Cyber Threat Detection & Response Analyst
Core
Implement detection engineering and response enablement solutions for security monitoring, including log normalization, rule tuning, and incident support.
Role type
Cyber Threat Detection & Response Analyst (SOC/CSIRT support)
Builds
Detection rules, alert triage workflows, and response playbooks for SIEM/EDR/XDR platforms
Domain
Cybersecurity, Security Operations Center (SOC), Threat Detection
Required skills
SIEM/EDR/XDR/IDS/IPS management, log telemetry collection and normalization, detection rule creation and tuning, incident response support, automation/orchestration (SOAR), basic scripting (Python/PowerShell/Bash), cloud logging (AWS/Azure/GCP), Windows/Linux troubleshooting, security frameworks (NIST/CIS)
Preferred skills
MITRE ATT&CK fundamentals, cloud security certifications (GCP, GIAC), advanced query languages (SPL/KQL)
Technologies
SIEM, EDR, XDR, SOAR, MITRE ATT&CK, AWS, Azure, GCP, Python, PowerShell, Bash, NIST, CIS Benchmarks
Responsibilities
Implement and maintain log/telemetry collection for security monitoring; Support SIEM and related detection platforms by onboarding data sources and maintaining platform health; Create, implement, and tune detection rules and alerts; Support alert triage and incident response by collecting logs/evidence and coordinating engineering fixes; Assist with automation and orchestration use cases (SOAR/playbooks); Develop and execute test plans for detections and response workflows
Seniority
Mid-level, hands-on IC