Remote job
Detection Analyst
Job details
About this role
Role overview This position sits inside a Detection Operations team supporting Managed Detection and Response customers, using an advanced detection platform to investigate endpoint telemetry, alerts, and log sources across multiple security domains. The role combines hands-on threat analysis with workflow automation to deliver high-fidelity, actionable threat reporting at scale.
Responsibilities - Analyze EDR telemetry, alerts, and log sources across Endpoint, Identity, Network, and Cloud/SaaS detection domains. - Publish threat findings to customers through clearly written communications that convey key indicators and remediation context. - Improve Detection Operations workflows through orchestration and automation to keep pace with high telemetry volumes. - Apply AI-driven tools and automated workflows where useful to accelerate threat detection and security engineering output.
Requirements - Strong experience in Endpoint Detection and Response plus at least one additional functional area such as Cloud/SaaS, Identity, Email, or Network detection. - Expertise using query languages and working with syntax across EDR or other security platforms, including SQL or Lucene. - Demonstrated curiosity about AI tools with a proven history of integrating new technologies into security workflows.
Nice to have - Practical experience applying AI-driven tools or automated workflows to accelerate threat detection. - Prior professional experience in a Red Team or offensive security capacity. - Active involvement in the Infosec community through blogs, webinars, or conference presentations.
Benefits and work setup - Remote position within the United States, reporting to the Detection Analyst Manager. - Full-time role with a published base pay range of $96,600–$138,000 USD, plus benefits that include health plans, paid time off, parental leave, retirement options, and education reimbursement.