Senior Cyber Defense Analyst

Abnormal AI

United States

On-site

USD 144,500 - 170,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Competitive salary
Bonus opportunities
Stock options
Comprehensive benefits

Job summary

A cybersecurity firm is seeking a Cyber Defense Analyst to monitor, investigate, and respond to security alerts. This role involves working with various teams to protect a hybrid environment. Ideal candidates should have 5-7 years of SOC experience and a strong understanding of security tools and processes. The position offers competitive salary and opportunities for bonuses and stock options.

Qualifications

  • 5-7 years of hands-on SOC or Incident Response experience.
  • Strong understanding of attacker lifecycle and MITRE ATT&CK.
  • Experience with EDR, SIEM, and SOAR tools.

Responsibilities

  • Monitor alerts from multiple sources and perform initial triage.
  • Lead incident containment and recovery efforts.
  • Proactively hunt for threats using telemetry sources.

Skills

SOC experience
Incident Response
Automations using Python
Threat analysis
Strong documentation skills

Tools

CrowdStrike
Splunk
SOAR tools
AWS

Job description

Cyber Defense Analyst – Abnormal AI

Overview

We at Abnormal AI are looking for a hands‑on Security Operations / Cyber Defense Analyst who thrives in a fast‑paced, engineering‑driven environment. You’ll be responsible for monitoring, investigating, and responding to security alerts across cloud, endpoint, identity, and application layers. You’ll work closely with detection engineers, cloud security, and IT teams to protect our hybrid environment from threats in real time. This is not a “click‑through‑the‑console” SOC role – we’re looking for someone who can think critically, automate relentlessly, and own incidents end‑to‑end.

Key Responsibilities
  • Detection & Triage – monitor alerts from SIEM, EDR, IAM, CSPM, CDR, etc.; perform initial triage, enrichment, and correlation across multiple data sources; identify false positives and fine‑tune rules with detection engineering.
  • Incident Response – lead containment, eradication, and recovery for endpoint, cloud, and identity incidents; document and communicate incidents through SOAR, Jira, ServiceNow workflows; perform root‑cause analysis and propose permanent preventive controls.
  • Threat Hunting & Analysis – proactively hunt using hypotheses mapped to MITRE ATT&CK; investigate anomalies across CloudTrail, Okta, GitHub, and other telemetry sources; collaborate with threat intelligence to identify emerging TTPs.
  • Automation & Process Improvement – build or enhance playbooks in SOAR (Torq or equivalent); create custom enrichment scripts and automations (Python, Bash, etc.); suggest new detection logic and operational improvements; track and report operational metrics (MTTD, MTTR, incident categories); maintain documentation and lessons learned.
Required Skills & Qualifications
  • 5‑7 years of hands‑on SOC or Incident Response experience in a cloud‑first or hybrid environment.
  • Strong understanding of attacker lifecycle, MITRE ATT&CK, and threat actor TTPs.
  • Experience with EDR (CrowdStrike preferred), SIEM (Splunk preferred), and SOAR (Torq, XSOAR, or Phantom).
  • Familiarity with AWS, Okta, and SaaS platforms.
  • Proficiency in writing queries and automations using Python, SPL, or equivalent.
  • Excellent analytical and investigative skills – capable of operating independently with minimal hand‑holding.
  • Strong documentation and communication skills for technical and executive audiences.
Nice to Have
  • Experience with CSPM, CDR, VM tools.
  • Knowledge of Containers and Kubernetes security.
  • Relevant certifications such as CEH, Security+, GCIH, GCIA, or AWS Security Specialty.
What Success Looks Like
  • Consistently deliver high‑quality triage with minimal false positives.
  • Automate repetitive tasks instead of manual duplication.
  • Transform a vague alert into a well‑documented case with actionable findings.
  • Make measurable improvements to detection coverage, response time, or tooling maturity.
Compensation & Benefits

Base salary range: $144,500 – $170,000 USD. Certain roles are eligible for a bonus, restricted stock units (RSUs), and benefits. Individual compensation packages are based on factors unique to each candidate, including skills, experience, qualifications, and other job‑related reasons.

EEO Statement

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status, or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer (AWS)
Senior Cloud Security Engineer (AWS)

Menlo Ventures • United States

On-site
USD 153,000 - 220,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Abnormal AI • United States

On-site
USD 153,000 - 220,000
Bonus eligibility
Equity
Benefits package
Senior Security Engineer, FedRAMP
Senior Security Engineer, FedRAMP

Menlo Ventures • United States

On-site
USD 153,000 - 220,000
Critical Situation Manager
Critical Situation Manager

Socket.dev • United States

On-site
USD 107,000 - 154,000
Critical Situation Manager
Critical Situation Manager

Abnormal AI, Inc. • United States

On-site
USD 107,000 - 154,000
Critical Situation Manager
Critical Situation Manager

Abnormal AI • United States

On-site
USD 107,000 - 154,000
Application Security Engineer II
Application Security Engineer II

Socket.dev • United States

On-site
USD 130,000 - 187,000
Senior Software Engineer - Product Engineering (Identity Security)
Senior Software Engineer - Product Engineering (Identity Security)

Abnormalsecurity • San Francisco (CA)

Hybrid
USD 179,000 - 259,000
Application Security Engineer II
Application Security Engineer II

Abnormal AI • United States

On-site
USD 130,000 - 187,000
Application Security Engineer II
Application Security Engineer II

Abnormal AI • United States

On-site
USD 130,000 - 187,000