Cyber Security Research Eng. 3 (Phishing & Threat Analytics)

Apex Systems

Charlotte (NC)

On-site

USD 85,411 - 89,544

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Benefits package
401K plan
ESPP

Job summary

Everforth Apex Systems in Charlotte, NC is seeking a Cyber Security Research Engineer focusing on phishing, threat analytics, and incident response. You will research, detect, disrupt phishing campaigns, and collaborate across Threat Analytics, Threat Intelligence, and Security Operations to strengthen defenses.

The role requires hands-on experience with SIEM, EDR/IDS, log analysis, and crafting detection logic using Regular Expressions and YARA rules.

Qualifications

  • 4+ years of Cyber Security Research experience or equivalent demonstrated through work experience, military experience, education, or training.
  • Advanced Information Security technical skills.
  • Experience detecting, investigating, and disrupting phishing attacks targeting employees, customers, or enterprise brands.

Responsibilities

  • Phishing Detection & Threat Analytics: Develop and enhance detection logic, review security logs, create detection content (Regular Expressions, YARA Rules, Threat Detection Logic).
  • Incident Response & Digital Forensics: Lead or participate in incident response activities and post-incident investigations.
  • Threat Hunting & Offensive Security Research: Apply adversarial thinking, develop hunting strategies, research TTPs.

Skills

Phishing detection
Threat analytics
Incident response
Threat hunting
Adversary emulation
Security analytics
IOC analysis
Data analysis

Tools

SIEM platforms
IDS/IPS
Endpoint security
Email security gateways
Web security gateways
YARA rules
Regular expressions

