Cybersecurity Threat Analyst I (Hybrid)
Core
Monitor security alerts, logs, and threat intelligence to identify suspicious activity, perform initial triage, and support incident response for a financial services firm.
Role type
Junior IC cybersecurity threat analyst (Level 1 triage)
Builds
Security operations center (SOC) alerting, incident response documentation, and vulnerability management reports
Domain
Financial services cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
TCP/IP networking, Windows/Linux/macOS OS familiarity, security log analysis, ticketing workflows, basic scripting (Python/PowerShell/SQL), AI tool validation
Preferred skills
SIEM/EDR/XDR/SOAR familiarity, vulnerability scanning, network traffic analysis, entry-level security certification, API/low-code automation, AI-assisted workflow usage
Technologies
SIEM, EDR/XDR, SOAR, vulnerability scanners, ticketing platforms, Python, PowerShell, SQL
Responsibilities
Monitor security alerts and perform initial triage using documented playbooks; Review firewall, email, DNS, and endpoint logs to identify indicators of compromise; Create and update tickets, document actions, and escalate incidents; Support incident response with evidence collection and containment tracking; Run vulnerability scans and review results for validation; Operate security monitoring tools and perform routine configuration tasks; Participate in change management and security awareness activities; Validate AI-generated content against authoritative sources before acting.
Seniority
Entry-level, hands-on IC