> Markdown version of [/jobs/ext/2169239-cyber-threat-analyst](https://www.wearedevelopers.com/jobs/ext/2169239-cyber-threat-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Analyst - **Company:** Brown Brothers Harriman (bbh) - **Location:** Philadelphia, PA, United States - **Experience:** Expert - **Salary:** $110,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software System Penetration Testing, Unix, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Computer Programming, Computer Networks, Databases, Computer Forensics, Computer Telephony Integration, Query Languages, Linux, Digital Forensics, Monitoring of Systems, Information Security Management, Internet Security, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Network Security, Microsoft Software, Network Administration, Open Source Technology, Open Web Application Security, Windows PowerShell, Red Hat Enterprise Linux, Red Team (Cyber Security), Kusto Query Language, Service Pack, Security Information and Event Management, SQL Databases, Software Vulnerability Management, Scripting, Computer Networking Systems, Inversion of Control, Mitre Att&ck, Swift (Programming Language), Malware, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Cybercrime, Splunk, Multiplatform, Vulnerability Analysis - **Published:** August 21, 2026 - **Apply:** https://www.careerbuilder.com/job-details/senior-cyber-threat-analyst-philadelphia-pa--9dca6c38-e12a-41df-8cdf-4251f01d332c ## About the Role As a Senior Cyber Threat Analyst within our Cyber Threat Monitoring Team, you will make a significant impact in enhancing our ability to anticipate, detect, analyze, and respond to cyber threats and proactively mitigate cyber risks effectively. With a focus on Cyber Threat Intelligence (CTI) and Threat Hunting, you will lead efforts to strengthen our security posture through proactive threat analysis, intelligence production, and alignment with industry frameworks and best practice guidance. Collaborating with cross-functional teams and interfacing with organizational leaders, you will contribute to innovative detection and response capabilities that protect our networks, systems, data, employees, and clients. The ideal candidate will have a strong background in cybersecurity with an analytical mindset, a passion for continuous learning and growth, and expertise in enhancing detection capabilities while delivering strategic threat insights., * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field * 5+ years of experience in Cyber Threat Intelligence, Security Operations, Incident Response, Threat Hunting, and/or related roles * Significant relevant experience (e.g., military) in one or more of the above roles may be considered in lieu of a degree * Familiarity with the Intelligence Cycle, Threat Intelligence Platforms, and the MITRE ATT&CK Framework * Excellent collaboration and communication skills, particularly in high-stress situations * Ability to produce products at the tactical, operational, and strategic level and to articulate findings and assessments effectively * A desire to understand and maintain awareness of changes to the cyber threat and risk landscape, including related geopolitical risks that may impact our overall security posture * Strong analytical skills and priority management Nice to Have: * Master's degree in Cybersecurity, Computer Science, Information Technology, or related field * Hands-on experience in two or more of the following areas: Security Operations, Incident Response, Cyber Threat Intelligence, Threat Hunting, Detection Engineering, Security Engineering, Insider Threat Analysis, Digital Forensics, All-Source Intelligence, Penetration Testing, Red Teaming, Network Security Management, Cyber Risk Management, Cloud Security, Vulnerability Management, Malware Analysis * Experience in the financial services sector and familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NYDFS, FFIEC, NIST CSF, ISO 27001, SWIFT CSF, OWASP) * Experience with threat hunting and developing custom detection rules using query languages (e.g., Splunk SPL, Microsoft KQL) * Experience with perimeter, host, and identity defense and monitoring technologies such as EDR/AV, IDS/IPS, Firewalls, WAF, DLP, UEBA, email gateway, sandboxing, and other security tools and terminology * Familiarity with risk scoring, threat analysis, threat hunting, and threat modeling techniques * Experience with Microsoft Defender (MDE, MDI, Defender for Cloud Apps) and Purview Insider Risk Management * Relevant certifications such as CISSP, GCIH, GSEC, GCTI, CTIA, CEH, Security+ * Experience with programming or scripting (Python, SQL, Powershell), Analysis