Senior Cyber Threat Analyst

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Harbor IT

Harbor IT

201 - 500 employees

Founded 1995

🔒 Cybersecurity

🤝 B2B

💰 $37M Series C on 2005-04

Cybersecurity • B2B

Harbor IT is a cyber-first managed services provider that delivers integrated IT, cybersecurity, and cloud services to organizations operating in complex, mission-critical, and regulated environments. They provide managed cybersecurity (including MDR), security awareness training, cyber governance and risk due diligence, managed IT helpdesk, server and network management, and managed cloud and infrastructure services. Harbor IT focuses on clients such as private equity-backed companies, healthcare & life sciences, critical infrastructure, and regulated professional services, emphasizing security, uptime, and enterprise value.

📋 Description

• Monitor, triage, investigate, and resolve security events and incidents within established client service-level agreements. • Perform advanced analysis across SIEM, EDR, IDS/IPS, firewall, DNS, identity, cloud, operating system, application, and database telemetry. • Lead or support incidents through the full incident response lifecycle, including preparation, identification, analysis, containment, eradication, recovery, and post-incident improvement. • Correlate network, endpoint, identity, and log evidence to determine attack scope, impact, root cause, and recommended remediation. • Recognize common attack techniques and provide practical containment and remediation guidance appropriate to the affected environment. • Serve as the first escalation point for junior analysts, providing a second review of investigations, validating conclusions, and coaching analysts through complex decisions. • Advise on alert tuning, detection quality, false-positive reduction, rule logic, thresholds, suppression criteria, and documentation improvements with the Detection Engineering Team. • Communicate directly and professionally with clients by telephone, email, and meetings, clearly explaining security findings, risk, business impact, response options, and next steps. • Escalate high-severity or high-impact incidents according to process and exercise sound judgment when available data is incomplete. • Create and improve investigation notes, client-facing incident communications, detection logic, procedures, and knowledge-base content. • Remain current on threat actor behavior, vulnerabilities, exploits, defensive techniques, and relevant changes in the threat landscape. • Participate in a rotating on-call schedule of two weeks on call followed by four weeks off. Employees receive an additional 10% compensation during scheduled on-call periods. • Serve as a voice of authority during the SOC Manager’s absence.

🎯 Requirements

• 3+ years of relevant cybersecurity experience, including hands-on experience in a SOC, incident response, threat detection, managed security, or closely related operational role. • Deep familiarity with networking fundamentals and traffic analysis, including TCP/IP, DNS, HTTP/S, routing, subnetting, public and private addressing, NAT/SNAT/DNAT, common ports and protocols, and packet-level investigation. • Deep familiarity with common cyberattacks, attacker techniques, indicators of compromise, likely impact, and effective containment, eradication, recovery, and remediation steps. • Deep familiarity with incident response lifecycles and the ability to apply them consistently during real-world investigations. • Advanced experience analyzing security logs and network traffic from diverse sources and distinguishing malicious activity from benign anomalies. • Strong working knowledge of Windows, Linux, Active Directory, authentication activity, endpoint telemetry, and cloud security concepts. • Experience with SIEM platforms, IDS/IPS technologies, EDR tools, packet analysis tools, vulnerability information, and case management workflows. • Ability to interpret and preferably develop or tune detection content, such as Snort, Suricata, YARA, SIEM queries, vendor rules, or alert logic. • Excellent written and verbal communication skills, including the ability to speak confidently and eloquently with clients about technical security topics, risk, and remediation. • Demonstrated ability to mentor analysts, provide constructive review, and make defensible decisions under time pressure with minimal supervision. • Ability to work Monday – Friday 9 am – 6 pm ET and participate in the rotating on-call schedule. • U.S. Work Authorization (Harbor IT is unable to provide visa sponsorship for this role).

🏖️ Benefits

• 100% employer-paid employee benefits, with additional premium selections available • 401(k) matching • Reimbursement for approved tuition, certifications, conference attendance, and related professional development • Harbor IT-approved holidays, when applicable • A culture that supports employees in putting family first • Additional benefits based on position and eligibility

Apply Now

Similar Jobs

🔥 20 hours ago

Nisos

51 - 200

🔒 Cybersecurity

🔐 Security

Senior Intelligence Analyst at Nisos providing actionable analysis for geopolitical and cybersecurity issues. Collaborating nationwide while working remotely with a distributed team.

🔥 22 hours ago

eFinancial

201 - 500

💸 Finance

🏪 Marketplace

Competitive Intelligence Analyst at Fidelity Life focusing on monitoring competitor activities and market trends. Collaborating with cross-functional teams to convert insights into actionable strategies.

🕒 Yesterday

LMI

1001 - 5000

🤖 Artificial Intelligence

⚕️ Healthcare Insurance

🏛️ Government

Logistics Operations Center Global Operations and Intel Analyst at LMI supporting Army logistics. Involves operational planning, situational awareness, and executive decision support in a remote role.

🕒 4 days ago

GM Financial

5001 - 10000

💸 Finance

👥 B2C

🤝 B2B

Fraud Intelligence Analyst II at General Motors Insurance analyzing and mitigating auto insurance fraud trends utilizing advanced analytics and AI tools. Collaborating with teams to strengthen fraud detection and prevention.

🕒 4 days ago

Sibylline Ltd

201 - 500

📋 Compliance

🔐 Security

Embedded Intelligence Analyst Team Lead at Sibylline overseeing a team focused on delivering actionable intelligence. Supporting intelligence programs for a global technology company while ensuring high-quality delivery in a remote environment.