Senior Detect & Respond Analyst
ShellAbout the role
Job Family Group:
Worker Type:
Posting Start Date:
Business Unit:
Experience Level:
Job Description:
What’s the Role
As organizations expand their digital and operational technology (OT) environments, the cyber‑attack surface grows rapidly. High‑profile incidents across industries demonstrate that cyber threats are real, sophisticated, and persistent — impacting business continuity, data integrity, and brand reputation.
To stay resilient, our Detect & Respond team plays a critical role in identifying intrusions, uncovering vulnerabilities, and responding to cyber incidents across both IT and OT landscapes. We are strengthening our global detection and incident response capabilities, and we are now looking for a Senior Detect & Respond Analyst to help elevate our cyber defense posture.
What You’ll Be Doing
Your role is ideal for someone who thrives in high‑pressure environments, enjoys deep technical investigation, and wants to contribute to protecting critical infrastructure.
As a Senior Detect & Respond Analyst, you will:
Execute end‑to‑end Detect & Incident Response processes — from initial detection through containment, eradication, and post‑incident review
Identify, triage, and respond to real‑time cyber intrusions across IT and OT environments
Lead detailed investigations to minimize business impact and uncover root causes
Collaborate with security engineering, automation, threat intelligence, and other cyber capabilities to continuously enhance detection and response
Analyze and correlate security events using industry‑leading SIEM, EDR, and network monitoring technologies (e.g., SIEM platforms, endpoint protection, IDS/IPS, network telemetry)
Monitor the performance and effectiveness of deployed security controls
Report vulnerabilities and drive corrective actions with stakeholders
Conduct forensic analysis, threat hunting, and advanced investigations
Develop and refine playbooks, standard operating procedures, and detection logic
Provide clear communication of incident impact and remediation progress to technical and executive stakeholders
Support wargame exercises, tabletop simulations, and continuous improvement initiatives
Participate in a rotating on‑call schedule to support 24/7 operations during critical incidents
What You Bring
We’re looking for someone with:
A bachelor’s degree (Master’s preferred) in Computer Science, Cybersecurity, or a related field. Certifications such as SANS, GCIH, GCIA, GCFA are a plus
Extensive experience in Cyber Detect & Respond, SOC operations, cybersecurity investigations, or network operations
Strong preference for OT SOC experience — including monitoring and responding to threats in industrial control systems (ICS), SCADA, and critical infrastructure environments
A solid background in one or more technical security domains, such as:
Ethical hacking / penetration testing
Red teaming / adversary simulation
Digital forensics
Threat hunting
Network security engineering
Strong analytical and problem‑solving skills, with the ability to examine complex data sets and identify patterns, anomalies, and attack indicators
Hands‑on experience with SIEM, EDR, IDS/IPS, firewalls, proxies, and network monitoring technologies
Understanding of the current threat landscape, attacker TTPs, malware behavior, and incident response practices
Familiarity with cloud platforms (AWS, Azure), scripting (PowerShell, Python, Bash), and system internals (Windows/Linux)
Ability to work under pressure, manage multiple investigations, and coordinate effectively across teams
Willingness to support after‑hours and on‑call responsibilities during high‑priority incidents
What we offer
You bring your skills and experience to
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s