Related Posts
The job search is so nerve wrecking.
When is a 3 page resume acceptable?
More Posts
Additional Posts in Cyber Security Bowl
Anyone working in Pharma industry?
New to Fishbowl?
Download the Fishbowl app to
unlock all discussions on Fishbowl.
unlock all discussions on Fishbowl.



Do you have any more details on the job description?
You can reference the NIST or SANS Incident Response frameworks (https://cybersecurity.att.com/blogs/security-essentials/incident-response-steps-comparison-guide)
Also some companies say “IR” but really mean security operations.
You may need to know more about digital forensics/windows artifacts. Is the role entry level?
Mentor
If you're unfamiliar with Splunk and SIEM technologies - do the free Splunk fundamentals course on their website. TryHackMe.com has some blue team rooms that could be helpful.
It does all depend on the role though - EY1 is absolutely right that "IR" usually means SOC. With SOC work, SIEM is vital, but also knowing what types of vulnerabilities are out there, basic networking (what port is what), etc. If it's a legitimate threat hunting role - go deep into offensive. The best threat hunters think like the attackers and need to know the entire Kill Chain, MITRE ATT@CK (hot topic), pivot techniques, standard processes and their behaviors, powershell, bash, etc. I'd argue that threat hunters are the blue team rockstars - the defensive equivalent of your penetration testers - they need to know a lot and be extraordinarily competent.
You might also get into digital forensics depending on the role (more actual IR). If you have the extra money - Autopsy has a great foundations course on using their software that provides a lot of insight to artifact discovery as well as hands-on experience working with a great forensics tool.
Get familiar with stride and other threat modeling frameworks
Community Builder
owasp threats