Remote job
Senior Threat Analyst
Job details
About this role
Role overview A senior-level position on a Managed Detection and Response (MDR) team responsible for monitoring, investigating, and responding to threats across customer environments. The role blends hands-on incident response, threat hunting, and detection engineering with leadership responsibilities such as mentoring junior analysts and quality-reviewing casework. The position operates within a 24/7 follow-the-sun cybersecurity function that combines machine learning, automation, and human-led analysis to defend a large global customer base.
Responsibilities - Monitor, investigate, and respond to alerts generated by the security stack, including EDR/XDR capabilities, and act as the escalation point for Tier I and Tier II analysts on complex or high-severity cases. - Lead end-to-end technical response to major security incidents, coordinating containment and remediation activities with customers and internal teams. - Plan and lead hypothesis-driven threat hunts across the MDR customer base, informed by threat intelligence, adversary behavior, and frameworks such as MITRE ATT&CK. - Investigate phishing emails, suspicious binaries, and behavioral anomalies, and perform end-to-end analysis to assess scope, impact, and risk. - Drive detection improvements by identifying recurring false positives and coverage gaps, then authoring or refining detection logic. - Accurately document findings, investigative steps, and outcomes in the case management platform, and mentor junior analysts while quality-reviewing their work.
Requirements - Significant experience working in a SOC, MDR, or equivalent security operations environment handling detection, response, and threat hunting. - Strong familiarity with EDR/XDR tools, log analysis platforms, and endpoint collection systems used in modern SOC tooling. - Working knowledge of adversary tactics, techniques, and procedures, including applied use of the MITRE ATT&CK framework. - Experience mentoring or coaching junior analysts and reviewing casework for investigative quality. - Ability to communicate clearly with customers and internal stakeholders during high-pressure investigations.
Nice to have - Experience with detection engineering, including authoring or tuning detection content and reducing false positives. - Background in proactive threat research, such as tracking emerging indicators of compromise, active exploits, or vulnerabilities.
Benefits and work setup - Remote-first working model, with some roles potentially hybrid depending on requirements; applicants must have legal authorization to work in the posted jurisdiction without employer sponsorship. - Employee-led diversity and inclusion networks, annual charity and volunteer days, global sustainability initiatives, fitness and trivia events, wellbeing days, and monthly wellbeing webinars and training.