Senior Cyber Threat Analyst

Posted Yesterday
Be an Early Applicant
Hiring Remotely in United States
Remote
80K-85K Annually
Senior level
Information Technology • Cybersecurity
We manage your technology and mitigate your cyber risk - so you don’t have to.
The Role
Lead SOC investigations and incident response, triage and analyze telemetry across SIEM/EDR/IDS/packet data, mentor junior analysts, tune detections, communicate findings and remediation to clients, and participate in rotating on-call duties to ensure timely, accurate security operations.
Summary Generated by Built In

Harbor IT is a security-led managed services provider built for critical, complex environments. We secure, operate, and scale IT for organizations where uptime, security, and compliance are mission-critical, backed by an in-house engineering team and a 24/7/365 US-based Security Operations Center. Security has been our foundation since day one, embedded into every layer of how we manage IT, cyber, AI, and cloud rather than bolted on as an add-on.  

Our tier-less SOC, deep vertical expertise, and proprietary Sagan detection engine gives clients fast detection, low false positives, and a high-touch response model. That combination makes Harbor IT a clear choice for managing security in environments where failure is not an option 

The Senior Cyber Threat Analyst is an experienced SOC practitioner who independently investigates complex security events, guides incidents through the response lifecycle, and communicates clearly with both technical and non-technical client stakeholders. This role serves as the first point of escalation for junior analysts who need a second set of eyes, assistance with analysis, or guidance on alert tuning, documentation, and response decisions.

The ideal candidate combines deep knowledge of networking, common attack techniques, security telemetry, and remediation practices with the professionalism to explain risks, findings, and recommended actions to clients. The role reports to the SOC Manager and partners closely with SOC analysts, engineering, security operations, reporting teams, and client contacts.

Key Responsibilities

  • Monitor, triage, investigate, and resolve security events and incidents within established client service-level agreements.
  • Perform advanced analysis across SIEM, EDR, IDS/IPS, firewall, DNS, identity, cloud, operating system, application, and database telemetry.
  • Lead or support incidents through the full incident response lifecycle, including preparation, identification, analysis, containment, eradication, recovery, and post-incident improvement.
  • Correlate network, endpoint, identity, and log evidence to determine attack scope, impact, root cause, and recommended remediation.
  • Recognize common attack techniques and provide practical containment and remediation guidance appropriate to the affected environment.
  • Serve as the first escalation point for junior analysts, providing a second review of investigations, validating conclusions, and coaching analysts through complex decisions.
  • Advise on alert tuning, detection quality, false-positive reduction, rule logic, thresholds, suppression criteria, and documentation improvements with the Detection Engineering Team.
  • Communicate directly and professionally with clients by telephone, email, and meetings, clearly explaining security findings, risk, business impact, response options, and next steps.
  • Escalate high-severity or high-impact incidents according to process and exercise sound judgment when available data is incomplete.
  • Create and improve investigation notes, client-facing incident communications, detection logic, procedures, and knowledge-base content.
  • Remain current on threat actor behavior, vulnerabilities, exploits, defensive techniques, and relevant changes in the threat landscape.
  • Participate in a rotating on-call schedule of two weeks on call followed by four weeks off. Employees receive an additional 10% compensation during scheduled on-call periods.
  • Serve as a voice of authority during the SOC Manager’s absence.

Required Qualifications

  • 3+ years of relevant cybersecurity experience, including hands-on experience in a SOC, incident response, threat detection, managed security, or closely related operational role.
  • Deep familiarity with networking fundamentals and traffic analysis, including TCP/IP, DNS, HTTP/S, routing, subnetting, public and private addressing, NAT/SNAT/DNAT, common ports and protocols, and packet-level investigation.
  • Deep familiarity with common cyberattacks, attacker techniques, indicators of compromise, likely impact, and effective containment, eradication, recovery, and remediation steps.
  • Deep familiarity with incident response lifecycles and the ability to apply them consistently during real-world investigations.
  • Advanced experience analyzing security logs and network traffic from diverse sources and distinguishing malicious activity from benign anomalies.
  • Strong working knowledge of Windows, Linux, Active Directory, authentication activity, endpoint telemetry, and cloud security concepts.
  • Experience with SIEM platforms, IDS/IPS technologies, EDR tools, packet analysis tools, vulnerability information, and case management workflows.
  • Ability to interpret and preferably develop or tune detection content, such as Snort, Suricata, YARA, SIEM queries, vendor rules, or alert logic.
  • Excellent written and verbal communication skills, including the ability to speak confidently and eloquently with clients about technical security topics, risk, and remediation.
  • Demonstrated ability to mentor analysts, provide constructive review, and make defensible decisions under time pressure with minimal supervision.
  • Ability to work Monday – Friday 9 am – 6 pm ET and participate in the rotating on-call schedule.
  • U.S. Work Authorization (Harbor IT is unable to provide visa sponsorship for this role.)

Preferred Qualifications

  • Experience in a managed security service provider or multi-client SOC environment.
  • Hands-on threat hunting, malware triage, digital forensics, cloud investigation, or detection engineering experience.
  • Practical scripting or automation experience with Python, PowerShell, Bash, or similar languages.
  • Experience with AWS and cloud-native security telemetry.
  • Relevant certifications such as BTL2, GCIH, GCIA, GCFA, CySA+, CISSP, or comparable practical credentials.
  • A demonstrated commitment to continuous learning through labs, research, technical writing, community involvement, or independent projects. 


