Senior Cyber Threat Analyst

Posted 4 Hours Ago
Be an Early Applicant
Hiring Remotely in USA
Remote
110K-164K Annually
Senior level
Insurance
The Role
Lead ransomware and cyber extortion communications and negotiation support, conduct adversary and malware analysis, provide threat intelligence to incident response teams, mentor junior analysts, improve workflows, and collaborate with DFIR, legal, insurance, and client teams to drive case strategy and outcomes.
Summary Generated by Built In
  • Job Title: Senior Cyber Threat Analyst
    Location: Remote, USA 
    Reports to: Managing Director
    Employment Type: Full time
    Job Req ID: 2026
    Req Begin Date: 8/10/2026
    About Vector3
    Vector3, Inc., is an incident response firm supporting TMHCC Cyber and Professional Lines Group (CPLG). Vector3 specializes in responding to Business Email Compromise (BEC) and Ransomware incidents, helping insured organizations investigate, contain, and recover from cyber events.
    About TMHCC
    Tokio Marine HCC (TMHCC) brings 50 years of service to the specialty insurance industry, today offering over 100 products to commercial customers in 180 countries around the world. Every policy we write is special, enabling our clients to do amazing things. From insuring the crops that feed us to the rock concerts that entertain us, to rescuing international travelers in trouble.
    Organic growth and over 60 successful acquisitions have grown our 2023 Gross Written Premium (GWP) to over $7.5 Billion. Our workforce has grown to 4,300 worldwide … big, but not so big that you cannot make a difference. Our Good Company values, including integrity, empowerment, and commitment to customer service, and a culture of innovation, communication, and collaboration make TMHCC a great place to work.

    What We Offer

    • Competitive salary and employee benefit package
    • Strong learning culture
    • Growth perspectives
    • 6% 401K match
    • 20 days of PTO and 2 Floating Days
    • Paid parental leave
    • An opportunity to love what you do

    Job Summary

    Join us in shaping the future of TMHCC-CPLG as a key contributor in our cyber extortion and threat intelligence function, Vector3. You will lead threat actor communications and negotiation support for ransomware and cyber extortion engagements, helping shape case strategy through direct communication, disciplined documentation, and sound judgment. You will also leverage advanced analytical skills to understand threat actors, campaigns, tactics, techniques, and procedures, while providing intelligence support that strengthens incident response and case outcomes.

    You will work closely with your team and engagement leads to turn direct communications and threat activity into actionable support that helps the organization anticipate, understand, and respond to adversaries.

    Key Responsibilities

    Relying on extensive security knowledge and advanced technical expertise, this role is accountable for the following responsibilities

    Relying on advanced knowledge and strong leadership skills, this role is accountable for the following responsibilities:

    Threat Actor Communications and Negotiation Leadership:

    • Lead written communications and negotiation support for ransomware and cyber extortion engagements under the direction of counsel.
    • Develop communication strategy, draft response language, and maintain disciplined negotiation records that support case objectives.
    • Track demands, deadlines, concessions, proof-of-possession requests, and actor behavior to help the engagement team assess leverage and next steps.
    • Review and refine communications prepared by junior analysts to ensure they are clear, professional, accurate, and aligned with case strategy.

    Threat Intelligence and Adversary Analysis:

    • Research, analyze, and track threat actors, extortion groups, malware families, campaigns, and emerging adversary infrastructure.
    • Correlate communications, indicators, and intelligence to identify patterns in actor behavior, tactics, techniques, and procedures.
    • Provide intelligence support to active investigations and time-sensitive events so response teams can make informed decisions.
    • Maintain actor profiles, negotiation notes, intelligence artifacts, and reference material in approved repositories.

    Team Leadership and Process Improvement:

    • Mentor junior analysts and help establish consistent standards for negotiation support, documentation, and intelligence reporting.
    • Improve communication workflows, intelligence collection, validation, and dissemination processes for scale and repeatability.
    • Collaborate with DFIR, legal, insurance, and client-facing teams to ensure communications are timely, relevant, and actionable.

    Competencies

    Planning

    • Contribute to the development of both short-term and long-term plans for designated area of the organization.

    Technical Excellence

    • Experience leading threat actor communications and producing intelligence products that inform decisions during active cyber incidents.
    • Write, or is a major contributor to, technical reports and documentation.
    • Analyze complex threat data and present findings in a clear and useful manner for multiple audiences.

    Cost Management

    • Develop innovative ways to improve financials.

    Business Controls and Policies

    • Comply with all corporate policies and procedures.

    Education

    Minimum 4 Year's bachelor's degree in cyber security, Computer Science, Information Technology related degree.

    Certifications, Licenses, and Designations

    Preferred advanced degrees or certifications (CISSP, CISM, GCFE, GCFA, GREM, GBFA, GCIH, CFCE, CCE) are a plus

    Experience

    4+ years of professional experience in cyber incident response, threat intelligence, negotiations, investigations, or related analytical work.

