Cyber Defense Analyst III
Core
Monitor, detect, and validate complex security threats while building automation scripts and SOAR playbooks to reduce manual toil and improve detection fidelity.
Role type
Senior IC cyber defense engineer (automation & detection)
Builds
Automated detection mechanisms, SOAR playbooks, and AI-augmented triage workflows
Domain
Cybersecurity, Security Operations Center (SOC), Cloud Security (GCP/AWS)
Deliverable
production ML models | product features | dashboards & analysis
Required skills
Telemetry analysis, Python scripting, SOAR playbook development, MITRE ATT&CK mapping, Cloud telemetry investigation, Detection-as-Code, CI/CD workflows, Threat hunting
Preferred skills
PowerShell, REST API integration, JSON/XML parsing, LLM prompt engineering, Mentorship
Technologies
Python, PowerShell, Git, SIEM, SOAR (Cortex XSOAR, Splunk SOAR, Torq, Tines), GCP, AWS
Responsibilities
Perform deep-dive analysis of network, host, identity, and cloud telemetry to identify malicious activity; Write automation scripts and build SOAR playbooks to eliminate manual monitoring tasks; Develop, test, and deploy SIEM detection rules using version control and CI/CD pipelines; Conduct proactive, hypothesis-driven threat hunts; Partner with engineering teams to validate AI-assisted workflows; Provide technical mentorship to junior analysts
Seniority
Senior, hands-on IC