Harbor IT

Harbor IT

Senior Cyber Threat Analyst

Remote (United States) · Senior

No sponsorshipDetected 2 days ago
PythonBashPowerShellAWSLinuxCybersecuritySIEMMicrosoft DefenderSOC OperationsDetection EngineeringIncident ResponseTCP/IPDNSFirewallWiresharkResearchCommunicationMentoringWritingCISSP

About the role

  • Harbor IT is a security-led managed services provider built for critical, complex environments. We secure, operate, and scale IT for organizations where uptime, security, and compliance are mission-critical, backed by an in-house engineering team and a 24/7/365 US-based Security Operations Center. Security has been our foundation since day one, embedded
  • into every layer of how we manage IT, cyber, AI, and cloud rather than bolted on as an add-on. Our tier-less SOC, deep vertical expertise, and proprietary Sagan detection engine gives clients fast detection, low false positives, and a high-touch response model. That combination makes Harbor IT a clear choice for managing security in environments where

Responsibilities

  • Perform advanced analysis across SIEM, EDR, IDS/IPS, firewall, DNS, identity, cloud, operating system, application, and database telemetry.
  • Lead or support incidents through the full incident response lifecycle, including preparation, identification, analysis, containment, eradication, recovery, and post-incident improvement.
  • Create and improve investigation notes, client-facing incident communications, detection logic, procedures, and knowledge-base content.

Requirements

  • 3+ years of relevant cybersecurity experience, including hands-on experience in a SOC, incident response, threat detection, managed security, or closely related operational role.
  • Deep familiarity with incident response lifecycles and the ability to apply them consistently during real-world investigations.
  • Strong working knowledge of Windows, Linux, Active Directory, authentication activity, endpoint telemetry, and cloud security concepts.
  • Experience with SIEM platforms, IDS/IPS technologies, EDR tools, packet analysis tools, vulnerability information, and case management workflows.
  • Excellent written and verbal communication skills, including the ability to speak confidently and eloquently with clients about technical security topics, risk, and remediation.
  • Demonstrated ability to mentor analysts, provide constructive review, and make defensible decisions under time pressure with minimal supervision.
  • Ability to work Monday - Friday 9 am - 6 pm ET and participate in the rotating on-call schedule.
  • Hands-on threat hunting, malware triage, digital forensics, cloud investigation, or detection engineering experience.
  • Practical scripting or automation experience with Python, PowerShell, Bash, or similar languages.
  • Experience with AWS and cloud-native security telemetry.

Nice to have

  • Harbor IT is a security-led managed services provider built for critical, complex environments.
  • We secure, operate, and scale IT for organizations where uptime, security, and compliance are mission-critical, backed by an in-house engineering team and a 24/7/365 US-based Security Operations Center.
  • Our tier-less SOC, deep vertical expertise, and proprietary Sagan detection engine gives clients fast detection, low false positives, and a high-touch response model.
  • That combination makes Harbor IT a clear choice for managing security in environments where failure is not an option
  • This role serves as the first point of escalation for junior analysts who need a second set of eyes, assistance with analysis, or guidance on alert tuning, documentation, and response decisions.
  • The ideal candidate combines deep knowledge of networking, common attack techniques, security telemetry, and remediation practices with the professionalism to explain risks, findings, and recommended actions to clients.
  • Monitor, triage, investigate, and resolve security events and incidents within established client service-level agreements.
  • Correlate network, endpoint, identity, and log evidence to determine attack scope, impact, root cause, and recommended remediation.

Benefits

  • Because the SOC operates 24/7/365, schedule flexibility may occasionally be required to support coverage, training, or critical incidents.

Equal opportunity

  • Harbor IT Information Security is committed to building a collaborative workplace and considers qualified applicants based on job-related skills, experience, and business needs.

Visa & Work Authorization

  • Work Authorization ( Harbor IT is unable to provide visa sponsorship for this role

This listing is sourced directly from Harbor IT's careers page and normalized into a canonical job model.