Senior Cyber Threat Analyst
Harbor IT · United States · 1 mo ago
RemoteRemoteInformation TechnologyFull-time
About the role
Harbor IT is a security-led managed services provider built for critical, complex environments. We secure, operate, and scale IT for organizations where uptime, security, and compliance are mission-critical, backed by an in-house engineering team and a 24/7/365 US-based Security Operations Center.
Responsibilities
- Monitor, triage, investigate, and resolve security events and incidents within established client service-level agreements.
- Perform advanced analysis across SIEM, EDR, IDS/IPS, firewall, DNS, identity, cloud, operating system, application, and database telemetry.
- Lead or support incidents through the full incident response lifecycle, including preparation, identification, analysis, containment, eradication, recovery, and post-incident improvement.
- Correlate network, endpoint, identity, and log evidence to determine attack scope, impact, root cause, and recommended remediation.
- Recognize common attack techniques and provide practical containment and remediation guidance appropriate to the affected environment.
- Serve as the first escalation point for junior analysts, providing a second review of investigations, validating conclusions, and coaching analysts through complex decisions.
- Advise on alert tuning, detection quality, false-positive reduction, rule logic, thresholds, suppression criteria, and documentation improvements with the Detection Engineering Team.
- Communicate directly and professionally with clients by telephone, email, and meetings, clearly explaining security findings, risk, business impact, response options, and next steps.
- Escalate high-severity or high-impact incidents according to process and exercise sound judgment when available data is incomplete.
- Create and improve investigation notes, client-facing incident communications, detection logic, procedures, and knowledge-base content.
- Remain current on threat actor behavior, vulnerabilities, exploits, defensive techniques, and relevant changes in the threat landscape.
- Participate in a rotating on-call schedule of two weeks on call followed by four weeks off. Employees receive an additional 10% compensation during scheduled on-call periods.
- Serve as a voice of authority during the SOC Manager’s absence.
Qualifications
- 3+ years of relevant cybersecurity experience, including hands-on experience in a SOC, incident response, threat detection, managed security, or closely related operational role.
- Deep familiarity with networking fundamentals and traffic analysis, including TCP/IP, DNS, HTTP/S, routing, subnetting, public and private addressing, NAT/SNAT/DNAT, common ports and protocols, and packet-level investigation.
- Deep familiarity with common cyberattacks, attacker techniques, indicators of compromise, likely impact, and effective containment, eradication, recovery, and remediation steps.
- Advanced experience analyzing security logs and network traffic from diverse sources and distinguishing malicious activity from benign anomalies.
- Strong working knowledge of Windows, Linux, Active Directory, authentication activity, endpoint telemetry, and cloud security concepts.
- Experience with SIEM platforms, IDS/IPS technologies, EDR tools, packet analysis tools, vulnerability information, and case management workflows.
- Ability to interpret and preferably develop or tune detection content, such as Snort, Suricata, YARA, SIEM queries, vendor rules, or alert logic.
- Excellent written and verbal communication skills, including the ability to speak confidently and eloquently with clients about technical security topics, risk, and remediation.
- Demonstrated ability to mentor analysts, provide constructive review, and make defensible decisions under time pressure with minimal supervision.
- Ability to work Monday – Friday 9 am – 6 pm ET and participate in the rotating on-call schedule.
Preferred Qualifications
- Experience in a managed security service provider or multi-client SOC environment.
- Hands-on threat hunting, malware triage, digital forensics, cloud investigation, or detection engineering experience.
- Practical scripting or automation experience with Python, PowerShell, Bash, or similar languages.
- Experience with AWS and cloud-native security telemetry.
- Relevant certifications such as BTL2, GCIH, GCIA, GCFA, CySA+, CISSP, or comparable practical credentials.
- A demonstrated commitment to continuous learning through labs, research, technical writing, community involvement, or independent projects.