Abnormal Security
Sr. Embedded Detection Analyst
Remote - USA · Senior
Sponsorship not specified$167k-$240kDetected 13 days ago
PythonSQLDatabricksData AnalysisCybersecuritySIEMSOC OperationsDetection EngineeringIncident ResponseAccount ManagementCustomer SuccessResearchCommunicationCollaborationProblem SolvingWritingCISSP
About the role
- Abnormal AI is looking for an Embedded Detection Analyst to join our Threat Intelligence team.
- You are highly motivated to understand what attackers are doing, why detections are behaving unexpectedly, and how to systematically improve customer outcomes.
Responsibilities
- Own detection performance outcomes for 3-5 strategic customer accounts, ensuring the AI engine maintains high efficacy aligned to each customer's risk tolerance and priorities.
- Perform incident triage and alert correlation to systematically diagnose why detections produce false positives or miss threats, using IOCs and TTPs.
- Design and implement detection tuning strategies based on customer-specific signals, attack patterns, threat intelligence, and behavioral characteristics, following established methodologies.
- Maintain close alignment with Sales and Customer Success leads to understand customer pain points, renewal risks, and what matters most for securing deals, without taking on primary account management responsibilities.
- Support training of other team members by sharing investigation insights and developing repeatable methodologies, including leveraging outputs from Email Security Analysts to scale tuning impact.
Requirements
- 7+ years of experience in SOC operations, detection engineering, incident response, email security analysis, or related cybersecurity role.
- Demonstrated proficiency with AI tools (ChatGPT, Claude, Claude Code, Copilot, or similar) to enhance productivity, automate tasks, and accelerate problem-solving in both routine workflows and ad-hoc investigations.
- The ideal candidate will bring SOC or security operations experience, strong analytical skills, hypothesis-driven investigation approaches, and the ability to work systematically with established tools and processes.
Nice to have
- Background in email security, phishing detection, anti-abuse systems, spam analysis, or email threat containment.
- Familiarity with Python, data analysis scripting, or notebook environments (e.g. Databricks, Jupyter, Splunk)
- Understanding of threat intelligence, IOCs (Indicators of Compromise), and threat hunting concepts.
- Familiarity with the MITRE ATT&CK framework and common email attack vectors (phishing, BEC, credential harvesting, malware, account takeover)
- Security certifications such as Security+, Network+, GIAC (GCIA, GCIH), CISSP, CEH, or similar
- Previous experience in technical account management, customer success engineering, or customer-facing security roles
- Experience documenting investigation methodologies and training team members
- AI and our hiring process
Compensation
- $167,210 - $240,350 USD
Benefits
- Fine-tune detection thresholds and configurations to optimize precision while maintaining coverage against emerging threats, balancing detection efficacy with customer experience.
- Document detection issues, investigation findings, and tuning approaches in a structured, reusable format to enable team learning and program improvement.
- Submit D360 CFN reports and AISM submissions to improve global detection coverage based on customer findings.
Company info
- The Embedded Detection Program partners directly with our highest-value customers to rapidly identify, resolve, and demonstrate measurable improvements in detection performance.
- As an Embedded Detection Analyst, you are a trusted technical partner for our strategic customers.
- You are a clear communicator who can explain technical detection issues to both technical and non-technical audiences, particularly customers and GTM stakeholders.
- Generate and present impact reports that demonstrate measurable improvement in detection improvement to both customers, and internal stakeholders, in close partnership with GTM teams.
Equal opportunity
- Abnormal AI is an equal opportunity employer.
- For our EEO policy statement please click here.
- If you would like more information on your EEO rights under the law, please click here.
- Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law.
Apply directly at Abnormal Security →Create a free account for alerts like thisView Abnormal Security immigration profile
This listing is sourced directly from Abnormal Security's careers page and normalized into a canonical job model.