Senior Information Security Analyst
Core
Design, deploy, and maintain deceptive technology (honeypots, honeytokens, decoy systems) to detect threat actors early and provide high-fidelity alerts to the security operations team.
Role type
Senior Information Security Analyst (Cyber Deception)
Builds
Deception layers across endpoint, cloud, network, identity, and application environments
Domain
Cybersecurity / Threat Detection
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Cyber deception concepts (honeypots, honeytokens, decoy systems), deception frameworks (Thinkst Canary, Illusive Networks, Cymmetria, TrapX, Acalvio, OpenCanary), network protocols, Windows/Linux internals, Active Directory, SIEM integration (Splunk, Elastic, QRadar), SOAR systems, MITRE ATT&CK framework, Python/PowerShell/Bash scripting
Preferred skills
Red/purple team experience, offensive thinking for defensive system building
Technologies
Thinkst Canary, Illusive Networks, Cymmetria, TrapX, Acalvio, OpenCanary, Splunk, Elastic, QRadar, Python, PowerShell, Bash
Responsibilities
Design and deploy deception assets (honeypots, honeytokens, decoy credentials, fake databases); Build deception layers tailored to different environments; Integrate deception events into detection pipelines (SIEM, SOAR, EDR); Develop and maintain custom honeypots or tune commercial platforms; Collaborate with threat intelligence and red team teams; Monitor and analyze attacker interactions to extract TTPs and IOCs; Assist in post-incident analysis; Document deployment strategies and playbooks; Research and evaluate new deception techniques
Seniority
Senior, hands-on IC