Cyber Detection & Response Analyst

Control Risks
San Francisco, CA, United States
29 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$120,000.0 - $140,000.0
Working hours
Shift work

Tech stack

Amazon Web Services Microsoft Azure Log Analysis Security Information and Event Management Cloud Platform System Mitre Att&ck Malware Cybercrime Dart Cyber Warfare Splunk

Job description

The Cyber Detection and Response Analyst supports day-to-day detection, investigation, and response activities as part of a Cyber Detection and Response Team (DART). This is a hands-on technical role focused on identifying, analyzing, and responding to cyber threats across the client’s environment, working closely with Security Engineering and broader security stakeholders.

This role will be a part of a 24/7 team and cover one of two shifts: Sunday-Thursday 9:00 am-5:00 pm PT or Tuesday-Saturday 9:00 am-5:00 pm PT

  • Monitor, triage, and investigate security alerts and events across endpoint, network, cloud, and identity systems.
  • Support incident response activities including analysis, containment, remediation, and documentation.
  • Execute established incident response playbooks and contribute to their continuous improvement.
  • Perform threat hunting activities to identify potential compromises and gaps in detection coverage.
  • Leverage threat intelligence to inform investigations and detection tuning.
  • Collaborate with Security Engineering to tune detection logic and improve security controls.
  • Produce clear, concise incident reports and support root cause analysis and remediation efforts.
  • Support escalation processes as part of a 24/7 detection and response capability.

Requirements

  • 3-5 years of experience in cybersecurity, with a focus on incident response, SOC operations, or cyber defense.
  • Hands-on experience with SIEM, EDR/XDR, and log analysis tools (e.g., Splunk, Sentinel, CrowdStrike).
  • Practical understanding of incident response methodologies and frameworks such as MITRE ATT&CK and NIST.
  • Familiarity with threat hunting, malware analysis, or forensic investigation techniques.
  • Exposure to cloud environments (AWS, Azure, or GCP) and modern enterprise architectures is preferred.
  • Strong analytical and problem-solving skills, with the ability to communicate technical findings clearly.
  • Relevant certifications (e.g., Security+, GCIH, GCIA, or equivalent) are a plus.

Benefits & conditions

  • Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarized in the full job offer.
  • We operate a discretionary bonus scheme that incentivizes, and rewards individuals based on company and individual performance.
  • Control Risks supports hybrid working arrangements, wherever possible, that emphasize the value of in-person time together - in the office and with our clients - while continuing to support flexible and remote working.
  • Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarized in the full job offer.
  • Medical Benefits, Prescription Benefits, FSA, Dental Benefits, Vision Benefits, Life and AD&D, Voluntary Life and AD&D, Disability Benefits, Voluntary Benefits, 401 (K) Retirement, Nationwide Pet Insurance, Employee Assistance Program.
  • As an equal opportunities employer, we encourage suitably qualified applicants from a wide range of backgrounds to apply and join us and are fully committed to equal treatment, free from discrimination, of all candidates throughout our recruitment process.

The base salary range for this position is $120000-$140000 per year. Exact compensation offered may vary depending on job-related knowledge, skills, and experience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on apply.workable.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:32 min

Introduction and history of the Dart language

Christoph Menzel Christoph Menzel · WWC 2022

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

Videos

See all

Related articles

See all