    Other

    • Experience leading threat actor communications in ransomware or cyber extortion cases.
    • Strong writing and presentation skills with the ability to communicate clearly under pressure.
    • Ability to manage multiple complex matters simultaneously and respond to urgent requests.
    • Familiarity with threat actor behavior, TTPs, malware families, and campaign activity using open-source and commercial intelligence sources.
  • Additional Job Description

    Pay Transparency
    The pay range for this position is $109,500-$164,300 which includes geographic adjustments, where applicable. The pay range is the range THMCC, in good faith, believes is the range of compensation for this role at the time of this posting. The hired applicant will be offered pay within the entire range based on the candidate’s geographic location, qualifications, work experience, education, and/or skill level. The Company is fully committed to ensuring equal pay opportunities for equal work regardless of color, race, sex, national origin, sexual orientation, religion, age, veteran status, disability, pregnancy, citizenship status, genetic information, or any other basis protected by federal, state, or local pay equity laws.
    California → Use CA Fair Chance language.
    The Company will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable federal, state and local laws, such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC

    • 1033(e))(the “VCCLEA”), which restricts financial institutions and insurers such as TMHCC from employing individuals with certain types of criminal convictions. Where the hiring and employment of individuals is not restricted by the foregoing, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law such as the California Fair Chance Act, the Los Angeles Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance, the San Diego Fair Chance Ordinance, and the San Francisco Fair Chance Ordinance.]

    As an insurance company, we comply with certain federal, state and local laws such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC

    • 1033(e)), which restricts our ability to employ individuals with certain types of criminal convictions. Where not restricted by law and for criminal history not covered by this law, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law.

    You do not need to disclose your criminal history or participate in a background check until a conditional job offer is made to you. After making a conditional offer and running a background check, if the Company is concerned about a conviction that is directly related to the job, you will be given the chance to explain the circumstances surrounding the conviction or challenge the accuracy of the background report. The Company will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable federal, state and local laws, such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC

    • 1033(e))(the “VCCLEA”), which restricts financial institutions and insurers such as TMHCC from employing individuals with certain types of criminal convictions. Where the hiring and employment of individuals is not restricted by the foregoing, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law such as the California Fair Chance Act, the Los Angeles Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance, the San Diego Fair Chance Ordinance, and the San Francisco Fair Chance Ordinance.]

    Applying our Mind Over Risk philosophy to writing insurance allows our customers to take on opportunity with confidence. That philosophy defines our way of thinking, unites us as a team, and differentiates us from our competitors. We are much more than just an insurance company; we are a good company.
    Equal Opportunity Employer
    TMHCC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity, genetic information, marital status, medical condition, national origin, physical or mental disability, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances.
    #CPLG1

    #VA-LI

Skills Required

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology or related field
  • 4+ years professional experience in cyber incident response, threat intelligence, negotiations, or investigations
  • Experience leading threat actor communications and negotiations in ransomware or cyber extortion cases
  • Advanced knowledge of threat intelligence, malware families, tactics, techniques, and procedures (TTPs)
  • Strong writing and presentation skills with ability to communicate clearly under pressure
  • Ability to manage multiple complex matters simultaneously and respond to urgent requests
  • Experience collaborating with DFIR, legal, insurance, and client-facing teams
  • Maintain actor profiles, negotiation records, and intelligence artifacts in approved repositories
  • Familiarity with open-source and commercial intelligence sources for adversary analysis
  • Mentoring junior analysts and improving communication and intelligence workflows
  • Preferred certifications: CISSP, CISM, GCFE, GCFA, GREM, GBFA, GCIH, CFCE, CCE

Tokio Marine Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Tokio Marine and has not been reviewed or approved by Tokio Marine.

  • Healthcare Strength Medical options include established carriers with PPO and HDHP choices, plus dental, vision, pharmacy, telehealth, and condition‑specific programs for comprehensive access. An employee assistance program and mental‑wellbeing resources further reinforce day‑to‑day support.
  • Retirement Support A 401(k) with company match and employer‑paid life and disability coverage strengthen long‑term financial security. Careers materials and recent updates signal continued attention to retirement and protection benefits.
  • Wellbeing & Lifestyle Benefits Wellness incentives, fitness access, and a holistic “body, mind, wallet, life” framework expand total‑rewards value beyond insurance alone. Paid volunteer time and community programs add lifestyle‑oriented benefits aligned with purpose.

Tokio Marine Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Houston, Texas
2,600 Employees

What We Do

Tokio Marine HCC can help you or your clients be prepared for unpredictable weather patterns. Event weather insurance protects revenue losses caused by adverse weather conditions that reduce attendance and the sales of concessions, food and parking.

Similar Jobs

DFIN Logo DFIN

Sr Cyber Threat Analyst

Fintech • Software
Remote or Hybrid
United States
1750 Employees

Zscaler Logo Zscaler

Principal AI Security Specialist - Central

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
4 Locations
8697 Employees
176K-251K Annually

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sales Associate II

eCommerce • Fashion • Retail • Sales • Wearables • Design
Remote or Hybrid
Mississippi, USA
16000 Employees
15-20 Hourly

General Motors Logo General Motors

Staff Software Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
Sunnyvale, CA, USA
165000 Employees
185K-284K Annually

Similar Companies Hiring

Globe Life Thumbnail
Insurance • Financial Services
McKinney, TX
3000 Employees
MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account