Senior Threat Analyst
Core
Provide 24/7 monitoring, detection, and response services for customer environments using enterprise security tools and log analysis.
Role type
Senior IC threat analyst (MDR Tier I)
Builds
Real-time threat monitoring, detection, and response services for global customers
Domain
Cybersecurity / Managed Detection and Response (MDR)
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Endpoint and network security tools (EDR, IDS/IPS), Windows OS (workstation/server), Linux/macOS environments, Windows event log analysis, TCP/IP and traffic analysis, incident response, threat hunting, attacker behavior analysis, containment and mitigation, persistence and privilege escalation identification, case management workflows, client communication
Preferred skills
MITRE ATT&CK framework, SIEM platforms, SQL queries, OSQuery, PowerShell scripting, cybersecurity certifications (GSEC, GCIA, GCIH, etc.)
Technologies
Sophos security stack, EDR/XDR, MDR case management platform, SIEM, OSQuery, PowerShell
Responsibilities
Monitor, investigate, and respond to alerts from the Sophos security stack; Lead and mentor Tier I Analysts on escalated cases; Perform end-to-end analysis on suspicious activity; Identify and respond to cyber threats using approved playbooks; Conduct threat hunting across the customer base; Investigate phishing emails, suspicious binaries, and behavioral anomalies; Support detection tuning by identifying false positives; Research emerging IOCs, exploits, and vulnerabilities; Manage case workflows and follow up with clients; Engage with clients via chat, phone, and tickets; Contribute to internal knowledge bases and process improvements.
Seniority
Senior, hands-on IC