Abnormal Security Logo

Abnormal Security

Senior Cyber Defense Analyst

Reposted 21 Days Ago
Remote
Hiring Remotely in USA
145K-170K Annually
Mid level
Remote
Hiring Remotely in USA
145K-170K Annually
Mid level
The Cyber Defense Analyst is responsible for monitoring, investigating, and responding to security alerts, leading incident response, and improving automation in a hybrid environment.
The summary above was generated by AI
About the Role

We at Abnormal AI are  looking for a hands-on Security Operations/ Cyber Defense Analyst who thrives in a fast-paced, engineering-driven environment. You’ll be responsible for monitoring, investigating, and responding to security alerts across cloud, endpoint, identity, and application layers. You’ll work closely with detection engineers, cloud security, and IT teams to protect our hybrid environment from threats in real time.

This is not a “click-through-the-console” SOC role — we’re looking for someone who can think critically, automate relentlessly, and own incidents end-to-end.

Key Responsibilities
  • Detection & Triage:
    • Monitor alerts from tools like SIEM, EDR, IAM, CSPM, CDR etc.
    • Perform initial triage, enrichment, and correlation across multiple data sources.
    • Identify false positives and fine-tune rules with detection engineering.
  • Incident Response:
    • Lead containment, eradication, and recovery for endpoint, cloud, and identity incidents.
    • Document and communicate incidents through SOAR/Jira/ServiceNow workflows.
    • Perform root cause analysis and propose permanent preventive controls.
  • Threat Hunting & Analysis:
    • Proactively hunt using hypotheses mapped to MITRE ATT&CK.
    • Investigate anomalies across CloudTrail, Okta, GitHub, and other telemetry sources.
    • Collaborate with threat intelligence to identify emerging TTPs.
  • Automation & Process Improvement:
    • Build or enhance playbooks in SOAR (Torq or equivalent).
    • Create custom enrichment scripts and automations (Python, Bash, etc.).
    • Suggest new detection logic and operational improvements.
  • Reporting & Metrics:
    • Track and report operational metrics (MTTD, MTTR, incident categories).
    • Maintain documentation and lessons learned.
Required Skills & Qualifications
  • 5-7 years of hands-on SOC or Incident Response experience in a cloud-first or hybrid environment.
  • Strong understanding of attacker lifecycle, MITRE ATT&CK, and threat actor TTPs.
  • Experience with EDR (CrowdStrike preferred), SIEM (Splunk preferred), and SOAR (Torq, XSOAR, or Phantom).
  • Familiarity with AWS, Okta, and SaaS platforms.
  • Proficiency in writing queries and automations using Python, SPL, or equivalent.
  • Excellent analytical and investigative skills — capable of operating independently with minimal hand-holding.
  • Strong documentation and communication skills for technical and executive audiences.
Nice to Have
  • Experience with CSPM/CDR/VM tools.
  • Knowledge of Containers and Kubernetes security.
  • Relevant certifications like CEH, Security+, GCIH, GCIA, or AWS Security Specialty.
What Success Looks Like
  • You consistently deliver high-quality triage with minimal false positives.
  • You automate repetitive tasks instead of manually doing them twice.
  • You can take a vague alert and turn it into a well-documented case with actionable findings.

#LI-EM5

  • You make measurable improvements to detection coverage, response time, or tooling maturity.

At Abnormal AI, certain roles are eligible for a bonus, restricted stock units (RSUs), and benefits. Individual compensation packages are based on factors unique to each candidate, including their skills, experience, qualifications and other job-related reasons. 

Base salary range:
$144,500$170,000 USD

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

Top Skills

AWS
Bash
Cdr
Cspm
Edr
Git
Okta
Python
SIEM
Soar

Similar Jobs

13 Minutes Ago
In-Office or Remote
Minnetonka, MN, USA
Senior level
Senior level
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Design and optimize database architectures and data models; build, automate, and maintain ETL/ELT pipelines and large-scale data platforms on Azure; ensure data quality, security, and compliance; collaborate with data scientists to deliver AI/ML solutions; lead projects, mentor junior engineers, and manage vendor and stakeholder relationships.
Top Skills: Sql,Postgres,Mysql,Azure,Ci/Cd,Devops,Mlops,Etl,Elt,Pyspark,Scala Spark,Hive,Hadoop,Nosql,Python,Scala,Data Warehousing,Paas
13 Minutes Ago
In-Office or Remote
Minnetonka, MN, USA
73K-130K Annually
Junior
73K-130K Annually
Junior
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Build and maintain tooling and infrastructure to automate releases, deployments, and upgrades across cloud and on-prem environments. Implement and manage CI/CD pipelines using Azure, Git Actions/Jenkins and Ansible. Improve system stability, scalability, and collaboration between development and operations to accelerate Agile delivery.
Top Skills: Azure,Git Actions,Jenkins,Ansible,Ci/Cd
13 Minutes Ago
In-Office or Remote
9 Locations
249K-373K Annually
Senior level
249K-373K Annually
Senior level
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Provide physician leadership for utilization management by conducting clinical coverage reviews, rendering determinations based on benefits and policies, documenting findings, engaging in peer-to-peer discussions, collaborating with providers and internal teams, and participating in call/holiday coverage to ensure cost-effective, high-quality care.
Top Skills: ExcelMs WordOutlook

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account