Threat Analyst
Core
Investigate and respond to sophisticated cyber threats across enterprise security environments, analyzing alerts and incidents to determine root cause, scope, and impact.
Role type
Mid-level SOC Threat Analyst (Incident Response & Threat Hunting)
Builds
Detection and response capabilities for clients in a 24x7x365 managed environment
Domain
Cybersecurity / Managed Detection and Response (MDR)
Deliverable
client delivery
Required skills
EDR and SIEM investigation, malware analysis and deobfuscation, threat hunting, Windows and Linux forensics, network traffic analysis (TCP/IP, DNS, HTTP/S), scripting (PowerShell/Python), MITRE ATT&CK framework application
Preferred skills
Security+, CySA+, GCIH certifications, cloud and identity security investigation experience
Technologies
EDR, SIEM, Windows Event Logs, Linux logs, Active Directory, TCP/IP, DNS, HTTP/S
Responsibilities
Investigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments; Analyze incidents to establish root cause, attack scope, lateral movement, and persistence mechanisms; Support ransomware investigations by examining attacker activity and malware behavior; Conduct proactive threat hunts based on defined hypotheses and emerging intelligence; Investigate suspicious authentication events and privilege escalation; Correlate information from multiple security sources including EDR, SIEM, and network telemetry; Document investigative findings and provide actionable remediation guidance
Seniority
Mid-level, hands-on IC