
Principal Security Analyst | Hybrid Cork
- Cork
- Permanent
- Full-time
- Managing the lifecycle of a security incident from detection to resolution
- Coordinating with IT operations, engineering teams, and stakeholders to execute containment, eradication, and remediation activities in response to incidents
- Performing digital forensic investigations, able to collect and analyze digital evidence in a forensically sound and defensible manner, and familiar with associated legal concepts
- Communicating up or down, technical and non-technical report writing, prioritizing information, and presenting findings to technical teams and senior management in a clear and precise manner
- Understanding the current regulatory environment in most major geographies and how to identify data privacy issues and potential reporting requirements during incidents and investigations
- Researching and understanding Cybersecurity threats and threat actors
- Running After Action Reviews to make improvements to existing detection and response capabilities
- Compiling and analyzing response data for management reporting and metrics
- Design and propose advanced AI-driven detection methodologies to identify sophisticated threats and attack patterns across enterprise systems
- Lead the evaluation and continuous improvement of machine learning models used for threat intelligence and anomaly detection
- Build methods to advance automation and security
- Automate security controls to streamline operational services and support.
- Familiarity with key information security concepts, standards, and industry best practices.
- Hands-on experience with SIEM platforms (LogRhythm, ArcSight, Splunk, Microsoft Sentinel) for threat detection and correlation.
- 5+ years of security analysis experience with specialized knowledge in applying AI/ML techniques to threat hunting and incident investigations
- Demonstrated ability to create and refine AI algorithms for identifying zero-day vulnerabilities and emerging attack vectors in large-scale environments
- Strong troubleshooting, problem-solving, and research capabilities to assess security incidents and risks.
- Bachelor’s degree in Cybersecurity, Information Systems, or related field preferred, with 8+ years in cybersecurity operations.
- Certifications (Preferred): CISSP, CISM, CISA, GIAC (GCIA, GCIH, GCFA), or CEH
- Lead in setting the quality standards for the team's technical work, from code to software designs, while raising the skill level of less experienced team members