> Markdown version of [/jobs/ext/2981884-paranoids-weekend-night-shift-forensic-and-incident-response-operations-fire-analyst](https://www.wearedevelopers.com/jobs/ext/2981884-paranoids-weekend-night-shift-forensic-and-incident-response-operations-fire-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst - **Company:** Yahoo - **Location:** Richardson, TX, United States - **Experience:** Starter - **Salary:** $88,500.0 - $184,375.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Apple Mac Systems, Automation of Tests, Cyber Security, Linux, Domain Name System (DNS), Intrusion Detection Systems, Mobile Application Software, Python (Programming Language), Log Analysis, Network Service, Productivity Software, Shell Script, Security Information and Event Management, EndPointSecurity, Data Logging, Mitre Att&ck, Cybercrime, Databricks - **Published:** September 18, 2026 - **Apply:** https://www.jofdav.com/jobs/59755194-paranoids-weekend-night-shift-forensic-and-incident-response-operations-fire-analyst ## About the Role * 1-3 years of experience or equivalent practical background in security fundamentals, including network/host forensics, log analysis, and basic malware triage. * Demonstrated interest in and commitment to the field of information security and incident response. * Working understanding of common network services (web, mail, DNS), protocols, network vulnerabilities, and standard adversary attack patterns (MITRE ATT&CK). * Functional hands-on experience navigating and analyzing Windows, macOS, and Linux operating systems and system logs. * Familiarity with using modern AI productivity tools or AI coding assistants (e.g., generating scripts, crafting targeted search queries, or summarizing technical logs). * Ability to work independently during shift hours and communicate effectively via collaboration platforms. * Strong written and verbal communication skills, including the ability to communicate technical findings clearly to both engineering and non-technical stakeholders., * Experience querying and analyzing telemetry in Databricks or Enterprise Event Monitoring (SIEM) platforms. * Experience with shell scripting, Python, or automation languages, including experience using AI pair-programming tools to build or optimize automation scripts. * Familiarity with modern Endpoint Detection & Response (EDR), Intrusion Detection Systems (IDS), and cloud logging services. * Demonstrated curiosity in experimenting with emerging AI security capabilities and integrating workflow automations into daily operations. The material job duties and responsibilities of this role include those listed above as well as adhering to Yahoo policies ; exercising sound judgment ; working effectively, safely and inclusively with others ; exhibiting trustworthiness and meeting expectations ; and safeguarding business operations and brand integrity. ## Description It takes powerful technology to connect our brands and partners with an audience of hundreds of millions of people. Whether you're looking to write mobile app code, engineer the servers behind our massive ad tech stacks, or develop algorithms to help us process trillions of data points a day, what you do here will have a huge impact on our business-and the world. A Little About Us When you impact millions of people every day, you become a large target for adversaries of all types within all layers of the stack. Our job is to keep our users safe and make Yahoo one of the safest places on the Internet. We are the information security team at Yahoo; known as "The Paranoids". As part of the Paranoids Forensics and Incident Response Operations Team (FIRE), we protect Yahoo and its users from dedicated adversaries. Working on the front lines monitoring for, hunting for, and responding to threats, we ensure that our users and company are kept safe. A Lot About You You are an inquisitive, highly motivated security analyst who is available to work the weekend night shift (9 PM EST to 9 AM EST Friday to Sunday) . You will use Yahoo internal detection platforms, SIEM technologies, and modern AI-augmented workflows to detect and respond to security events. You are eager to protect sensitive corporate and user data from unauthorized access at Internet scale, bringing continuous curiosity and an open mindset to experimenting with emerging tools and automation to find bad actors and keep Yahoo secure. During your time here we will * Give you the opportunity to contribute to key operational processes supporting the mission of finding malicious acitivty * Enable you to investigate advanced threats and protect our global user base * Provide you with a positive, supportive team environment and healthy work-life balance * Encourage you to follow investigations through to full resolution * Support your career development through continuous learning in forensic methodologies, threat hunting, and modern security automation Responsibilities * Monitor, triage, and analyze security events from networks, applications, endpoints, and cloud data stores. * Leverage AI-assisted investigation tools and structured prompts to accelerate log parsing, synthesize alert telemetry, and draft initial incident timelines. * Assess security incidents, perform initial containment actions, and coordinate with Yahoo business units to remediate operational issues. * Identify repetitive, manual monitoring tasks and partner with senior engineers to implement AI-driven efficiencies and automated triage playbooks. * Assist in tuning detection signatures and developing new alerting use cases for identifying malicious activity across internal systems. * Evaluate new log sources for security detection value and contribute to detection engineering rules under senior analyst mentorship. * Critically evaluate and validate AI-generated outputs, detection queries, and script suggestions to prevent hallucinations and false positives. * Collaborate with the team to support regular threat hunting exercises and table-top simulation scenarios. * Maintain accurate documentation, incident response runbooks, and shift handoff logs. * Participate in a scheduled 24x7 on-call rotation as required for critical incident response escalations. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cutting LLM Costs Without Cutting Quality: How to Beat Proprietary LLMs with Fine-Tuned Open Source](https://www.wearedevelopers.com/videos/100151-cutting-llm-costs-without-cutting-quality-how-to-beat-proprietary-llms-with-fine-tuned-open-source) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [OLTP in the Lakehouse: Redefining Data for AI Workloads](https://www.wearedevelopers.com/videos/2038-oltp-in-the-lakehouse-redefining-data-for-ai-workloads) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)