Job Summary:
The ideal candidate is a self-motivated security professional who consistently delivers high-quality results, demonstrates strong ownership of investigations and operational outcomes, proactively identifies opportunities for improvement, mentors team members, and effectively leverages automation and AI technologies to enhance security operations, threat detection, and incident response capabilities.
Apply if you are looking for a challenging opportunity to drive direction and participate in the dynamic growth in IT security at onsemi, voted the World’s Most Ethical Company for 5 years in a row.
Performance Objectives
Security Operations, Detection & Incident Response
- Lead the monitoring, analysis, investigation, and response of cybersecurity threats and security incidents across enterprise environments.
- Perform advanced triage and investigation of alerts generated by SIEM, EDR, DLP, IAM, cloud security, email security, network security, and other enterprise security technologies.
- Conduct comprehensive incident investigations, including threat validation, scope determination, timeline reconstruction, impact assessment, root cause analysis, and containment recommendations.
- Serve as an escalation point for junior analysts and assist with complex incidents requiring advanced analytical and technical expertise.
- Coordinate response activities across Security Operations, Infrastructure, Security Engineering, Legal, and business stakeholders.
- Drive incidents through the complete lifecycle from detection through remediation, recovery, documentation, and lessons learned.
- Maintain situational awareness of the evolving threat landscape, emerging risks, and active incidents affecting the organization.
Threat Hunting, Analysis & Detection Engineering
- Perform proactive threat hunting across endpoint, identity, network, cloud, application, and emerging technology environments to identify malicious activity beyond alert-driven detection.
- Leverage threat intelligence, behavioral analytics, telemetry correlation, and adversary tradecraft analysis to identify indicators of compromise (IOCs) and attacker tactics, techniques, and procedures (TTPs).
- Investigate sophisticated attack techniques including credential theft, ransomware, insider threats, business email compromise, cloud compromise, and living-off-the-land activity.
- Design, develop, tune, validate, and maintain detection content, analytics rules, dashboards, correlation logic, and threat-driven use cases.
- Continuously improve detection coverage through threat modeling, attack simulation findings, incident lessons learned, and intelligence-driven prioritization.
- Utilize frameworks such as MITRE ATT&CK, NIST 800-61, Cyber Kill Chain, and adversary emulation methodologies to improve detection and response effectiveness.
- Identify gaps in telemetry, monitoring coverage, and response capabilities while recommending improvements to increase operational maturity.
Digital Forensics & Advanced Investigation
- Support digital forensic investigations involving enterprise collaboration and communication.
- Assist with malware triage, indicator extraction, timeline development, and root cause determination.
- Develop investigative methodologies that improve repeatability, consistency, and overall investigative effectiveness.
Security Engineering, Automation & AI-Enabled Operations
- Lead efforts to enhance and optimize security tools, telemetry pipelines, integrations, and monitoring capabilities.
- Support onboarding of new data sources, cloud platforms, applications, and infrastructure services into enterprise security monitoring solutions.
- Develop and maintain automation workflows, orchestration capabilities, and machine-driven response processes using SOAR and related technologies.
- Leverage scripting, query languages, and security automation techniques to improve detection, investigation, reporting, and operational efficiency.
- Utilize artificial intelligence, machine learning technologies, large language models (LLMs), agentic frameworks, and AI-assisted workflows to accelerate investigations and improve analyst effectiveness.
- Contribute to secure AI adoption by helping evaluate AI-related risks, controls, governance requirements, and monitoring capabilities.
- Identify opportunities to increase operational efficiency through automation, AI augmentation, and process optimization.
Leadership, Mentorship & Operational Excellence
- Act as a senior resource and mentor for junior and mid-level analysts.
- Provide investigative guidance, technical coaching, and peer review of incident investigations and response activities.
- Demonstrate ownership and accountability for operational outcomes while consistently contributing to team objectives and strategic initiatives.
- Serve as a trusted advisor during major incidents and provide actionable recommendations to leadership.
- Lead or participate in tabletop exercises, purple-team engagements, operational readiness testing, and post-incident reviews.
