Incident Handler

<p><span style="color:#3b454a"><span><b>Incident Handler II, Detection & Response Services</b></span></span></p><p><span style="color:#3b454a"><span><br>We are looking for people with a passion for investigation and forensic analysis to join our MDR SOC team at Rapid7. As an Incident Handler II, you will work side by side MDR SOC analysts and MDR Incident Responders to investigate incidents ranging from commodity malware to sophisticated threat actors. </span></span></p><p><span style="color:#3b454a"><span><b>About the Team</b></span></span></p><p><span style="color:#3b454a"><span><br>Rapid7’s Managed Detection and Response (MDR) team is built from the ground up to bring motivated and passionate security talent face to face with emerging threats, practical challenges, and evil at scale. Our MDR service uses an impact-driven mindset to focus efforts on effective solutions, encouraging personal and technical innovation within the SOC. MDR provides 24/7/365 monitoring, threat hunting, incident response, and more with a focus on endpoint detection and behavioral intelligence.</span></span></p><p><span style="color:#3b454a"><span><b>About the Role</b></span></span></p><p><span style="color:#3b454a"><span><br>As an Incident Handler II in Rapid7’s SOC, you will be responsible for investigating and analyzing malicious activity in a multitude of customer environments. You will be enabled to complete investigations scaling in complexity from account compromises and commodity malware infections, to complex web server compromises and zero-day vulnerability exploitation. The trigger for the majority of these investigations will be from inbound customer requests, but you will also receive investigations handed off to you from frontline analysts. There may be times where you’re triaging alerts using Rapid7’s award-winning SIEM, InsightIDR, where you’ll find malicious activity that you’ll need to investigate and escalate to customers. In these investigations, your Cybersecurity Advisor colleagues will be largely responsible for direct communication with the customers regarding your investigations, however you will be expected to engage with customers as needed to drive more complex investigations forward. Lastly, you’re the go-to person for handling incident response engagements run by Rapid7’s Incident Response team.</span></span></p><p><span style="color:#3b454a"><span><b>In this role, you will:</b></span></span></p><ul><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>As a core duty, you will conduct investigations into a variety of malicious activity on workstations, servers, and in the cloud. You will investigate all levels of incidents, including Incident Response engagements in which you will provide analysis assistance to Rapid7’s Incident Responders, including scoping, timeline analysis, finding IAV, and helping update documents as needed.</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Own complex investigations that may need various levels of delegation, customer communication, documentation, and collaboration across teams.</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Be an escalation point for complex and advanced incidents. </span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Communicate with Cybersecurity Advisors regarding investigation findings, Requests For Information from clients, and remediation and mitigation recommendations.</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Directly communicate with customers regarding investigation findings or to assist in driving an investigation forward as needed.</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Prepare Incident Reports for each minor incident investigation you complete, which follow MITRE’s ATT&CK Framework and include your own forensic, malware, and root-cause analysis.</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Communicate with other analysts to share new intelligence regarding tactics, techniques, and trends utilized by threat actors.</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Provide continuous input to Rapid7’s Threat Intelligence and Detection Engineering team regarding new detection opportunities.</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Assist in customer engagement opportunities pertaining to the function of your role in the MDR service as necessary.</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Participate in projects that directly relate to your role in an effort to increase positive customer outcomes.</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Utilize Rapid7’s world-class software to triage and investigate alerts to identify potential compromises in customer environments as necessary.</span></span></p></li></ul><p><span style="color:#3b454a"><span><b>The skills you’ll bring include:</b></span></span></p><ul><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>3-4 years of experience in a cybersecurity related position (SOC and/or SIEM analysis experience preferred)</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Dedication to putting each customer’s needs and concerns at the forefront of all decision making.</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Understanding of core operating system concepts in Windows, MacOS/Darwin, and Linux. This includes at least an understanding of common internal system tools and directory structures.</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Proficiency with analyzing forensic artifacts to determine root cause analysis in investigation</span></span></p><ul><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Windows largely preferred, but bonus points for experience with Linux, AWS, Azure, and GCP)</span></span></p></li></ul></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>A fundamental understanding of how threat actors utilize tactics such as lateral movement, privilege escalation, defense evasion, persistence, command and control, and exfiltration. </span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Effective verbal communication skills that foster collaboration between the MDR SOC and the Incident Response team; this role serves as the bridge between our major service delivery functions.</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Strong written communication skills</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Some experience with static and dynamic malware analysis.</span></span></p></li><li style="color:#3b454a !important"><p><span style="color:#3b454a"><span>Passion for continuous learning and growth in the cybersecurity world.</span></span></p></li></ul><p><span style="color:#3b454a"><span>We know that the best ideas and solutions come from multi-dimensional teams. That’s because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don’t be shy - apply today.</span></span></p><p><span style="color:#3b454a"><span><b>About Rapid7</b></span></span></p><p><span style="color:#3b454a"><span><br>At Rapid7, we are on a mission to create a secure digital world for our customers, our industry, and our communities. We do this by embracing tenacity, passion, and collaboration to challenge what’s possible and drive extraordinary impact.<br> </span></span></p><p><span style="color:#3b454a"><span>Here, we’re building a dynamic workplace where everyone can have the career experience of a lifetime. We challenge ourselves to grow to our full potential. We learn from our missteps and celebrate our victories. We come to work every day to push boundaries in cybersecurity and keep our 10,000 global customers ahead of whatever’s next.<br><br></span></span></p><p><span style="color:#3b454a"><span>Join us and bring your unique experiences and perspectives to tackle some of the world’s biggest security challenges.</span></span></p><p><br></p><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;"> #LI-WP1 #LI-Remote</span><br><h2>About Rapid7</h2><p>At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome.</p><br><p>Protecting 11,500+ customers against bad actors and threats means we’re continuing to push the envelope just like we’ ve been doing for the past 20 years. If you ’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.</p><p></p><p><i>All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.</i></p>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...