What You'll Do:
Works as part of a Cyber Defense team that works 24/7 on rotational shifts.
Continuously monitor and respond to advanced threats and evolving attack vectors across multiple environments
Perform in-depth investigation and triage of security alerts to determine root cause, impact, and relevance.
Correlate alerts and telemetry from SIEM and log sources like EDR, IPS, Firewall and threat intelligence platforms to identify real threats.
Handle detections targeting cloud infra/services/applications.
Provide recommendations for containment, mitigation, and recovery to client or internal response teams.
Contribute to the development and fine-tuning of detection rules, analytics, and use cases to enhance threat visibility and strength overall defense posture.
Collaborate closely with Threat Intelligence, SOAR, and Engineering teams for enrichment and contextual analysis.
Document investigations, findings, and recommendations in accordance with SOC SOPs and reporting standards.
Serve as a subject matter expert on detection and response methodologies, including SIEM, SOAR, threat intelligence, log analysis, network and EDR telemetry, and other response techniques.
Develop and maintain accurate documentation which includes SOPs, playbooks, runbooks and SOC operational procedures.
Mentor and guide junior analysts, foster a culture of continuous learning and operational excellence and ensure adherence to operational quality benchmarks and SLAs.
What You've Done:
4+ years of experience in incident response, SOC Tier 2 or equivalent.
Strong understanding of adversary tradecraft (MITRE ATT&CK, Cyber Kill Chain, etc.).
Deep understanding of cloud security concepts.
Experience with EDRs, SIEMs, SOARs and log pipelines.
Solid grasp of Windows, Linux, and cloud security.
Familiarity with scripting languages for analysis.
In-depth understanding of network protocols, endpoint artifacts, memory, and log analysis.
Excellent problem-solving and analytical thinking.
Ability to work under pressure during incidents and with minimal supervision.
Strong documentation and communication skills, especially when dealing with stakeholders.
Collaborative, yet capable of deep focus and individual contribution.
What We Offer:
- 401(k), including an employer match of 100% of the first 3% contributed and 50% of the next 2% contributed
- Medical, Dental, and Vision Insurance (available on the 1st day of the month following your first day of employment)
- Group Term Life, Short-Term Disability, Long-Term Disability
- Voluntary Life, Hospital Indemnity, Accident, and/or Critical Illness
- Participation in the Discretionary Time Off (DTO) Program
- 11 Paid Holidays Annually
Similar Jobs
What you need to know about the Chicago Tech Scene
Key Facts About Chicago Tech
- Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
- Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
- Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
- Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory



