Cyber Defense Analyst

Posted 7 Days Ago
Hiring Remotely in USA
Remote
145K-170K Annually
Mid level
Security • Cybersecurity
The Role
The Cyber Defense Analyst is responsible for monitoring, investigating, and responding to security alerts, leading incident response, and improving automation in a hybrid environment.
Summary Generated by Built In
About the Role

We at Abnormal AI are  looking for a hands-on Security Operations/ Cyber Defense Analyst who thrives in a fast-paced, engineering-driven environment. You’ll be responsible for monitoring, investigating, and responding to security alerts across cloud, endpoint, identity, and application layers. You’ll work closely with detection engineers, cloud security, and IT teams to protect our hybrid environment from threats in real time.

This is not a “click-through-the-console” SOC role — we’re looking for someone who can think critically, automate relentlessly, and own incidents end-to-end.

Key Responsibilities
  • Detection & Triage:
    • Monitor alerts from tools like SIEM, EDR, IAM, CSPM, CDR etc.
    • Perform initial triage, enrichment, and correlation across multiple data sources.
    • Identify false positives and fine-tune rules with detection engineering.
  • Incident Response:
    • Lead containment, eradication, and recovery for endpoint, cloud, and identity incidents.
    • Document and communicate incidents through SOAR/Jira/ServiceNow workflows.
    • Perform root cause analysis and propose permanent preventive controls.
  • Threat Hunting & Analysis:
    • Proactively hunt using hypotheses mapped to MITRE ATT&CK.
    • Investigate anomalies across CloudTrail, Okta, GitHub, and other telemetry sources.
    • Collaborate with threat intelligence to identify emerging TTPs.
  • Automation & Process Improvement:
    • Build or enhance playbooks in SOAR (Torq or equivalent).
    • Create custom enrichment scripts and automations (Python, Bash, etc.).
    • Suggest new detection logic and operational improvements.
  • Reporting & Metrics:
    • Track and report operational metrics (MTTD, MTTR, incident categories).
    • Maintain documentation and lessons learned.
Required Skills & Qualifications
  • 5-7 years of hands-on SOC or Incident Response experience in a cloud-first or hybrid environment.
  • Strong understanding of attacker lifecycle, MITRE ATT&CK, and threat actor TTPs.
  • Experience with EDR (CrowdStrike preferred), SIEM (Splunk preferred), and SOAR (Torq, XSOAR, or Phantom).
  • Familiarity with AWS, Okta, and SaaS platforms.
  • Proficiency in writing queries and automations using Python, SPL, or equivalent.
  • Excellent analytical and investigative skills — capable of operating independently with minimal hand-holding.
  • Strong documentation and communication skills for technical and executive audiences.
Nice to Have
  • Experience with CSPM/CDR/VM tools.
  • Knowledge of Containers and Kubernetes security.
  • Relevant certifications like CEH, Security+, GCIH, GCIA, or AWS Security Specialty.
What Success Looks Like
  • You consistently deliver high-quality triage with minimal false positives.
  • You automate repetitive tasks instead of manually doing them twice.
  • You can take a vague alert and turn it into a well-documented case with actionable findings.

#LI-EM5

  • You make measurable improvements to detection coverage, response time, or tooling maturity.

At Abnormal AI, certain roles are eligible for a bonus, restricted stock units (RSUs), and benefits. Individual compensation packages are based on factors unique to each candidate, including their skills, experience, qualifications and other job-related reasons. 

Base salary range:
$144,500$170,000 USD

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

Top Skills

AWS
Bash
Cdr
Cspm
Edr
Git
Okta
Python
SIEM
Soar
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
San Francisco, CA
175 Employees
Year Founded: 2018

What We Do

The Abnormal Security platform protects enterprises from targeted email attacks. Abnormal Behavior Technology (ABX) models the identity of both employees and external senders, profiles relationships and analyzes email content to stop attacks that lead to account takeover, financial damage and organizational mistrust. Though one-click, API-based Office 365 and G Suite integration, Abnormal sets up in minutes and does not disrupt email flow.
Abnormal Security was founded in 2018 by CEO Evan Reiser, CTO Sanjay Jeyakumar, Head of Machine Learning Jeshua Bratman, and Founding Engineers Abhijit Bagri and Dmitry Chechik. The team previously built behavioral profiling and machine learning technologies at Twitter, Google and Pinterest that are being applied to solve a problem that costs organizations $1 billion per year, according to the FBI. The Abnormal Security platform stops targeted phishing, business email compromise and account takeover attacks that have never been seen before.

Similar Jobs

Experian Logo Experian

Lead Cyber Defense Analyst - Remote

Big Data • Marketing Tech • Analytics
Remote
United States
16292 Employees

Mondelēz International Logo Mondelēz International

Senior Manager Supply Chain Excellence (TPM Regional Manager / Manufacturing Excellence)

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
6 Locations
90000 Employees
137K-189K Annually

UL Solutions Logo UL Solutions

Sales Executive

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Remote or Hybrid
Chicago, IL, USA
15000 Employees
65K-113K Annually

UL Solutions Logo UL Solutions

Senior Sales Executive

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Remote or Hybrid
6 Locations
15000 Employees
105K-250K Annually

Similar Companies Hiring

Silverfort Thumbnail
Security • Sales • Information Technology • Cybersecurity • Automation
GB
507 Employees
Oso Thumbnail
Software • Security • Infrastructure as a Service (IaaS)
New York, New York
36 Employees
Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account