todyl

todyl

Detection & Response Analyst II

Denver CO · Mid

Sponsorship not specifiedDetected 134 days ago
PythonBashPowerShellAWSGCPAzureCloud PlatformsLinuxOAuthData AnalysisCybersecuritySIEMUEBASOC OperationsDetection EngineeringIncident ResponseTCP/IPResearchLeadershipCollaborationMentoring

About the role

  • We are looking for a passionate Detection and Response Analyst II to join our Managed Extended Detection and Response (MXDR) team.
  • This role reports to the Director of MXDR.
  • Todyl has an in-office team, and this role is for our Augusta, GA or Denver, CO office.

Responsibilities

  • Monitoring & Reporting: Actively monitor alerts and craft technical reports, describing the overall activity and root cause of the alert to our partners.
  • Collaborative Work: Work closely beside other members of the team to learn and share knowledge and collaborate on projects and incidents.
  • Automation & Tool Development: Independently contribute to internal projects, documentation, and develop new capabilities to automate security operations and enhance overall security.
  • Threat Hunting & Analysis: Support proactive threat-hunting exercises, analyze indicators of compromise (IOCs), and research malware threat families to anticipate and mitigate risks.
  • Work closely beside other members of the team to learn and share knowledge and collaborate on projects and incidents.
  • Independently contribute to internal projects, documentation, and develop new capabilities to automate security operations and enhance overall security.
  • Support proactive threat-hunting exercises, analyze indicators of compromise (IOCs), and research malware threat families to anticipate and mitigate risks.

Requirements

  • Operating System Knowledge: Advanced operational and forensic proficiency in Windows (required), with strong working knowledge of Linux and macOS environments.
  • Ability to analyze packet captures and network telemetry for threat detection.
  • Ability to map telemetry to adversary behaviors across the full intrusion lifecycle.
  • Detection & Security Engineering: Demonstrated experience designing, tuning, and optimizing detections across SIEM, EDR, UEBA, and cloud security platforms.
  • Proven ability to reduce false positives and increase signal fidelity.
  • Automation & Development: Proficiency in scripting (Python, PowerShell, Bash) to automate detection, response, and investigative workflows.
  • Leadership & Collaboration: Experience leading complex investigations, mentoring junior analysts, and partnering cross-functionally with IT, engineering, and leadership teams.
  • Advanced operational and forensic proficiency in Windows (required), with strong working knowledge of Linux and macOS environments.
  • Proficiency in scripting (Python, PowerShell, Bash) to automate detection, response, and investigative workflows.
  • Values Fit
  • Extreme ownership, particularly when things go wrong or aren't completed on time.
  • Intrinsic drive for growth
  • self-motivated, always learning, and focused on raising the bar for self and team.
  • Strong bias for action with impact
  • make tough decisions quickly, measure results, and iterate with clarity to move the mission forward.
  • Comfort with ambiguity and change, embrace change and uncertainty as part of startup life.
  • Humility, purpose over ego to acknowledge mistakes, learn from others, and embrace feedback while putting the mission first.
  • Who You Are
  • Education & Certifications: Advanced industry certifications (e.g., GCIH, GCFA, GREM, GCLD) strongly preferred. Bachelor's degree or equivalent experience required.

Nice to have

  • Advanced industry certifications (e.g., GCIH, GCFA, GREM, GCLD) strongly preferred.
  • Bachelor's degree or equivalent experience required.

Benefits

  • Health & Wellbeing
  • Medical, dental, and vision coverage for you and your family
  • HSA/FSA options
  • Life insurance and short- and long-term disability coverage
  • Short- and long-term disability coverage for when life gets unpredictable
  • Flexibility & Time Off
  • Flexible PTO + 13 company holidays
  • Generous parental leave
  • Intrinsic drive for growth; self-motivated, always learning, and focused on raising the bar for self and team.

Company info

  • At Todyl, we are on a mission to protect small and medium-sized businesses from ever-changing cyber threats.
  • The Todyl platform fully integrates threat, risk, and compliance management to provide exceptional and affordable unified cybersecurity solutions to MSPs (Managed Service Providers) and their end customers.
  • At the end of the day, we're here to keep our partners and customers safe and help them manage the risks and comply with regulations.
  • Protecting others requires a team that works together with trust and cares deeply about carrying out our mission.

This listing is sourced directly from todyl's careers page and normalized into a canonical job model.