Cyber Security Analyst

Brooksource

United States

Hybrid

USD 114,000 - 135,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health insurance
Vision insurance
Dental insurance
401k with company match
Paid time off

Job summary

The ideal candidate has 6+ years in enterprise incident response, strong reporting skills for executives, and experience with MITRE ATT&CK and cloud-native tooling. This contract role offers comprehensive benefits and a path to FTE conversion.

Qualifications

  • 6-8+ years hands-on incident response in enterprise environments
  • Proven ability to drive detection, containment, and remediation independently
  • Expertise in writing and delivering professional incident reports and executive presentations
  • Familiarity with MITRE ATT&CK framework applied to investigations
  • Proficiency with cloud-native response tools across Azure, AWS, Google Cloud
  • Hands-on experience with Demisto/XSOAR, Splunk, CrowdStrike; malware/threat hunting knowledge

Responsibilities

  • Lead full lifecycle of incident response from detection to closure
  • Develop detection logic and workflows to identify threats
  • Produce formal incident reports and presentations for technical and executive stakeholders
  • Manage investigations related to vulnerabilities, malware, and emerging threats
  • Coordinate across response, detection, and intelligence teams for containment
  • Utilize cloud tooling for investigation across Azure, AWS, Google Cloud
  • Tune security platforms including Demisto/XSOAR, Splunk, CrowdStrike
  • Collaborate on automation/orchestration with CDO tools lead
  • Partner with vulnerability management and PCI teams as needed
  • Present findings and threat updates to leadership
  • Contribute to roadmap for incident response tooling and processes

Skills

Incident response
Threat detection
Threat intelligence
MITRE ATT&CK
Cloud security

Tools

Demisto/XSOAR
Splunk
CrowdStrike

Job description

Engagement:

6-12 Month W2 Contract (Strong FTE Conversion Potential)

Rate:

$55-65/hr. (DOE)

Hours:

East Coast business hours (10am-3pm EST core)

As a Brooksource consultant, you will be a W2 employee with a full-time 40-hour work week. Comprehensive benefits (health, vision, dental), paid holidays, and sick time accrual are available to all employees on contract. Upon FTE conversion, the client's benefits package will take over.

About the Team

You'll be joining a Cyber Defense Operations (CDO) team at a fast-growing, agile media and advertising technology company. The CDO team plays a pivotal role in safeguarding the organization's assets, data, and brand reputation - proactively detecting, containing, and learning from threats while constantly evolving capabilities to stay ahead of an ever-changing threat landscape.

The Role

We're seeking a Senior Incident Responder to serve as both a hands-on technical expert and strategic advisor in managing and evolving an incident response program. You'll drive the full incident lifecycle - from detection and containment to post-incident analysis and process improvement - while mentoring other responders and collaborating with detection, intelligence, and tooling teams.

This is a hybrid role wearing three hats: Incident Response, Threat Detection, and Threat Intelligence. You'll work closely with security leadership, engineering, and operations teams to ensure defenses are prepared for today's most sophisticated cyber threats.

Responsibilities
  • Lead and execute the full lifecycle of incident response, from detection to closure
  • Develop and refine detection logic and workflows to proactively identify threats
  • Produce clear, formal incident reports and presentations for technical and executive stakeholders
  • Manage incident investigations related to vulnerabilities, malware, and emerging threats
  • Coordinate across response, detection, and intelligence teams to ensure swift containment and remediation
  • Leverage cloud-native tooling for incident investigation and remediation across Azure, AWS, and Google Cloud (including Azure IAM and identity-related investigations)
  • Utilize and tune security platforms including Demisto/XSOAR, Splunk, and CrowdStrike
  • Collaborate with the CDO tools management lead to enhance automation and orchestration capabilities
  • Partner with vulnerability management, PCI compliance, and penetration testing teams as needed
  • Present incident findings and threat landscape updates to leadership
  • Contribute to the strategic roadmap for incident response tooling and lifecycle processes
Requirements
  • 6-8+ years of hands-on experience in incident response in enterprise environments
  • Proven ability to drive incident detection, containment, and remediation efforts independently
  • Expertise in writing and delivering professional incident reports and executive presentations
  • Familiarity with MITRE ATT&CK framework and applying it to investigations
  • Proficiency with cloud-native response tools and workflows across Azure, AWS, and Google Cloud
  • Deep hands-on experience with Demisto/XSOAR, Splunk, and CrowdStrikeStrong knowledge of malware behavior, threat hunting, and vulnerability exploitation methods
  • Ability to operate in a hybrid role spanning incident response, threat detection, and threat intelligence
Nice to Have
  • Certifications such as GCIH, GCFA, GCIA, OSCP (not required)
  • Experience in large-scale media, entertainment, or streaming environments
  • Familiarity with PCI compliance, penetration testing, and MSSP collaboration
Interview Process
  • 20-minute initial screening call with Brooksource recruiter
  • 30-minute video interview with Brooksource
  • Final interview with a CDO Director
EEO Statement:

Brooksource is an equal opportunity employer that does not discriminate on the basis of actual or perceived race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth, lactation and related medical conditions), gender identity or gender expression, sexual orientation, marital status, military service and veteran status, physical or mental disability, protected medical condition as defined by applicable state or local law, genetic information, or any other characteristic protected by applicable federal, state, or local laws and ordinances.

Benefits & Perks: Brooksource offers competitive medical, dental, vision, Health Savings Account, Dependent Care FSA, and supplemental coverage with plans that can fit each employee’s needs. We offer a 401k plan that includes a company match and is fully vested after you become eligible, paid time off, sick time, and paid company holidays. We also offer an Employee Assistance Program (EAP) that provides services like virtual counseling, financial services, legal services, life coaching, etc.

Pay Disclaimer:

The pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Architect
Security Architect

Brooksource • Denver (CO)

Hybrid
USD 170,000 - 230,000
Competitive benefits
401k with company match
Paid time off
Cybersecurity Specialist
Cybersecurity Specialist

CyberMaxx • Maryland

On-site
USD 59,000 - 72,000
Flexible Paid Time Off
401k with company match
Medical, Dental and Vision Coverage
+2
Senior Detection and Response Analyst
Senior Detection and Response Analyst

Prestige Staffing • Dallas (TX)

On-site
USD 120,000 - 180,000
Contract extension potential
Remote work
Career growth
+2
Analyst, Cyber Security II
Analyst, Cyber Security II

TALENT Software Services • Columbia (SC)

On-site
USD 90,000 - 140,000
Cyber Security Engineer
Cyber Security Engineer

EMW Staffing Solutions LLC • Denver (CO)

Hybrid
USD 125,000 - 135,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobgether • United States

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
+1
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Jobgether • United States

Hybrid
USD 125,000 - 190,000
Remote or hybrid work
Security Analyst
Security Analyst

Brooksource • Lansing (MI)

Hybrid
USD 62,000 - 69,000
Health insurance
401k plan
Paid time off
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Penetration Tester
Penetration Tester

Brooksource • United States

On-site
Comprehensive benefits (health, vision, dental)
Paid holidays
Sick time accrual