Security Analyst (Threat Detection)
Core
Frontline responder in the Security Operations Center (SOC) identifying, triaging, and remediating security detections and anomalies to protect systems from unauthorized changes, loss, or theft.
Role type
Security Analyst (Threat Detection)
Builds
Detection capabilities and response playbooks for endpoint and network visibility
Domain
Information Security / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
OS auditing (Linux, Windows, macOS), network and host-based collection tools, incident response, scripting for automation, reverse engineering, C2 exploitation, system/network forensics, cloud security
Preferred skills
Understanding of threat actor TTPs (pre- and post-exploitation), SIEM usage (Elastic, Splunk), security community contributions (blogs, talks, CTFs, tool dev)
Technologies
Elastic, Splunk, Linux, Windows, macOS
Responsibilities
Identify, triage, and remediate security detections and anomalies; investigate security incidents from detection through root cause; collect evidence and collaborate with engineering teams to secure systems; enhance endpoint and network visibility and detection playbooks
Seniority
Individual Contributor (Level I or Level II)