Monitoring & Incident Response Analyst
- Incident Response
- triage
- Incident Management
- AWS
- Azure
- GCP
Introduction
This role within the Vehicle and Connected Cybersecurity organization is responsible for hands-on operational monitoring and incident response for connected vehicle and cloud environments. As part of the Product Security Operations Center (PSOC) team, you will triage alerts, support investigations, and help drive timely resolution across vehicle telematics, embedded systems, and cloud-native application stacks. This role contributes directly to the continuous cybersecurity monitoring capability for connected vehicles and the cloud services that support them. Reporting to the Manager of Monitoring Operations, this role focuses on alert triage, incident support, and continuous improvement of monitoring processes. We are seeking candidates with a solid cybersecurity foundation, including API security experience, along with embedded-vehicle exposure or a demonstrated aptitude and eagerness to learn. You will partner with cloud, vehicle, enterprise, incident-response, and global PSOC teams to help ensure effective investigation and resolution of security events affecting connected vehicles and the cloud services that power them.
Required Skills & Qualifications (Must-have qualifications that candidates must meet to be considered)
- Cyber Security, API, Information Security
- 3 to 5 years' experience in relevant field
- Bachelor’s degree in Computer Science, Cybersecurity, or Engineering, or related field
- 2 years in cybersecurity, security operations, or a related technical field
- Working understanding of incident response lifecycles, escalation, and incident management practices
- Experience with API security and exposure to cloud security operations on one or more major cloud platforms
- Embedded vehicle cybersecurity exposure, or a demonstrated aptitude and eagerness to learn
- Ability to work effectively in a fast-paced 24x7 operations environment, including shift-based coverage
- Clear written and verbal communication for documenting incidents and coordinating with technical team
- Prior work experience at client or in client's Industry
Applicants must be able to work directly for Artech on W2
Preferred Skills & Qualifications (Nice-to-have skills but are not required)
- Exposure to detecting and investigating threats across cloud and vehicle telemetry data
- Experience using/refining runbooks, playbooks, and escalation procedures in an operations setting
- Relevant certifications such as Security+, GIAC, or foundational cloud security certifications across AWS, Azure, or GCP
- Familiarity with embedded or automotive environments and the security considerations of cloud architecture
- Ability to turn recurring incidents into process or detection improvement suggestions
Day-to-Day Responsibilities (key tasks and expectations for the role)
- Operational Monitoring and Incident Response: Perform daily PSOC alert triage and support incident coordination, containment, remediation, recovery, and closure
- Cloud & Embedded Investigation and Resolution: Support investigations of security events across cloud application stacks and embedded vehicle architectures using available logging and telemetry
- Global PSOC Collaboration and Continuity: Partner with PSOC teams across regions to deliver consistent monitoring, investigation, and incident-response services; maintain effective continuity and handoffs for active security events
- Operational Improvement and Feedback Loop: Surface operational friction points and provide feedback to help improve detection logic, tooling, and response workflows
- Cross-Functional Partnership: Collaborate closely with the Cyber Incident Response Team (CIRT), Product Development, and Enterprise IT to execute response playbooks and coordinate complex mitigations
For immediate consideration please click APPLY to begin the screening process with Alex
Monitoring & Incident Response Analyst · Artech LLC