Jobs · Information Technology

Senior Cyber Threat Analyst

Harbor IT · United States · 1 mo ago
RemoteRemoteInformation TechnologyFull-time

About the role

Harbor IT is a security-led managed services provider built for critical, complex environments. We secure, operate, and scale IT for organizations where uptime, security, and compliance are mission-critical, backed by an in-house engineering team and a 24/7/365 US-based Security Operations Center.

Responsibilities

  • Monitor, triage, investigate, and resolve security events and incidents within established client service-level agreements.
  • Perform advanced analysis across SIEM, EDR, IDS/IPS, firewall, DNS, identity, cloud, operating system, application, and database telemetry.
  • Lead or support incidents through the full incident response lifecycle, including preparation, identification, analysis, containment, eradication, recovery, and post-incident improvement.
  • Correlate network, endpoint, identity, and log evidence to determine attack scope, impact, root cause, and recommended remediation.
  • Recognize common attack techniques and provide practical containment and remediation guidance appropriate to the affected environment.
  • Serve as the first escalation point for junior analysts, providing a second review of investigations, validating conclusions, and coaching analysts through complex decisions.
  • Advise on alert tuning, detection quality, false-positive reduction, rule logic, thresholds, suppression criteria, and documentation improvements with the Detection Engineering Team.
  • Communicate directly and professionally with clients by telephone, email, and meetings, clearly explaining security findings, risk, business impact, response options, and next steps.
  • Escalate high-severity or high-impact incidents according to process and exercise sound judgment when available data is incomplete.
  • Create and improve investigation notes, client-facing incident communications, detection logic, procedures, and knowledge-base content.
  • Remain current on threat actor behavior, vulnerabilities, exploits, defensive techniques, and relevant changes in the threat landscape.
  • Participate in a rotating on-call schedule of two weeks on call followed by four weeks off. Employees receive an additional 10% compensation during scheduled on-call periods.
  • Serve as a voice of authority during the SOC Manager’s absence.

Qualifications

  • 3+ years of relevant cybersecurity experience, including hands-on experience in a SOC, incident response, threat detection, managed security, or closely related operational role.
  • Deep familiarity with networking fundamentals and traffic analysis, including TCP/IP, DNS, HTTP/S, routing, subnetting, public and private addressing, NAT/SNAT/DNAT, common ports and protocols, and packet-level investigation.
  • Deep familiarity with common cyberattacks, attacker techniques, indicators of compromise, likely impact, and effective containment, eradication, recovery, and remediation steps.
  • Advanced experience analyzing security logs and network traffic from diverse sources and distinguishing malicious activity from benign anomalies.
  • Strong working knowledge of Windows, Linux, Active Directory, authentication activity, endpoint telemetry, and cloud security concepts.
  • Experience with SIEM platforms, IDS/IPS technologies, EDR tools, packet analysis tools, vulnerability information, and case management workflows.
  • Ability to interpret and preferably develop or tune detection content, such as Snort, Suricata, YARA, SIEM queries, vendor rules, or alert logic.
  • Excellent written and verbal communication skills, including the ability to speak confidently and eloquently with clients about technical security topics, risk, and remediation.
  • Demonstrated ability to mentor analysts, provide constructive review, and make defensible decisions under time pressure with minimal supervision.
  • Ability to work Monday – Friday 9 am – 6 pm ET and participate in the rotating on-call schedule.

Preferred Qualifications

  • Experience in a managed security service provider or multi-client SOC environment.
  • Hands-on threat hunting, malware triage, digital forensics, cloud investigation, or detection engineering experience.
  • Practical scripting or automation experience with Python, PowerShell, Bash, or similar languages.
  • Experience with AWS and cloud-native security telemetry.
  • Relevant certifications such as BTL2, GCIH, GCIA, GCFA, CySA+, CISSP, or comparable practical credentials.
  • A demonstrated commitment to continuous learning through labs, research, technical writing, community involvement, or independent projects.

Similar jobs

Senior Cyber Threat Analyst

Valiant SolutionsWashington, DC· 1 mo ago
RemoteInformation Technology$120k–$140k/yrapply on careers-valiantsolutions.icims.com