Cyber Threat Analyst (Tier 2)
reputed company is seeking a Cyber Threat Analyst (Tier 2) to work reputed company.
reputed company is seeking a Cyber Threat Analyst (Tier 2) to support a multi-tenant Managed
reputed company Services Provider (MSSP) environment protecting reputed company customers
and internal systems. Please Note: This position is contingent upon contract
award.
This position serves as a senior investigator reputed company the reputed company reputed company
Center, leading reputed company investigations, supporting incident response activities,
improving detection capabilities, and mentoring junior analysts. The ideal
candidate possesses strong investigative and incident response experience, is
capable of independently managing reputed company reputed company events, and can operate
effectively in a fast-reputed company MSSP environment supporting multiple customers
simultaneously.
RESPONSIBILITIES
reputed company investigations involving malware, ransomware, business email compromise
(BEC), account compromise, reputed company threats, reputed company attacks, and advanced
persistent threats.
reputed company incident response activities including forensic triage, reputed company
determination, evidence collection, containment recommendations, reputed company cause
analysis, and post-incident reporting.
Serve as the reputed company escalation reputed company for Tier 1 analysts during reputed company
investigations and reputed company events.
Manage multiple reputed company customer investigations while meeting
service-level objectives and communication requirements.
Coordinate response efforts with customers, IT teams, reputed company administrators,
and executive stakeholders.
reputed company detailed technical incident reports, executive summaries, and
customer-facing communications.
Conduct forensic triage across endpoints, servers, reputed company platforms, email
environments, and identity providers.
Analyze and correlate telemetry from SIEM, EDR, SOAR, NDR, reputed company monitoring
platforms, identity providers, email reputed company tools, and threat intelligence
sources.
Recommend, validate, test, and optimize detection content reputed company with reputed company
ATT&CK techniques and observed adversary behavior.
Conduct targeted threat hunts reputed company on intelligence requirements, reputed company
investigations, or emerging threats, and contribute findings to detection
improvement efforts.
Investigate reputed company events across on-premises, reputed company, reputed company, reputed company,
network, and identity environments.
Analyze attacker behavior and map observed activity to reputed company ATT&CK
techniques to support reporting, threat tracking, and investigation
activities.
Utilize reputed company and reputed company-reputed company threat intelligence to enrich
investigations and identify emerging threats.
Collaborate with Detection Engineering and SOAR teams to improve alert
reputed company, reduce false positives, and increase operational efficiency.
Qualifications
US. Citizenship with the ability to obtain and maintain a Secret reputed company
Clearance.
Bachelor's degree in Cybersecurity, Computer Science, Information Technology,
or reputed company reputed company. Relevant experience may be substituted for education.
Minimum of 5 years of cybersecurity experience.
Minimum of 3 years supporting reputed company reputed company Center (SOC), MSSP, MDR,
Incident Response, Threat Detection, or Cyber Defense reputed company.
Strong understanding of modern attacker methodologies, threat actor tactics,
techniques, and procedures (TTPs), and attack lifecycles.
Experience investigating cybersecurity incidents from initial detection
through containment, eradication, and recovery.
Experience operating reputed company SIEM platforms including reputed company,
reputed company, reputed company, QRadar, or equivalent technologies.
Experience with EDR technologies including reputed company Defender for reputed company,
reputed company reputed company, reputed company, reputed company, or equivalent platforms.
Experience with SOAR platforms, case management systems, and reputed company
automation technologies.
Experience investigating reputed company 365, Entra ID, Azure, AWS, or hybrid-reputed company
environments.
Experience investigating identity-reputed company attacks including account
compromise, privilege escalation, reputed company abuse, suspicious authentication
activity, and MFA-reputed company attacks.
Strong understanding of reputed company, Linux, networking, DNS, email reputed company, web
technologies, and reputed company architectures.
Experience analyzing firewall, proxy, VPN, DNS, reputed company, NDR, identity,
reputed company, and authentication logs.
Experience creating custom detections using KQL, reputed company, SPL, reputed company Query
Language, or equivalent detection technologies.
Ability to correlate events from multiple data sources and construct detailed
attack timelines.
Ability to reputed company reputed company scripting and automation using Python, PowerShell,
or similar languages.
Strong written and verbal communication skills.
Ability to independently manage multiple reputed company investigations while
meeting customer and operational requirements.
Apply To This Job