Strategic Services Analyst
DeepSeas · San Jose, CA · 2 days ago
RemoteRemoteOTHRFull-time
About the role
The Strategic Services Analyst plays a critical role in DeepSeas' Threat Management practice, serving as a client-facing subject matter expert who bridges hands-on SIEM engineering with strategic security advisory. This role involves partnering directly with client stakeholders to mature their detection and response capabilities, providing strategic guidance, and maintaining strong client relationships.
Responsibilities
- Serve as the primary strategic point of contact for assigned clients, building trusted-advisor relationships with client security stakeholders.
- Design, develop, and tune detection logic and use cases within client SIEM platforms, closing detection gaps identified through Cyber Threat Intelligence review.
- Lead regular briefings with client leadership on detection coverage, incident trends, and overall program maturity.
- Develop and refine incident response playbooks and procedures in partnership with client security teams.
- Conduct threat-hunting activities across client SIEM and EDR data to proactively surface sophisticated adversary activity.
- Use frameworks such as MITRE ATT&CK to assess detection coverage and categorize threat actor TTPs for client audiences.
- Partner with the SOC and internal Detection Engineering teams on escalations, ensuring client-specific detection content stays current.
- Generate and present metrics and reporting on incident response activity, detection coverage, and program trends for client leadership.
- Provide guidance on malware and forensic findings, translating technical analysis into clear recommendations for client teams.
- Drive continuous improvement of clients' detection engineering and SIEM content, staying current on emerging threats and vulnerabilities.
Requirements
- 5+ years of experience in cybersecurity, including hands-on work with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar, Elastic).
- At least one year of experience in a SOC analyst or detection engineering role.
- Strong log analysis skills and previous experience writing or tuning detection logic.
- Working knowledge of MITRE ATT&CK and cloud-based technologies.
- Excellent client-facing communication skills, both written and verbal.
- Bachelor's degree in Cybersecurity, Computer Science, or related field, or equivalent practical experience.
- Familiarity with a variety of SIEM tools beyond your primary platform, plus proficiency in EDR and NDR tooling.
- Experience with threat hunting and data engineering.
- Knowledge of scripting languages such as Python, PowerShell, or Bash for automation and analysis.
- Prior experience in a client-facing advisory, consulting, or managed services role.
- Familiarity with regulations and standards such as HIPAA, GDPR, and NIST frameworks.
- Certifications such as GIAC Certified Incident Handler (GCIH), CISSP, CISM, CEH, or equivalent advanced security certifications.
Qualifications
- Understanding and following DeepSeas’s information security policies and procedures.
- Remaining vigilant and reporting any suspicious activity or possible weaknesses in DeepSeas’s information security.
- Actively participating in DeepSeas’s efforts to maintain and improve information security.
- Believing in the power of diversity.
Skills
- Knowledge of scripting languages such as Python, PowerShell, or Bash for automation and analysis.
- Experience with threat hunting and data engineering.
- Experience in a client-facing advisory, consulting, or managed services role.
- Familiarity with regulations and standards such as HIPAA, GDPR, and NIST frameworks.
- Certifications such as GIAC Certified Incident Handler (GCIH), CISSP, CISM, CEH, or equivalent advanced security certifications.
Benefits
- Heart rates go down, careers take off, and security programs mature.
- Stand in solidarity with our teammates.
- Prioritize personal health and well-being.
- Believe in the power of diversity.
- Solve hard problems at the speed of cyber.
Pay
Compensation is competitive and commensurate with experience.
Schedule
This is a full-time position.