Incident Response Analyst, Cybersecurity Operations Detection & Response - Global SOC L3 Response
McDonald's CorporationAbout the role
Company Description
McDonald’s growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and Drive Thru). McDonald’s will accelerate technology innovation so 65M+ customers a day will experience a fast, easy experience, whether at one of our 25,000 and growing Drive thrus, through McDelivery, dine-in or takeaway.
McDonald’s Global Technology is here to power tomorrow’s feel-good moments.That’s why you’ll find us at the forefront of transformative technology, exploring new and innovative ways to serve our millions of customers and spread happiness one delicious Hot Fudge Sundae-dipped fry at a time. Using AI, robotics and emerging tech, we’re digitizing the Golden Arches. Combine that with our unparalleled global scale, and we’re reshaping all areas of the business, industry and every community that is home to a McDonald’s restaurant. We face complex tech challenges every day. But that’s where our diverse and talented teams come in. They’re made up of the best and brightest from all over the globe, and they thrive in the space where feel-good meets fast-paced.
Check out the McDonald’s Global Technology Technical Blog to learn how technology and our global team are directly enabling the Accelerating the Arches strategy.
Job Description
As a L3 Response Analyst within the Security Operations Center (SOC), your responsibilities include using defensive measures and information gathered from various sources to identify, analyze, and report cybersecurity events, ensuring the protection of McDonald's information assets. You play a crucial role in supporting the Incident Response process, responding to crisis situations, and mitigating immediate and potential cyber threats. Your expertise in security operations, event monitoring, eDiscovery, forensics, and incident response will be key in this role. The role works directly within Global Cyber Security (GCS), the organization responsible for our Cybersecurity Operations & Incident Response program and critical services, ensuring our leadership makes informed risk-based decisions.
Working within the Incident Response team and coordinating with other Cyber Operations teams to identify and report on security incidents as they occur and overseeing end-to-end remediation. Activities will include triaging security events, network and endpoint analysis, malware reverse engineering, threat hunting, vulnerability escalation, and resolving security incidents from detection to remediation. As part of the Security Operations team, you will create and implement standard operating procedures, playbooks, and processes to help streamline response monitoring, investigations, and analysis research. The role works directly within GCS, the organization responsible for our Cybersecurity Operations & Incident Response program and critical services, ensuring our leadership makes informed risk-based decisions.
In addition to the above SecOps/Incident Response functions, we are looking for someone who has experience and training in using forensic techniques to aid cybersecurity investigations. These include:
- Conduct analysis of log files, evidence, and other information to determine the best methods for identifying the perpetrators of network intrusions.
- Confirm what is known about an intrusion and discover new information, if possible, after identifying the intrusion via dynamic analysis.
- Provide technical summaries of findings in accordance with established reporting procedures.
- Examine recovered data for information relevant to the issue at hand.
- Perform file signature analysis and file system forensic analysis.
- Collect and analyze intrusion artifacts (e.g., source code, malware, and system configuration) and use discovered data to enable mitigation of potential cyber defense incidents within the enterprise.
- Utilize forensic tool suites (e.g., EnCase, Sleuthkit, FTK) and conduct forensic analyses in multiple operating system environments.
- Analyze anomalous code as malicious or benign and conduct bit-level analysis.
- Analyze memory dumps to extract information and identify obfuscation techniques.
- Conduct deep analysis of captured malicious code (e.g., malware forensics) and reverse engineering.
- Review existing investigative processes and tools in order to improve and mature current process, tooling, and other analyst skillsets
McDonald's is investing heavily in technology to drive our growth. We are looking at how to use technology to improve the customer experience and build new customer experiences. We are al
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s