge of core Enterprise IT concepts (web application architectures, networking, etc.)
- Experience with host-based and network-based forensics tools and analysis
- Knowledge of the cyber threat landscape to include different types of adversaries, campaigns, and the motivations that drive them
- Knowledge of industry recognized security and analysis frameworks (Mitre ATT&CK, Kill Chain, Diamond Model, NIST Incident Response, etc.)
- Exceptional written and verbal communication skills
- Must be self-motivated and able to work both independently and as part of a team
- Strong communication (both verbal and written) and client intimacy skills with experience briefing corporate executives and professionals
- Ability to be on call and provide support during nontraditional working hours
- Hands on experience working with Incident Response and Threat Monitoring SOC functions
- Previous experience providing incident response/SOC support for Fortune 1000 companies
- Previous experience with various endpoint detection and response (EDR) technologies
- Previous experience working with various Forensics technologies to include EnCase, FTK, etc.
- Incorporates the word “Peacock” into resume and/or job application
- Previous experience working with network tools and technologies such as firewall (FW), proxies, IPS/IDS devices, full packet capture (FPC), and email platforms
- Previous experience conducting static, dynamic, or reverse engineering malware analysis
- Experience in applying security concepts to Cloud computing (AWS, Azure, GCP)
- Relevant certifications (GCIA, GCIH, GCFA, GNFA, etc.)
- Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee’s residence.
Recommended Jobs
Senior Technical Lead ios,android,java
Job Senior Technical Lead ios,android,java Mastercard Location: NYC Front End Developer with (iOS and Android) 5+ years' experience in Mobile Development. Experience developing …
Auditor 1 (Municipal), SG-18, Auditor Tr 2 (Municipal) ,SG-16, Auditor Trainee 1 (Municipal) ,SG-14 (NYHELPS) Item# 04046
NY HELP Yes Agency State Comptroller, Office of the Title Auditor 1 (Municipal), SG-18, Auditor Tr 2 (Municipal) ,SG-16, Auditor Trainee 1 (Municipal) ,SG-14 (NYHELPS) Item# 04046 Occu…
Technical Program Manager
Summary: The main function of a Technical Program Manager is to provide successful definition, implementation and delivery of complex programs that require cross-functional collaboration and interd…
Sprinter/Cargo Van Owner Operator
Hello, guys! We are hiring Sprinter / Cargo Van owner-operators for our company VICTORIA LOGISTICS CARRIER. We work within an independent contract agreement and offer very competitive rates. You …
Geriatric Medicine w/NYC PACE Program in Brooklyn Bushwick, New York - Sign-On
Our client is one of the oldest non-profit comprehensive healthcare organizations in the United States. They are a premier provider of home and community-based healthcare and services in the New York…
Bookkeeper NYC
Job description We’re seeking a reliable, detail-oriented, experienced Bookkeeper to manage the day-to-day financial operations for our client, a real estate construction company based in NYC. Thi…
Subscription Renewal Representative (Remote - East Coast, USA)
**Recruitment Fraud Alert** We've learned that scammers are impersonating Commvault team members-including HR and leadership-via email or text. These bad actors may conduct fake interviews and ask for…
9-15 Ft Reefer-Vans Owner-Operators
Owner-Operators With Reefer Vans With DOT Needed: 9-15ft Of Space Needed Requirements: ~ Age: 21+. ~ No Rental Vehicles. ~ Not older than 2010. ~ Reefer equipment. ~9-15ft of the cargo…
Platform Software Engineer
&##127919; Why we exist We’re on a mission to improve the reliability, transparency, and efficiency of our energy systems, fostering a future with sustainable and abundant energy. To accomplish our a…
Flagship Director - Madison Ave
At Richemont Americas, we aspire to reflect the ever-changing world around us. We are proud to employ talent from many different backgrounds, experiences, and identities to build a continually evolvi…