Harbor IT
Senior Cyber Threat Analyst
Remote (United States) · Senior
No sponsorshipDetected 2 days ago
PythonBashPowerShellAWSLinuxCybersecuritySIEMMicrosoft DefenderSOC OperationsDetection EngineeringIncident ResponseTCP/IPDNSFirewallWiresharkResearchCommunicationMentoringWritingCISSP
About the role
- Harbor IT is a security-led managed services provider built for critical, complex environments. We secure, operate, and scale IT for organizations where uptime, security, and compliance are mission-critical, backed by an in-house engineering team and a 24/7/365 US-based Security Operations Center. Security has been our foundation since day one, embedded
- into every layer of how we manage IT, cyber, AI, and cloud rather than bolted on as an add-on. Our tier-less SOC, deep vertical expertise, and proprietary Sagan detection engine gives clients fast detection, low false positives, and a high-touch response model. That combination makes Harbor IT a clear choice for managing security in environments where
Responsibilities
- Perform advanced analysis across SIEM, EDR, IDS/IPS, firewall, DNS, identity, cloud, operating system, application, and database telemetry.
- Lead or support incidents through the full incident response lifecycle, including preparation, identification, analysis, containment, eradication, recovery, and post-incident improvement.
- Create and improve investigation notes, client-facing incident communications, detection logic, procedures, and knowledge-base content.
Requirements
- 3+ years of relevant cybersecurity experience, including hands-on experience in a SOC, incident response, threat detection, managed security, or closely related operational role.
- Deep familiarity with incident response lifecycles and the ability to apply them consistently during real-world investigations.
- Strong working knowledge of Windows, Linux, Active Directory, authentication activity, endpoint telemetry, and cloud security concepts.
- Experience with SIEM platforms, IDS/IPS technologies, EDR tools, packet analysis tools, vulnerability information, and case management workflows.
- Excellent written and verbal communication skills, including the ability to speak confidently and eloquently with clients about technical security topics, risk, and remediation.
- Demonstrated ability to mentor analysts, provide constructive review, and make defensible decisions under time pressure with minimal supervision.
- Ability to work Monday - Friday 9 am - 6 pm ET and participate in the rotating on-call schedule.
- Hands-on threat hunting, malware triage, digital forensics, cloud investigation, or detection engineering experience.
- Practical scripting or automation experience with Python, PowerShell, Bash, or similar languages.
- Experience with AWS and cloud-native security telemetry.
Nice to have
- Harbor IT is a security-led managed services provider built for critical, complex environments.
- We secure, operate, and scale IT for organizations where uptime, security, and compliance are mission-critical, backed by an in-house engineering team and a 24/7/365 US-based Security Operations Center.
- Our tier-less SOC, deep vertical expertise, and proprietary Sagan detection engine gives clients fast detection, low false positives, and a high-touch response model.
- That combination makes Harbor IT a clear choice for managing security in environments where failure is not an option
- This role serves as the first point of escalation for junior analysts who need a second set of eyes, assistance with analysis, or guidance on alert tuning, documentation, and response decisions.
- The ideal candidate combines deep knowledge of networking, common attack techniques, security telemetry, and remediation practices with the professionalism to explain risks, findings, and recommended actions to clients.
- Monitor, triage, investigate, and resolve security events and incidents within established client service-level agreements.
- Correlate network, endpoint, identity, and log evidence to determine attack scope, impact, root cause, and recommended remediation.
Benefits
- Because the SOC operates 24/7/365, schedule flexibility may occasionally be required to support coverage, training, or critical incidents.
Equal opportunity
- Harbor IT Information Security is committed to building a collaborative workplace and considers qualified applicants based on job-related skills, experience, and business needs.
Visa & Work Authorization
- Work Authorization ( Harbor IT is unable to provide visa sponsorship for this role
Apply directly at Harbor IT →Create a free account for alerts like thisView Harbor IT immigration profile
This listing is sourced directly from Harbor IT's careers page and normalized into a canonical job model.