
Senior Cyber Threat Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Oversee, assess, investigate, and resolve security events and incidents in accordance with established client service-level agreements.
• Conduct advanced analysis utilizing SIEM, EDR, IDS/IPS, firewall, DNS, identity, cloud, operating systems, applications, and database telemetry.
• Lead or assist in incidents throughout the entire incident response lifecycle, which includes preparation, identification, analysis, containment, eradication, recovery, and post-incident enhancement.
• Correlate evidence from network, endpoint, identity, and logs to ascertain attack scope, impact, root cause, and recommend remediation strategies.
• Identify common attack techniques and offer practical guidance for containment and remediation tailored to the affected environment.
• Act as the primary escalation point for junior analysts, performing a second review of investigations, validating findings, and mentoring analysts through complex decision-making processes.
• Provide insights on alert tuning, detection quality, reducing false positives, rule logic, thresholds, suppression criteria, and documentation enhancements with the Detection Engineering Team.
• Engage directly and professionally with clients via telephone, email, and meetings, clearly articulating security findings, risks, business impacts, response options, and subsequent steps.
• Escalate high-severity or high-impact incidents according to protocols and exercise sound judgment when data is incomplete.
• Develop and enhance investigation notes, client-facing incident communications, detection logic, procedures, and knowledge-base content.
• Stay updated on threat actor behavior, vulnerabilities, exploits, defensive techniques, and significant changes in the threat landscape.
• Participate in a rotating on-call schedule of two weeks on call followed by four weeks off, with an additional 10% compensation during scheduled on-call periods.
• Serve as an authority in the absence of the SOC Manager.
• A minimum of 3 years of relevant cybersecurity experience, including hands-on roles in a SOC, incident response, threat detection, managed security, or closely related operational positions.
• Extensive knowledge of networking fundamentals and traffic analysis, including TCP/IP, DNS, HTTP/S, routing, subnetting, public and private addressing, NAT/SNAT/DNAT, common ports and protocols, and packet-level investigation.
• Profound understanding of common cyberattacks, attacker techniques, indicators of compromise, potential impacts, and effective containment, eradication, recovery, and remediation approaches.
• Strong familiarity with incident response lifecycles and the capability to apply them consistently during real-world investigations.
• Advanced experience in analyzing security logs and network traffic from various sources, differentiating between malicious activities and benign anomalies.
• Solid working knowledge of Windows, Linux, Active Directory, authentication activities, endpoint telemetry, and cloud security concepts.
• Experience with SIEM platforms, IDS/IPS technologies, EDR tools, packet analysis tools, vulnerability information, and case management processes.
• Ability to interpret and preferably develop or refine detection content, such as Snort, Suricata, YARA, SIEM queries, vendor rules, or alert logic.
• Exceptional written and verbal communication skills, including the ability to confidently and articulately discuss technical security topics, risks, and remediation with clients.
• Proven ability to mentor analysts, provide constructive feedback, and make defensible decisions under pressure with minimal supervision.
• Ability to work Monday to Friday from 9 am to 6 pm ET and participate in the rotating on-call schedule.
• U.S. Work Authorization is required (Harbor IT cannot provide visa sponsorship for this position).
• 100% employer-covered employee benefits, with additional premium selections available.
• 401(k) matching.
• Reimbursement for approved tuition, certifications, conference attendance, and related professional development.
• Harbor IT-approved holidays, when applicable.
• A culture that prioritizes supporting employees in putting family first.
• Additional benefits based on position and eligibility.
Unisys
Sibylline Ltd
Instituto Hardware BR HBR
Allstate
Get handpicked remote jobs straight to your inbox weekly.