Execute day‑to‑day threat intake, triage, and analysis to protect the enterprise and field organizations.
Convert raw signals into validated findings, concise reports, and timely escalations.
Monitor and triage inbound alerts related to domain impersonation, credential exposure, bot‑log listings, payment/credit exposure, vulnerability chatter, and external threat activity.
Validate and categorize events using corroborating evidence and defined criteria; document decision points and rationale.
Escalate and coordinate with the appropriate owners following established workflows.
Maintain case records with reproducible notes, supporting artifacts, and status updates through closure.
Perform structured analysis to transform data into intelligence: outline assumptions, weigh confidence, and articulate likely impact and recommended actions.
Produce flash advisories for time‑sensitive threats, emerging threat briefs for significant trends, and field vulnerability summaries.
Assist detection engineering teams by researching adversary TTPs, validating indicators, and providing context for detection logic development.
Fulfill RFIs from internal teams; gather, analyze, and deliver answers aligned to intelligence requirements and timelines.
Support investigations by researching indicators, mapping findings to threat models, and providing targeted recommendations.
Participate in information‑sharing activities to stay informed on emerging threats and contribute relevant insights when appropriate.
Maintain program documentation and track key performance indicators, ensuring accuracy and currency.
Engage in team collaboration and knowledge‑sharing, contributing to process documentation, supporting onboarding, and participating in regular team discussions.
Identify opportunities for process improvement to enhance efficiency and consistency in alert handling, escalation, and reporting workflow.
Requirements
Associates degree
2+ years of experience in cyber security
Familiarity with alert triage and escalation workflows, including identifying false positives and prioritizing based on risk.
Understanding of common attack vectors and techniques (e.g., phishing, credential abuse, malware delivery) and how they relate to detection and response processes.
Ability to analyze security events, perform basic log review, and correlate indicators to identify potential threats.
Strong documentation and case management discipline, ensuring accurate and complete records for investigations.
Effective communication skills for summarizing findings and providing clear updates to technical and non-technical stakeholders.
Ability to work in a fast-paced environment, manage multiple tasks, and collaborate with SOC, IR, and engineering teams.
Exposure to SIEM alert handling, security monitoring, or basic detection tuning.
Experience assisting with incident investigations, including researching indicators and providing context for detection engineering or response teams.
Familiarity with threat modeling concepts (e.g., MITRE ATT&CK, kill chain) and how they apply to detection and response.
Basic knowledge of network and endpoint fundamentals (e.g., logs, authentication flows, common protocols).
Participation in tabletop exercises, after-action reviews, or cross-team security projects.
Cybersecurity certifications such as: - CompTIA Security+ - CompTIA CySA+
Benefits
Regular collaboration with relevant stakeholders.
Focused one-on-one time with your manager.
Access to mentorship opportunities.
Networking opportunities including access to Asian, Hispanic/Latinx, African American, women, LGBTQIA+, veteran and disability-focused Business Resource Groups.
Access to learning content on Degreed and other informational platforms.
Job title
Information Security Consultant – Threat Intelligence Analyst
Desktop Support & Security Analyst handling technical support and cybersecurity for the WHOI. Balancing responsibilities between End - User Technology support and Information Security operations while ensuring user functionality.
IT & Security Analyst managing IT operations and security for WEBTOON Entertainment in Los Angeles. Collaborating with global security teams and overseeing user access and security systems.
Information Security Analyst managing critical governance, risk, and compliance topics. Leading incident responses and security policy development in a hybrid work model.
Cyber Security Analyst enhancing cyber resilience for the Swiss financial sector with a focus on threat intelligence. Collaborating closely with partners and regulatory agencies to safeguard against cyber threats.
Information Security Analyst overseeing access management for SKY applications, ensuring security compliance and incident management. Involves technical support and lifecycle management of requests.
Junior Information Security Analyst at Dotz supporting IT in security solutions and information asset protection. Engaging with various technology areas and projects on cybersecurity initiatives.
Cybersecurity Analyst developing and implementing information security programs at WebTPA. Liaising between IT and business partners, addressing security requirements throughout project life cycle.
Cyber Security Analyst managing user access and security for all company applications at a non - profit organization. Collaborating with teams to monitor cyber security incidents and ensure compliance with policies.
Cyber Security Analyst managing cyber security incidents and improving resilience at Heathrow Airport. Leading response playbook development and simulation exercises for effective incident handling.