todyl
Detection & Response Analyst II
Denver CO · Mid
Sponsorship not specifiedDetected 134 days ago
PythonBashPowerShellAWSGCPAzureCloud PlatformsLinuxOAuthData AnalysisCybersecuritySIEMUEBASOC OperationsDetection EngineeringIncident ResponseTCP/IPResearchLeadershipCollaborationMentoring
About the role
- We are looking for a passionate Detection and Response Analyst II to join our Managed Extended Detection and Response (MXDR) team.
- This role reports to the Director of MXDR.
- Todyl has an in-office team, and this role is for our Augusta, GA or Denver, CO office.
Responsibilities
- Monitoring & Reporting: Actively monitor alerts and craft technical reports, describing the overall activity and root cause of the alert to our partners.
- Collaborative Work: Work closely beside other members of the team to learn and share knowledge and collaborate on projects and incidents.
- Automation & Tool Development: Independently contribute to internal projects, documentation, and develop new capabilities to automate security operations and enhance overall security.
- Threat Hunting & Analysis: Support proactive threat-hunting exercises, analyze indicators of compromise (IOCs), and research malware threat families to anticipate and mitigate risks.
- Work closely beside other members of the team to learn and share knowledge and collaborate on projects and incidents.
- Independently contribute to internal projects, documentation, and develop new capabilities to automate security operations and enhance overall security.
- Support proactive threat-hunting exercises, analyze indicators of compromise (IOCs), and research malware threat families to anticipate and mitigate risks.
Requirements
- Operating System Knowledge: Advanced operational and forensic proficiency in Windows (required), with strong working knowledge of Linux and macOS environments.
- Ability to analyze packet captures and network telemetry for threat detection.
- Ability to map telemetry to adversary behaviors across the full intrusion lifecycle.
- Detection & Security Engineering: Demonstrated experience designing, tuning, and optimizing detections across SIEM, EDR, UEBA, and cloud security platforms.
- Proven ability to reduce false positives and increase signal fidelity.
- Automation & Development: Proficiency in scripting (Python, PowerShell, Bash) to automate detection, response, and investigative workflows.
- Leadership & Collaboration: Experience leading complex investigations, mentoring junior analysts, and partnering cross-functionally with IT, engineering, and leadership teams.
- Advanced operational and forensic proficiency in Windows (required), with strong working knowledge of Linux and macOS environments.
- Proficiency in scripting (Python, PowerShell, Bash) to automate detection, response, and investigative workflows.
- Values Fit
- Extreme ownership, particularly when things go wrong or aren't completed on time.
- Intrinsic drive for growth
- self-motivated, always learning, and focused on raising the bar for self and team.
- Strong bias for action with impact
- make tough decisions quickly, measure results, and iterate with clarity to move the mission forward.
- Comfort with ambiguity and change, embrace change and uncertainty as part of startup life.
- Humility, purpose over ego to acknowledge mistakes, learn from others, and embrace feedback while putting the mission first.
- Who You Are
- Education & Certifications: Advanced industry certifications (e.g., GCIH, GCFA, GREM, GCLD) strongly preferred. Bachelor's degree or equivalent experience required.
Nice to have
- Advanced industry certifications (e.g., GCIH, GCFA, GREM, GCLD) strongly preferred.
- Bachelor's degree or equivalent experience required.
Benefits
- Health & Wellbeing
- Medical, dental, and vision coverage for you and your family
- HSA/FSA options
- Life insurance and short- and long-term disability coverage
- Short- and long-term disability coverage for when life gets unpredictable
- Flexibility & Time Off
- Flexible PTO + 13 company holidays
- Generous parental leave
- Intrinsic drive for growth; self-motivated, always learning, and focused on raising the bar for self and team.
Company info
- At Todyl, we are on a mission to protect small and medium-sized businesses from ever-changing cyber threats.
- The Todyl platform fully integrates threat, risk, and compliance management to provide exceptional and affordable unified cybersecurity solutions to MSPs (Managed Service Providers) and their end customers.
- At the end of the day, we're here to keep our partners and customers safe and help them manage the risks and comply with regulations.
- Protecting others requires a team that works together with trust and cares deeply about carrying out our mission.
This listing is sourced directly from todyl's careers page and normalized into a canonical job model.