Threat Analyst 2
Core
Investigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments to identify, investigate, and neutralize sophisticated cyber threats.
Role type
Mid-level incident response analyst (MDR)
Builds
Incident response playbooks, detection capabilities, and client security posture
Domain
Cybersecurity / Managed Detection and Response
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
Incident investigation, threat hunting, malware analysis, ransomware investigation, MITRE ATT&CK framework, Windows/Linux forensics, network traffic analysis, PowerShell scripting, log analysis, documentation
Preferred skills
Security+, CySA+, GCIH certifications, Python scripting, cloud security investigations
Technologies
EDR, SIEM, Active Directory, Windows Event Logs, Linux logs, TCP/IP, DNS, HTTP/S
Responsibilities
Investigate escalated security alerts and incidents; Analyze incidents to establish root cause and attack scope; Support ransomware investigations; Analyze and deobfuscate suspicious scripts and malware; Conduct proactive threat hunting; Investigate suspicious authentication and privilege escalation; Correlate information from EDR, SIEM, and cloud logging; Document findings and provide remediation recommendations; Collaborate with senior analysts on high-severity incidents; Support detection tuning and response playbook improvement
Seniority
Mid-level, hands-on IC