Senior Cyber Threat Analyst
$110,000–$160,000 year
On-siteBoston, Massachusetts, United States or Philadelphia, Pennsylvania, United States
Job Summary
Produce and disseminate weekly, monthly, and quarterly cyber threat intelligence reports to internal stakeholders and senior leaders. Monitor open-source and vendor-provided threat data to identify emerging risks and develop proactive defense strategies. Enhance detection capabilities by supporting SOC procedures, incident response playbooks, and analyst decision trees. Analyze alert trends to build threat hunting strategies and develop threat actor profiles aligned with the MITRE ATT&CK framework. Conduct privileged access reviews across various platforms to identify anomalies and collaborate on insider risk initiatives. Plan and perform threat hunting activities by searching SIEM logs to identify undetected malicious activity. Collaborate with Red Team and Cyber Incident Management on assessments, penetration tests, and tabletop exercises.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field
- 5+ years of experience in Cyber Threat Intelligence, Security Operations, Incident Response, Threat Hunting, and/or related roles
- Significant relevant experience (e.g., military) in one or more of the above roles may be considered in lieu of a degree
- Familiarity with the Intelligence Cycle, Threat Intelligence Platforms, and the MITRE ATT&CK Framework
- Excellent collaboration and communication skills, particularly in high-stress situations
- Ability to produce products at the tactical, operational, and strategic level and to articulate findings and assessments effectively
- A desire to understand and maintain awareness of changes to the cyber threat and risk landscape, including related geopolitical risks that may impact our overall security posture
- Strong analytical skills and priority management
Desired Qualifications
- Master's degree in Cybersecurity, Computer Science, Information Technology, or related field
- Hands-on experience in two or more of the following areas: Security Operations, Incident Response, Cyber Threat Intelligence, Threat Hunting, Detection Engineering, Security Engineering, Insider Threat Analysis, Digital Forensics, All-Source Intelligence, Penetration Testing, Red Teaming, Network Security Management, Cyber Risk Management, Cloud Security, Vulnerability Management, Malware Analysis
- Experience in the financial services sector and familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NYDFS, FFIEC, NIST CSF, ISO 27001, SWIFT CSF, OWASP)
- Experience with threat hunting and developing custom detection rules using query languages (e.g., Splunk SPL, Microsoft KQL)
- Experience with perimeter, host, and identity defense and monitoring technologies such as EDR/AV, IDS/IPS, Firewalls, WAF, DLP, UEBA, email gateway, sandboxing, and other security tools and terminology
- Familiarity with risk scoring, threat analysis, threat hunting, and threat modeling techniques
- Experience with Microsoft Defender (MDE, MDI, Defender for Cloud Apps) and Purview Insider Risk Management
- Relevant certifications such as CISSP, GCIH, GSEC, GCTI, CTIA, CEH, Security+
- Experience with programming or scripting (Python, SQL, Powershell)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.