Graytitude · 5 months ago
Senior Cyberthreat Analyst
Graytitude is seeking a highly skilled and motivated Senior Analyst to join their dynamic team. The primary responsibilities include monitoring networks for security breaches, leading incident response efforts, and analyzing potential threats to enhance the organization's security posture.
ConsultingCyber SecurityInformation Technology
Responsibilities
Continuously monitor networks and systems for security breaches, analyze potential threats, investigate security incidents, and mitigate identified threats and incidents
Lead and participate in incident response efforts, including containment, eradication, and recovery
Gather, analyze, and disseminate threat intelligence to stakeholders
Identify and assess vulnerabilities in systems and applications
Conduct strategic analysis of cyber threats, including threat actor TTPs, and provide recommendations to improve the organization's security posture
Collaborate with internal teams to share threat intelligence and coordinate efforts
Prepare reports on threat activity, vulnerability assessments, and incident response activities, and maintain accurate documentation
Serve as an escalation point for junior team members in accordance with defined runbooks and SLAs
Mentor junior analysts, share knowledge, and contribute to the development of the team's expertise
Continuously learn about new threats, attack techniques, and security technologies
Assist leadership in understanding the organization’s security posture in relation to specific threat scenarios through a consultative approach
Analyze threat actors, risk footprint, and the effectiveness of current controls to provide strategic insights
Design and facilitate operational tabletop exercises for SOC, CSIRT, and PSIRT functions
Take responsibility for independent projects
Create and maintain runbooks and other procedural documentation
Qualification
Required
5+ years of experience in cyber threat positions, including but not limited to cyber threat intelligence, incident response, threat modeling, blue team, purple team, and red team roles
Bachelor's degree in a related information technology or information security discipline is required
5+ years of experience with security controls and concepts (e.g., antivirus, NDR, EDR, IPS/IDS, DLP, SIEM, vulnerability scanners, application security)
Strong understanding of cybersecurity principles, network security, malware analysis, intrusion detection, and incident response
Familiarity with cybersecurity terminology and concepts, and a demonstrated understanding of the cyber threat landscape and attack vectors
Familiarity with frameworks like MITRE ATT&CK, Diamond Model, and Cyber Kill Chain
Capable of learning new concepts and processes quickly and adapting to a changing environment
Ability to think strategically and to identify, understand, and act on business needs
Ability to think analytically to identify root causes and provide effective solutions
Superior verbal communication skills, including the ability to tailor communications based on the audience
Strong interpersonal skills and the ability to work both independently and collaboratively across teams
Preferred
Relevant certifications such as CISSP, CISM, CEH, PenTest+, or GCIH are beneficial
Experience facilitating training sessions or tabletop exercises is preferred
MITRE ATT&CK: 5 years (Preferred)
Diamond Model: 4 years (Preferred)
Cyber Kill Chain: 4 years (Preferred)
IDS: 5 years (Preferred)
Incident response: 5 years (Preferred)
Ability to Commute: Meridian, ID 83642 (Preferred)
Ability to Relocate: Meridian, ID 83642: Relocate before starting work (Preferred)
Benefits
401(k)
Dental insurance
Health insurance
Life insurance
Relocation assistance
Vision insurance
Performance bonus