CareerPlanSign in

Cyber Threat Detection & Response Analyst

USA, VA, Richmond💼 Full-time🗓 2026-08-04 → 2026-09-29

Core

Implement detection engineering and response enablement solutions for security monitoring, including log normalization, rule tuning, and incident support.

Role type

Cyber Threat Detection & Response Analyst (SOC/CSIRT support)

Builds

Detection rules, alert triage workflows, and response playbooks for SIEM/EDR/XDR platforms

Domain

Cybersecurity, Security Operations Center (SOC), Threat Detection

Required skills

SIEM/EDR/XDR/IDS/IPS management, log telemetry collection and normalization, detection rule creation and tuning, incident response support, automation/orchestration (SOAR), basic scripting (Python/PowerShell/Bash), cloud logging (AWS/Azure/GCP), Windows/Linux troubleshooting, security frameworks (NIST/CIS)

Preferred skills

MITRE ATT&CK fundamentals, cloud security certifications (GCP, GIAC), advanced query languages (SPL/KQL)

Technologies

SIEM, EDR, XDR, SOAR, MITRE ATT&CK, AWS, Azure, GCP, Python, PowerShell, Bash, NIST, CIS Benchmarks

Responsibilities

Implement and maintain log/telemetry collection for security monitoring; Support SIEM and related detection platforms by onboarding data sources and maintaining platform health; Create, implement, and tune detection rules and alerts; Support alert triage and incident response by collecting logs/evidence and coordinating engineering fixes; Assist with automation and orchestration use cases (SOAR/playbooks); Develop and execute test plans for detections and response workflows

Seniority

Mid-level, hands-on IC

Sourced via workday · Listed on CareerPlan, which tracks 854,000+ jobs from 20+ sources.