Назад
Company hidden
1 день назад

Threat Detection Analyst (Expert)

70 000 - 140 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Threat Detection Analyst (Expert) (Cybersecurity): Developing, validating, and maintaining high-fidelity threat detections across SIEM, XDR, EDR, cloud, and network security platforms with an accent on threat intelligence, adversary tradecraft, and enterprise telemetry. Focus on MITRE ATT&CK-aligned detection engineering, purple team validation, coverage gap analysis, and tuning logic to reduce false positives and false negatives.

Location: Onsite at a hirify.global corporate office in Detroit, Dallas, Columbus, Pittsburgh, Minnetonka, or Atlanta, United States.

Salary: $70,000–$140,000 annual base salary, plus eligibility for applicable incentive compensation.

Company

hirify.global is a banking organization providing financial services and operating enterprise cybersecurity functions.

What you will do

  • Design, develop, test, deploy, maintain, and tune threat detections across SIEM, XDR, EDR, cloud, and network security platforms.
  • Analyze threat intelligence, adversary behaviors, attack techniques, security telemetry, and log sources to identify detection opportunities.
  • Develop detection use cases, correlation rules, anomaly detections, behavioral detections, and telemetry requirements.
  • Validate detections through threat simulations, purple team exercises, adversary emulation, and attack replay testing.
  • Assess detection coverage and gaps, maintain documentation and coverage mappings, and report detection health and performance metrics.
  • Collaborate with Incident Response, Threat Intelligence, Security Engineering, and IT Operations teams, while mentoring junior analysts.

Requirements

  • At least 5 years of cybersecurity experience and at least 1 year of data analytics experience in threat detection.
  • High school diploma or 8+ additional years of equivalent experience; a bachelor's degree or equivalent experience is preferred.
  • Experience developing, testing, deploying, and maintaining enterprise threat detections based on MITRE ATT&CK, threat intelligence, and adversary behaviors.
  • Experience with security telemetry, log analytics, detection coverage analysis, and reducing false positives while maintaining detection efficacy.
  • Experience or knowledge involving platforms such as Palo Alto Cortex XSIAM, Microsoft Sentinel, Splunk, or Microsoft Defender XDR, and analytics languages such as KQL, SPL, XQL, or SQL.
  • Occasional travel may be required, at less than 10%.

Nice to have

  • Familiarity with detection-as-code and version-controlled detection development.
  • Experience with threat hunting, attack simulation, adversary emulation, or purple team methodologies.
  • Knowledge of Windows, Linux, macOS, Active Directory, Azure AD/Entra ID, cloud security telemetry, network protocols, and cybersecurity frameworks including Cyber Kill Chain and NIST CSF.
  • Scripting and automation experience with Python, PowerShell, Bash, or similar languages.

Culture & Benefits

  • Office-based work environment with collaboration across cybersecurity and IT teams.
  • Health insurance, wellness programs, life and disability insurance, and retirement savings plan.
  • Paid leave programs, paid holidays, and paid time off.
  • Position is exempt from overtime eligibility.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →