Senior Security Analyst- Endpoints

Datto, Norwalk, CT, United States

The Total Data Protection Company

As the world’s leading provider of cloud-based software and technology solutions delivered by managed service providers (MSPs), Datto believes there is no limit to what small and medium businesses can achieve with the right technology. Datto offers Unified Continuity, Networking, and Business Management solutions and has created a one-of-a-kind ecosystem of MSP partners. These partners provide Datto solutions to over one million businesses across the globe. Since its founding in 2007, Datto continues to win awards each year for its rapid growth, product excellence, superior technical support, and for fostering an outstanding workplace. With headquarters in Norwalk, Connecticut, Datto has global offices in the United Kingdom, Netherlands, Denmark, Germany, Canada, Australia, China, and Singapore. Learn more at datto.com.

You will report to the Director of Security Operations. 

​​Datto, Inc. is seeking a Senior Security Analyst to conduct real-time analysis using SIEM and proprietary endpoint-based technologies. Your role will be to serve as technical lead in identifying and responding to cyber security incidents, performing digital forensics, conducting threat hunting and generally enhancing the defensive capabilities of the Security Operations Center (SOC). Ultimately, your purpose will be to help ensure Datto and its’ 18,000+ partners are able to respond effectively to whatever cyber threats impact them and our shared customers.

Additional responsibilities and functions:

  • Assist Datto partners through the incident handling process across Windows, Mac, and Linux platforms, perform basic malware analysis, and create security incident reports
  • Develop and improve processes for incident detection and the execution of countermeasures
  • Produce high-quality written and verbal communications, recommendations, and findings to internal and external stakeholders
  • Assist detection engineers in tuning detection rules to reduce false positives and noise
  • Create automations and workflow improvements for SOC analysts to triage and respond to detected events
  • Demonstrate industry thought leadership through blog posts, social media, and/or public speaking events

Required Skills:

  • At least three years of experience in Security Operations, Endpoint Detection & Response (EDR) analysis, endpoint monitoring, and/or digital forensics
  • Experience conducting or managing technical incident response for organizations
  • Strong understanding of targeted attacks and able to create customized containment and remediation plans for compromised organizations
  • Strong understanding of secure network architecture and networking principles
  • Knowledge of MITRE ATT&CK™ behavioral techniques and how to detect them
  • Knowledge of Windows, Linux and MacOS operating system internals
  • Knowledge of regex and SQL-type query languages
  • Knowledge of Systems Administration in order to implement and execute countermeasures and remediation
  • Capable of completing technical tasks without supervision
  • Must be willing to rotate between various shift schedules, including the possibility of nights or weekend

Desired Skills:

  • Former experience in one or more areas: security operations, cyber threat hunting, Endpoint Detection and Response (EDR), detection signatures and analytics 
  • Threat hunting & data analytics via tools like Elastic, Athena, or Redshift and SQL-like query languages
  • Experience with scripting and interpreter languages, particularly bash and PowerShell
  • Knowledge of offensive tools (e.g. Cobalt Strike, Mimikatz, Metasploit or Powershell Empire)
  • One or more applicable certifications: i.e. GCFA, GCFE, GREM, GNFA, or OSCP

At Datto, we’re committed to cultivating a healthy, positive and growth enabling environment. We are proud of our wide ranging benefits package which is available to all full-time employees, including:
  • Comprehensive health-care benefits
  • Flexible paid time off policy
  • Generous paid parental leave
  • “Datto University” virtual on-boarding program
  • Access to more than 5,000 courses via LinkedIn Learning
  • Education reimbursement
  • Employee Assistance Program
  • Headspace App
  • Charity match program
  • A dynamic and socially active work culture, including Employee Resource Groups
  • Networking and career development opportunities
  • And more!
Note: We are looking only for candidates willing to join us directly as W2 employees (No 3rd party candidates)
By submitting an application, you acknowledge we will process your data in order to consider you for the position you apply for and for other open positions within our company for which you may be suited. We collect and store your data in accordance with our Recruiting Privacy Practices.

Datto is an equal opportunity employer.

About Datto

About us Datto protects business data and provides secure connectivity for tens of thousands of the world's fastest growing companies. Datto's Total Data Protection solutions deliver uninterrupted access to business data on site, in transit and in the cloud. Thousands of IT service providers globally rely on Datto's combination of pioneering technology and dedicated services to ensure businesses are always on, no matter what. Datto is headquartered in Norwalk, Connecticut and has offices in Rochester, Boston, Portland, Toronto, London, Singapore and Sydney. Learn more at www.datto.com.

Want to learn more about Datto? Visit Datto's website.