Tools and Technologies

  • SIEM and log analysis platforms; IDS/IPS and packet inspection technologies
  • Snort, Suricata, Wireshark.
  • EDRs such as SentinelOne, Crowdstrike, and Microsoft Defender for Endpoint
  • Linux CLI; Windows; Active Directory; AWS
  • Firewalls, DNS, endpoint and identity telemetry, vulnerability data, and OSINT resources
  • Bash, PowerShell, Python, or other scripting and automation tools (basic level)

Success in This Role

  • Produces timely, accurate, well-supported investigations and meets client service commitments.
  • Gives clients clear, actionable guidance while representing Harbor IT with confidence and professionalism.
  • Improves analyst decision quality by providing accessible escalation support and thoughtful coaching.
  • Identifies opportunities to tune detections, strengthen documentation, and improve SOC efficiency without reducing security coverage.
  • Exercises ownership, sound judgment, attention to detail, and consistent follow-through during routine and high-pressure situations.

What We Provide

  • Clear performance metrics and opportunities to influence how the SOC operates
  • 100% employer-paid employee benefits, with additional premium selections available
  • 401(k) matching
  • Reimbursement for approved tuition, certifications, conference attendance, and related professional development
  • Harbor IT-approved holidays, when applicable
  • A culture that supports employees in putting family first
  • Additional benefits based on position and eligibility

Training and Schedule

Initial training may last up to eight weeks. Because the SOC operates 24/7/365, schedule flexibility may occasionally be required to support coverage, training, or critical incidents.

Equal Opportunity

Harbor IT Information Security is committed to building a collaborative workplace and considers qualified applicants based on job-related skills, experience, and business needs.

Skills Required

  • 3+ years of relevant cybersecurity experience in a SOC, incident response, threat detection, managed security, or closely related operational role
  • Deep familiarity with networking fundamentals and traffic analysis (TCP/IP, DNS, HTTP/S, routing, subnetting, NAT, common ports, packet-level investigation)
  • Deep familiarity with common cyberattacks, attacker techniques, indicators of compromise, and remediation practices
  • Deep familiarity with incident response lifecycles and ability to apply them during investigations
  • Advanced experience analyzing security logs and network traffic from diverse sources and distinguishing malicious from benign activity
  • Strong working knowledge of Windows, Linux, Active Directory, authentication activity, endpoint telemetry, and cloud security concepts
  • Experience with SIEM platforms, IDS/IPS technologies, EDR tools, packet analysis tools, vulnerability information, and case management workflows
  • Ability to interpret and preferably develop or tune detection content (Snort, Suricata, YARA, SIEM queries, vendor rules, alert logic)
  • Excellent written and verbal communication skills to explain risks, findings, and remediation to technical and non-technical clients
  • Demonstrated ability to mentor analysts, provide constructive review, and make defensible decisions under time pressure
  • Ability to work Monday - Friday 9 am - 6 pm ET and participate in a rotating on-call schedule (two weeks on, four weeks off)
  • U.S. citizenship (employer unable to provide visa sponsorship)
  • Experience in a managed security service provider or multi-client SOC environment
  • Hands-on threat hunting, malware triage, digital forensics, cloud investigation, or detection engineering experience
  • Practical scripting or automation experience with Python, PowerShell, Bash, or similar languages
  • Experience with AWS and cloud-native security telemetry
  • Relevant certifications such as BTL2, GCIH, GCIA, GCFA, CySA+, CISSP, or comparable practical credentials
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Campinas
162 Employees
Year Founded: 1995

What We Do

We are not merely a provider that handles firewalls and answers calls. We are your dedicated IT partner, with our origins deeply rooted in cybersecurity. Just as our proprietary code is seamlessly integrated into our SIEM, cybersecurity is ingrained in our very DNA, setting us apart from our competitors. Our journey began as a cybersecurity firm, and this foundation continues to influence every aspect of our operations. Our holistic approach ensures that we are deeply attuned to your business requirements. We leverage cutting-edge technology and proactively shore up risks to drive your success. By understanding your unique needs and challenges, we offer comprehensive solutions that align with your strategic goals. Our commitment goes beyond the basics, empowering your organization to thrive in a secure digital landscape. How We’re Different - Beyond IT Support - Communication & Consistency for Quality - Efficiency for Impact

Similar Jobs

DFIN Logo DFIN

Sr Cyber Threat Analyst

Fintech • Software
Remote or Hybrid
United States
1750 Employees

GitLab Logo GitLab

Project Manager

Cloud • Security • Software • Cybersecurity • Automation
Easy Apply
Remote
United States
2500 Employees

GitLab Logo GitLab

Senior Professional Services Engineer - EMEA

Cloud • Security • Software • Cybersecurity • Automation
Easy Apply
Remote
United States
2500 Employees

HiBob Logo HiBob

Customer Experience Process Specialist- Payroll & Partners

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
United States
1350 Employees
119K-145K Annually

Similar Companies Hiring

Scrunch  Thumbnail
Artificial Intelligence • Information Technology • Marketing Tech • Software • SEO
Salt Lake City, Utah
Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account