> Markdown version of [/jobs/ext/1241708-senior-cyber-security-incident-response-threat-intelligence-analyst](https://www.wearedevelopers.com/jobs/ext/1241708-senior-cyber-security-incident-response-threat-intelligence-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Security Incident Response & Threat Intelligence Analyst - **Company:** Brooksource - **Location:** Owings Mills, MD, United States (Remote available) - **Experience:** Expert - **Salary:** $124,800.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Bash Shell, Cyber Security, Computer Networks, Linux, Digital Forensics, Intrusion Detection and Prevention, Python (Programming Language), Network Security, Packet Analyzer, Network Protocols, Windows PowerShell, Security Information and Event Management, Software Vulnerability Management, Scripting, Mitre Att&ck, Malware, Cyber Threat Analysis, Information Technology, Cybercrime - **Published:** July 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d3f7e4586f75c05e ## About the Role * Bachelor's degree in Computer Science, Cyber Security, Information Technology, or a related field (or equivalent experience). * 5-8 years of experience in cyber security, incident response, or Security Operations (SOC/CSOC). * Experience leading complex incident investigations and responding to advanced cyber threats. * Strong knowledge of SIEM platforms, threat hunting, malware analysis, digital forensics, network security, and vulnerability management. * Experience with Windows, Linux, network protocols, log and packet analysis, and scripting using Python, PowerShell, or Bash. * Working knowledge of APTs, MITRE ATT&CK, Cyber Kill Chain, and NIST/SANS security frameworks. * Strong communication skills with the ability to document findings and communicate technical information to both technical and non-technical audiences. * Willingness to participate in an on-call rotation, including occasional evenings, weekends, and holidays. ## Description We are seeking an experienced Senior Cyber Security Incident Response & Threat Intelligence Analyst to join a Cyber Security Operations Center (CSOC). This role is responsible for leading complex cyber incident response efforts while proactively identifying, analyzing, and mitigating emerging cyber threats across the enterprise. The ideal candidate has a strong background in incident response, threat hunting, malware analysis, digital forensics, SIEM engineering, and threat intelligence. This individual will work closely with CSOC analysts, threat intelligence, and forensic teams to improve detection capabilities and strengthen the organization's overall security posture., * Lead Level 2/3 cyber security incident response activities, including identification, containment, eradication, recovery, and post-incident analysis. * Investigate advanced cyber threats, malware infections, ransomware, and Advanced Persistent Threats (APTs). * Conduct proactive threat hunting and active defense investigations across enterprise environments. * Analyze network traffic, system logs, endpoint telemetry, and forensic artifacts to identify malicious activity. * Develop, maintain, and improve SIEM detection rules, correlation logic, signatures, alerts, and custom automation scripts. * Build and operationalize threat intelligence, indicators of compromise (IOCs), and countermeasures to strengthen defensive capabilities. * Partner with Threat Intelligence and Digital Forensics teams to investigate sophisticated attacks and maintain current threat profiles. * Perform forensic analysis and packet-level investigations to support security incidents. * Research emerging threats, attacker tactics, techniques, and procedures (TTPs), recommending improvements to security controls and monitoring. * Document investigations, incident findings, detection logic, and response procedures. * Perform trend analysis and contribute to continuous improvement of CSOC operations and incident response processes. * Participate in an on-call rotation to support critical security incidents, including occasional evenings, weekends, and holidays. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)