- Drive continual improvement of security operations processes, playbooks, detection content, threat hunting methodologies, and incident response procedures.
- Maintain a strong commitment to operational excellence, continuous learning, and technical leadership within the team.
Documentation & Communication
- Produce high-quality investigation reports, executive summaries, incident briefings, and post-incident analyses.
- Communicate technical findings, risk implications, and recommended actions to both technical and executive audiences.
- Develop and maintain operational procedures, playbooks, runbooks, standards, and knowledge management documentation.
- Contribute to security metrics, reporting, operational dashboards, and program maturity assessments.
#LI-RT1
onsemi (Nasdaq: ON) is driving disruptive innovations to help build a better future. With a focus on automotive and industrial end-markets, the company is accelerating change in megatrends such as vehicle electrification and safety, sustainable energy grids, industrial automation, and 5G and cloud infrastructure. With a highly differentiated and innovative product portfolio, onsemi creates intelligent power and sensing technologies that solve the world’s most complex challenges and leads the way in creating a safer, cleaner, and smarter world.
We are committed to sourcing, attracting, and hiring high-performance innovators, while providing all candidates a positive recruitment experience that builds our brand as a great place to work.
|
Requirements:
Experience
- 5+ years of experience in Security Operations, Incident Response, Threat Hunting, Detection Engineering, Digital Forensics, Security Engineering, or a related cybersecurity discipline.
- Demonstrated experience leading complex investigations and coordinating response activities for high-priority cybersecurity incidents.
- Proven ability to independently manage investigative workstreams and drive incidents through resolution.
- Experience mentoring analysts and contributing to operational maturity initiatives.
Technical Knowledge
- Strong understanding of cybersecurity operations, threat detection, threat hunting, incident response, security engineering, and digital forensic principles.
- Advanced knowledge of networking, operating systems, authentication technologies, cloud computing, enterprise infrastructure, and security controls.
- Experience investigating activity across Windows, Linux, macOS, Microsoft 365, Azure, AWS, identity platforms, and cloud-native technologies.
- Hands-on experience with SIEM, EDR, SOAR, IAM, DLP, email security, cloud security, vulnerability management, and threat intelligence platforms.
- Understanding of malware behavior, forensic artifacts, attack methodologies, post-exploitation techniques, and attacker tradecraft.
Education
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline, or equivalent practical experience.
Preferred Qualifications
- Experience with EDR, Anti-virus solutions, SIEM, email security, vulnerability and penetration testing platforms, and other enterprise security platforms.
- Proficiency with scripting languages, e.g. Python, PowerShell, bash, or similar languages.
- Experience with digital forensics technologies and investigative methodologies.
- Experience with security automation, SOAR, orchestration, and AI-assisted security operations.
- Familiarity with large language models (LLMs), agentic AI frameworks, retrieval-augmented generation (RAG), AI governance, and secure AI architecture.
- Experience conducting advanced threat hunting and detection engineering activities.
- Experience operating in cloud-first and hybrid enterprise environments.
- Knowledge of MITRE ATT&CK, NIST 800-61, CIS Controls, Zero Trust, and modern cyber defense frameworks.
- Industry certifications such as GCIA, GCIH, CISSP, CySA+, or equivalent.
onsemi (Nasdaq: ON) is driving disruptive innovations to help build a better future. With a continued focus on the automotive and industrial end-markets, onsemi is accelerating change and driving disruptive innovation towards a sustainable ecosystem in high-growth megatrends such as vehicle electrification, advanced safety, alternative energy, and factory automation. With a highly differentiated and innovative product portfolio, onsemi creates intelligent power and sensing technologies that solve the world’s most complex challenges and leads the way in creating a safer, cleaner, and smarter world. Today, the industrial and automotive end-markets are responsible for two-thirds of global greenhouse gas emissions, providing an immense opportunity for onsemi to do its part in achieving a net-zero economy with its intelligent power and sensing technologies. Climate change presents not only a risk to the environment, but also opportunities for innovative business solutions, and onsemi is committed to applying its research and design expertise and adapting its own operations to achieve net-zero emissions by 2040.
#LI-RT1