McKesson
Cyber Threat Detection & Response Analyst
USA, VA, Richmond · Internship
Sponsorship not specifiedDetected 22 days ago
PythonBashPowerShellAWSGCPAzureCloud PlatformsLinuxDevOpsCybersecuritySIEMKQLSOARSOC OperationsDetection EngineeringIncident ResponseFirewallResearchLeadershipCommunicationCollaborationAdaptabilityOrganizational Skills
About the role
- The Cybersecurity Threat Detection & Response (TDR) Analyst is responsible for implementing and supporting detection engineering and response enablement solutions.
Responsibilities
- Implement and maintain log/telemetry collection for security monitoring (endpoints, network devices, cloud services, identity systems, and applications) following documented standards and change-management procedures.
- Create, implement, and tune detection rules and alerts (SIEM/EDR/XDR) to improve fidelity and reduce noise
- document logic, assumptions, and expected outcomes.
- Support alert triage and incident response by collecting logs/evidence, assisting with containment/eradication tasks, and coordinating engineering fixes (e.g., telemetry gaps, detection improvements) as directed.
- test and validate playbook changes in partnership with SOC/IR.
- Develop and execute test plans for detections and response workflows (use-case testing, regression checks)
- Work with security operations, infrastructure, and application teams to resolve telemetry issues, implement secure logging configurations, and support remediation of security findings.
- Perform other duties as assigned.
- Create, implement, and tune detection rules and alerts (SIEM/EDR/XDR) to improve fidelity and reduce noise; document logic, assumptions, and expected outcomes.
- Assist with automation and orchestration use cases (SOAR/playbooks) to streamline repetitive response tasks; test and validate playbook changes in partnership with SOC/IR.
Requirements
- Degree or equivalent and typically requires 4+ years of relevant experience
- 4+ years of experience in cybersecurity and/or IT operations with exposure to security monitoring, detection engineering, incident response, or SOC-supporting engineering (internship/co-op experience
- Experience supporting or implementing monitoring/detection tooling such as SIEM, EDR, IDS/IPS, logging agents/collectors, or vulnerability scanners
- Working knowledge of security monitoring technologies such as SIEM, EDR/XDR, IDS/IPS, firewalls, and threat intelligence feeds
- familiarity with ticketing/case management workflows.
- Experience onboarding or supporting log sources and telemetry pipelines (e.g., Windows/Linux logs, network device logs, cloud logs) including basic parsing/normalization concepts.
- Familiarity with one or more cloud platforms (AWS, Azure, or GCP) and cloud logging/monitoring concepts (IAM signals, audit logs, flow logs, and service logs).
- Familiarity with security frameworks and standards (e.g., NIST, CIS Benchmarks) and the importance of adhering to security policies and standard operating procedures.
- Bachelor's degree in computer science, information security/assurance, MIS, engineering, or related field
Nice to have
- Google Cloud Professional Cloud Security Engineer and/or Associate Cloud Engineer, Google Professional Cloud DevOps Engineer, and/or GIAC certifications (e.g., GSEC, GCIH) depending on role focus.
- Alternate Care markets are growing rapidly and MMS is proud to be a leader in this space.
- Security+, SSCP, or equivalent foundational security certification.
- Track record of acting with integrity, being curious and adaptable, and continuously improving technical skills
- familiarity with basic adversary concepts (e.g., MITRE ATT&CK, kill chain fundamentals) is a plus.
Compensation
- We will also continue to be one of the largest medical-surgical distributors in the U.S., with over $11B in annual sales.
Benefits
- McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare.
- Here, we focus on the health, happiness, and well-being of you and those we serve - we care.
- Together, we thrive as we shape the future of health for patients, our communities, and our people.
- If you want to be part of tomorrow's health today, we want to hear from you.
- Support SIEM and related detection platforms by onboarding data sources, validating parsing/normalization, maintaining data integrity, and monitoring platform health and capacity.
- Develop and execute test plans for detections and response workflows (use-case testing, regression checks); identify gaps and recommend enhancements to improve coverage and reliability.
Company info
- We are known for delivering insights, products, and services that make quality care more accessible and affordable.
Equal opportunity
- Equal Opportunity Employer
Apply directly at McKesson →Create a free account for alerts like thisView McKesson immigration profile
This listing is sourced directly from McKesson's careers page and normalized into a canonical job model.