McKesson

McKesson

Cyber Threat Detection & Response Analyst

USA, VA, Richmond · Internship

Sponsorship not specifiedDetected 22 days ago
PythonBashPowerShellAWSGCPAzureCloud PlatformsLinuxDevOpsCybersecuritySIEMKQLSOARSOC OperationsDetection EngineeringIncident ResponseFirewallResearchLeadershipCommunicationCollaborationAdaptabilityOrganizational Skills

About the role

  • The Cybersecurity Threat Detection & Response (TDR) Analyst is responsible for implementing and supporting detection engineering and response enablement solutions.

Responsibilities

  • Implement and maintain log/telemetry collection for security monitoring (endpoints, network devices, cloud services, identity systems, and applications) following documented standards and change-management procedures.
  • Create, implement, and tune detection rules and alerts (SIEM/EDR/XDR) to improve fidelity and reduce noise
  • document logic, assumptions, and expected outcomes.
  • Support alert triage and incident response by collecting logs/evidence, assisting with containment/eradication tasks, and coordinating engineering fixes (e.g., telemetry gaps, detection improvements) as directed.
  • test and validate playbook changes in partnership with SOC/IR.
  • Develop and execute test plans for detections and response workflows (use-case testing, regression checks)
  • Work with security operations, infrastructure, and application teams to resolve telemetry issues, implement secure logging configurations, and support remediation of security findings.
  • Perform other duties as assigned.
  • Create, implement, and tune detection rules and alerts (SIEM/EDR/XDR) to improve fidelity and reduce noise; document logic, assumptions, and expected outcomes.
  • Assist with automation and orchestration use cases (SOAR/playbooks) to streamline repetitive response tasks; test and validate playbook changes in partnership with SOC/IR.

Requirements

  • Degree or equivalent and typically requires 4+ years of relevant experience
  • 4+ years of experience in cybersecurity and/or IT operations with exposure to security monitoring, detection engineering, incident response, or SOC-supporting engineering (internship/co-op experience
  • Experience supporting or implementing monitoring/detection tooling such as SIEM, EDR, IDS/IPS, logging agents/collectors, or vulnerability scanners
  • Working knowledge of security monitoring technologies such as SIEM, EDR/XDR, IDS/IPS, firewalls, and threat intelligence feeds
  • familiarity with ticketing/case management workflows.
  • Experience onboarding or supporting log sources and telemetry pipelines (e.g., Windows/Linux logs, network device logs, cloud logs) including basic parsing/normalization concepts.
  • Familiarity with one or more cloud platforms (AWS, Azure, or GCP) and cloud logging/monitoring concepts (IAM signals, audit logs, flow logs, and service logs).
  • Familiarity with security frameworks and standards (e.g., NIST, CIS Benchmarks) and the importance of adhering to security policies and standard operating procedures.
  • Bachelor's degree in computer science, information security/assurance, MIS, engineering, or related field

Nice to have

  • Google Cloud Professional Cloud Security Engineer and/or Associate Cloud Engineer, Google Professional Cloud DevOps Engineer, and/or GIAC certifications (e.g., GSEC, GCIH) depending on role focus.
  • Alternate Care markets are growing rapidly and MMS is proud to be a leader in this space.
  • Security+, SSCP, or equivalent foundational security certification.
  • Track record of acting with integrity, being curious and adaptable, and continuously improving technical skills
  • familiarity with basic adversary concepts (e.g., MITRE ATT&CK, kill chain fundamentals) is a plus.

Compensation

  • We will also continue to be one of the largest medical-surgical distributors in the U.S., with over $11B in annual sales.

Benefits

  • McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare.
  • Here, we focus on the health, happiness, and well-being of you and those we serve - we care.
  • Together, we thrive as we shape the future of health for patients, our communities, and our people.
  • If you want to be part of tomorrow's health today, we want to hear from you.
  • Support SIEM and related detection platforms by onboarding data sources, validating parsing/normalization, maintaining data integrity, and monitoring platform health and capacity.
  • Develop and execute test plans for detections and response workflows (use-case testing, regression checks); identify gaps and recommend enhancements to improve coverage and reliability.

Company info

  • We are known for delivering insights, products, and services that make quality care more accessible and affordable.

Equal opportunity

  • Equal Opportunity Employer

This listing is sourced directly from McKesson's careers page and normalized into a canonical job model.