Skills, Audiovisual, Best Practices, Cloud Applications, Cloud Computing, Communication Skills, Computer Forensics, Computer Hacking, Computer Science, Computer Security, Computer Telephony Integration (CTI), Cross-Functional, Cyber Threat Hunting, Database Programming Languages, Establish Priorities, Financial Services, Firewalls, Global Financial Markets, Hunting, IR (Infrared), ISO (International Organization for Standardization), Incident Management, Incident Response, Information Technology & Information Systems, Internet Security, Intrusion Detection Systems, Intrusion Prevention Systems, Inversion of Control (IoC), Investment Services, Linux Operating System, Malware Analysis, Mentoring, Metered Dose Inhalers, Microsoft Product Family, Microsoft Windows Operating System, Multiplatform/Cross-Platform, Network Administration/Management, Network Security, Network Systems, Open Source, Operational Strategy, Penetration Testing, People Management, Problem Solving Skills, Process Improvement, Python Programming/Scripting Language, Red Hat Linux Operating System, Regulatory Requirements, Risk, Risk Management, SQL (Structured Query Language), Sales Management, Scripting (Scripting Languages), Security Analysis, Security Attacks, Security Information and Event Management (SIEM), Security Monitoring, Service Delivery, Social Engineering, Software Patches, Splunk, Strategic Planning, Sustainability, Tactical Operations, Team Player, Testing, Threat Modeling, Threat and risk analysis (TRA), Time Management, Trend Analysis, U.S. National Institute of Standards and Technology (NIST), Unix Operating Systems, Vendor/Supplier Sourcing, Windows PowerShell ## Description * Perform strategic and operational CTI functions, including producing and disseminating weekly, monthly, and quarterly emails, products, reports, and briefings on the evolving threat landscape to internal stakeholders and senior leaders * Monitor open-source, closed-source, and vendor-provided threat intelligence and current events to stay abreast of emerging cyber risks, threats, vulnerabilities, trends, and best practices, and make recommendations for proactive defense strategies and continuous process improvements * Enhance threat detection and response capabilities by supporting the development and enhancement of SOC and incident response (IR) procedures, escalation playbooks, and analyst decision trees * Analyze and identify the likely threats targeting the organization through analysis of alert and IOC trends and use this information to build threat intelligence reporting and develop threat hunting strategies * Develop and maintain threat profiles of relevant threat actors likely to target or actively targeting the organization, including a catalog of their tactics, techniques, and procedures (TTPs) aligned with the MITRE ATT&CK framework * Assist in SOC and IR escalations and investigations, providing expert guidance and context to ensure IR-related actions are threat-informed, effective, and timely * Conduct threat, risk, and vulnerability assessments to provide actionable and prioritized remediation and control enhancement guidance to relevant control and system owners * Work with Vulnerability Management to assist with developing and implementing threat-informed patch prioritization efforts, including through direct engagement with systems owners * Collaborate with the Red Team and Cyber Incident Management to develop relevant red team assessments, penetration tests, incident response trainings, social engineering tests, and tabletop exercises * Using a threat-informed approach, plan and perform threat hunting activities by proactively searching across various logs within the Security Incident and Event Management (SIEM) solution and other security tools to identify previously undetected and unknown anomalous and malicious activity and indicators * Conduct proactive analysis of alert trends to support intelligence reporting and to identify and prioritize missing or ineffective detection capabilities * Perform privileged and general user access reviews across various platforms (Windows, Unix/Linux, RHEL, databases, network components, applications, cloud infrastructure) to identify anomalies and escalate appropriately * Collaborate with DLP and other security teams on insider risk initiatives, collaborating and coordinating efforts to identify and mitigate potential threats from within * Develop, enhance, and maintain procedures, standards, and policies for CTI and threat hunting processes * Collaborate with relevant stakeholders on security awareness messaging and training ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)