Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
TikTok USDS logo

Senior Incident Response Analyst

TikTok USDS
  • ๐Ÿ‡บ๐Ÿ‡ธ United States
  • On-site
  • Senior
  • 1 month ago
  • AI
  • Threat Intelligence
  • Excel
  • Linux
  • Unix
  • Incident Response
  • Docker
  • Kubernetes
  • Zeek
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

About the Team

The TikTok USDS JV Security Operations Center (SOC) is responsible for global around-the-clock monitoring, response, mitigation, and resolution of critical security events to protect and defend TikTok US data, infrastructure, customers, users, and products. Aside from monitoring TikTok US infrastructure and networks for indicators of anomalies, breach, and/or unauthorized access, the SOC is responsible for leading response efforts to enterprise-wide incidents, including post-incident root-cause analysis and recovery efforts, as well as leading proactive investigations into threats otherwise unidentified, developing and maintaining response plans, playbooks, and procedures.

About the Role

This role is based in our Converged Security Operations Center in Washington, D.C., working closely in a follow-the-sun model with our global SOC counterparts in London and Sydney.

This is a highly proactive, technical, and high-stakes role. It requires a high degree of autonomy and a self-starter mentality - driven by an unwavering passion to defend the enterprise and minimize impact during critical security incidents.

As an IR Analyst, you will belong to a team of strong people, processes, and technologies responsible for monitoring, investigation, containing, eradicating, and recovering from sophisticated threats targeting TikTok's US operations, users, and infrastructure.

As a key member of the SOC, you will effectively fuse an understanding of the global threat landscape with deep knowledge of our US-based business operations to lead incident identification, investigation, cross-team management, containment strategies, and remediation efforts that make tangible impacts to the security of the business.

Responsibilities

  • You will drive technical response actions to protect our stakeholders and US-based users from increasingly fast-paced and AI-driven threats and attackers, including develop and tuning alerts to quickly identify anomalous and/or malicious activity occurring within TikTok USDS JV infrastructure.
  • You will leverage AI-driven and agentic tools and methodologies, paired closely with your investigative and problem-solving skills to conduct comprehensive investigations and root-cause analysis to guide the business in unearthing, evicting, and recovering from attacks from sophisticated threat actors.
  • You will collaborate closely with a variety of partner teams, including the Hunt team, Cyber Threat Intelligence, Digital Forensics, Legal, and Infrastructure teams to coordinate seamless, effective, and efficient operations.
  • To be most successful in this role, you must excel in highly complex, ambiguous situations, transforming chaotic incident signals into clear paths forward to ensure the resiliency of our critical US operational infrastructure, customers, users, and data.

Minimum Qualifications

  • 5+ years of experience directly triaging, managing, investigating, and remediating high-severity security incidents
  • Proven experience and capability leading teams in performing deep and complex global investigations involving a multitude of disparate data sources from teams and regions spanning the globe
  • Deep hands-on Linux/Unix command line experience for low-level system interrogation, log analysis, and artifact collection
  • Hands-on experience with cloud forensics and incident response across multi-cloud infrastructure, including container and container-level forensics (e.g., Docker, Kubernetes, container runtime logs) during active security investigations
  • Must possess the ability to navigate the chaos of an active breach, make progress without prescriptive direction, proactively drive remediation solutions a high degree of integrity, and have the ability to lead and inspire change through post-incident lessons learned

Preferred Qualifications

  • Demonstrated teamwork and collaboration skills in leading or contributing to global, multi-functional incident response teams
  • Demonstrated time management, problem-solving, and strict effort prioritization and within multiple constraints
  • Strong cross-functional expertise across multiple IT operational, network, cloud, and security disciplines
  • Excellent communication skills (verbal and written) with the ability to act as a technical leader or incident commander and influence without authority during crises
  • Ability to effectively translate complex technical compromise details into clear executive summaries for a broad range of technical and non-technical staff
  • Strong understanding and aptitude toward leveraging AI tools to accelerate investigation speeds and response efficacy
  • Excellent fundamental knowledge of industry-standard incident handling frameworks (e.g., NIST SP 800-61, ISO/IEC 27035, MITRE ATT&CK)
  • Proven capability and experience in performing deep and complex network analysis using PCAP captures and Zeek logs to reconstruct threat activity and adversary C2 communications
  • Proven experience with live incident identification, investigation, containment, eradication, and recovery from advanced persistent threats (APTs) and threat actor TTPs
  • Tenured experience and efficiency in querying, parsing, and analyzing large-scale datasets across large data warehouses and distributed data architectures

Senior Incident Response Analyst ยท TikTok USDS

Auto apply with Likeremote