Job description

# Cyber Security Research Eng. 3 (Phishing & Threat Analytics)Apply**Job#: 3043812****Job Description:**Cyber Security Research Engineer**Phishing, Threat Analytics & Incident Response**Location* Charllotte, NC / Dallas, TX / Minneapolis, MN / Chandler, AZ / Des Moines. IA, Raleigh, NCJob SummaryThe Cyber Security Research Engineer is responsible for the research, analysis, detection, disruption, and mitigation of phishing threats and advanced cyber attacks targeting employees, customers, and enterprise systems. This role serves as a key contributor within Threat Analytics, Cyber Threat Intelligence, Incident Response, and Security Operations functions.The ideal candidate will possess strong expertise in phishing detection, threat hunting, security analytics, incident response, digital forensics, and adversarial analysis. This individual will leverage enterprise security tools, develop detection logic, investigate cyber threats, and provide actionable recommendations that improve the organization's security posture.This role requires a highly analytical and investigative mindset with the ability to think like an adversary, identify emerging attack techniques, and develop scalable solutions to detect and mitigate future threats.Key Responsibilities**Phishing Detection & Threat Analytics*** Play a key role in phishing disruption efforts impacting customers, employees, and the company brand.* Develop and enhance detection logic, processes, and procedures used to identify phishing campaigns and threat actor activity.* Review, analyze, and correlate security logs from multiple data sources.* Create and maintain detection content including: + Regular Expressions + YARA Rules + Threat Detection Logic + Security Analytics Content* Identify indicators of compromise (IOCs), malicious domains, phishing infrastructure, suspicious URLs, and threat actor patterns.* Support cyber threat intelligence and threat hunting initiatives.* Leverage large-scale security analytics and threat intelligence techniques to identify, investigate, and disrupt cyber threats.* Develop cybersecurity reporting, threat metrics, and operational dashboards supporting security leadership.**Incident Response & Digital Forensics*** Lead or participate in computer security incident response activities for moderately complex security events.* Conduct technical investigations involving: + Phishing Incidents + Malware Activity + Credential Theft + Account Compromise + Insider Threat Activity* Perform post-incident digital forensics to identify attack vectors, root cause, scope, and remediation requirements.* Analyze endpoint, network, email, identity, and security telemetry to support investigations.* Document investigative findings and provide recommendations for future prevention.* Collaborate with security operations, engineering, risk, and threat intelligence teams to improve response capabilities.**Threat Hunting & Offensive Security Research*** Utilize offensive security methodologies and adversarial techniques to improve detection and response capabilities.* Apply attacker-focused thinking to identify emerging threats and develop hunting strategies.* Research threat actor tactics, techniques, and procedures (TTPs).* Support vulnerability analysis, cyber threat investigations, and security research initiatives.* Conduct analysis involving: + Exploitation Techniques + Vulnerability Research + Security Assessments + Adversary Emulation + Threat Simulation Activities* Develop proof-of-concept methodologies and custom techniques to assess security controls and improve threat detection capabilities.**Security Monitoring & Detection Engineering*** Utilize enterprise security platforms to investigate and respond to security events, including: + SIEM Platforms + IDS/IPS Technologies + Endpoint Security Solutions + Email Security Gateways + Web Security Gateways + Security Detection and Mitigation Devices* Develop automated detection capabilities, security analytics, YARA rules, and alerting logic.* Improve phishing detection and threat monitoring through security automation and enhanced detection engineering.* Identify detection gaps and recommend improvements to monitoring capabilities.* Support integration and optimization of enterprise security tools and monitoring technologies.**Security Risk Assessment & Security Engineering*** Perform security risk assessments and technical reviews to ensure compliance with corporate security standards and best practices.* Identify security vulnerabilities, control gaps, and areas of elevated risk.* Evaluate remediation alternatives and recommend long-term mitigation strategies.* Provide security consulting and guidance to internal business and technology teams.* Support enterprise security engineering programs involving: + Application Security + Vulnerability Management + Threat Modeling + Security Assessments + Security Control Validation + Security Monitoring* Assist with design, testing, implementation, and maintenance of security solutions across networking, cloud, authentication, email, internet, application, and endpoint environments.**AI Security & Emerging Threat Research*** Research emerging threats involving: + Generative AI + Large Language Models (LLMs) + AI-Assisted Phishing + AI-Enabled Social Engineering* Support security analytics initiatives involving AI-driven threat detection and security assessment automation.* Assist in evaluating AI-related security risks and developing mitigation strategies.* Contribute to security research involving prompt engineering abuse, AI threat activity, and emerging cyberattack techniques.* Support AI security testing and threat intelligence initiatives designed to improve organizational cyber defense capabilities.**Cloud Security & Security Operations*** Support cloud security monitoring, investigation, and threat response activities.* Assist with monitoring and threat detection across cloud platforms and hybrid enterprise environments.* Support DevSecOps and modern security operations initiatives that enhance visibility, automation, and incident response effectiveness.* Participate in security engineering efforts focused on platform automation and security tool integration.**Collaboration & Leadership*** Collaborate with peers, security engineers, analysts, threat intelligence teams, and managers to resolve issues and achieve objectives.* Provide guidance and mentorship to junior security engineers and analysts.* Communicate complex technical findings to both technical and non-technical stakeholders.* Support a fast-paced, high-demand environment while balancing multiple priorities.* Drive continuous improvement of phishing detection, threat analytics, incident response, and security monitoring capabilities.Required Qualifications* 4+ years of Cyber Security Research experience or equivalent demonstrated through work experience, military experience, education, or training.* Advanced Information Security technical skills.* Experience detecting, investigating, and disrupting phishing attacks targeting employees, customers, or enterprise brands.* Experience creating and maintaining: + Regular Expressions + YARA Rules + Detection Logic + Threat Analytics Content* Experience reviewing and correlating security logs from multiple security platforms.* Experience supporting security investigations and incident response activities.* Hands-on experience with: + SIEM Platforms + IDS/IPS Technologies + Endpoint Security Solutions + Email Security Gateways + Web Security Gateways + Security Detection Technologies* Experience with host and network log analysis supporting incident response and threat hunting.* Strong analytical, investigative, and problem-solving skills.* Ability to manage complex security issues and develop long-term solutions.Preferred QualificationsThreat Analytics, Detection Engineering & Emerging Threat Research* Experience leveraging security analytics, large-scale data analysis, and threat intelligence techniques to identify and disrupt cyber threats.* Experience developing cybersecurity reporting, threat intelligence metrics, and operational security dashboards.* Experience supporting: + Threat Hunting + Cyber Threat Intelligence + Incident Response + Digital Forensics + Security Monitoring + Detection Engineering* Experience developing automated detection capabilities, security analytics, YARA rules, and security automation workflows.* Experience integrating and optimizing enterprise security tools to improve phishing and threat detection effectiveness.* Experience supporting security operations within large enterprise environments.* Familiarity with AI security research, AI-driven threat detection, security analytics, and AI-related threat investigations.Offensive Security & Investigation Experience* Knowledge of: + Offensive Security Methodologies + Penetration Testing + Vulnerability Research + Adversary Emulation + Exploitation Techniques + Red Team Methodologies* Experience utilizing adversarial thinking during investigations, threat hunting, and incident response activities.* Experience supporting phishing analysis, email investigations, malicious domain analysis, and cybercrime investigations.Cloud & Security Engineering* Experience supporting cloud security monitoring and incident response activities.* Experience with security engineering, security tool integration, and security automation initiatives.* Knowledge of DevSecOps principles and modern security operations practices.* Experience supporting enterprise security programs within highly regulated environments.Technical SkillsPhishing & Email Security* Phishing Detection* Phishing Disruption* Email Threat Analysis* DMARC* Email Security Gateways* Brand Protection* Malicious Domain Analysis* Regular Expressions* YARA RulesThreat Analytics & Detection Engineering* Security Analytics* Threat Hunting* Detection Engineering* Threat Intelligence* IOC Analysis* Security Monitoring* Alert Tuning* Cybersecurity ReportingIncident Response & Forensics* Incident Response* Digital Forensics* Malware Investigations* Host Log Analysis* Network Log Analysis* Root Cause Analysis* Threat InvestigationsOffensive Security* Penetration Testing* Ethical Hacking* Adversary Emulation* Vulnerability Research* Security Assessments* Exploitation Analysis* Threat SimulationSecurity Platforms* SIEM* IDS/IPS* Endpoint Security* Email Security Gateways* Web Security Gateways* Security Detection Platforms* Log Management TechnologiesSecurity Domains* Application Security* Vulnerability Management* Threat Modeling* Security Engineering* Cloud Security* Authentication & Identity Services* Access Management* Security Risk AssessmentAI & Emerging Technologies* AI Security* Generative AI Security* LLM Threat Analysis* AI Threat Intelligence* Security Analytics Automation* AI Security AssessmentPreferred Certifications* GIAC (GCIH, GCIA, GCFA, GCFE, GPEN, GREM)* CISSP* GCTI* OSCP* Security+* Other Cyber Defense, Incident Response, Threat Intelligence, or Offensive Security CertificationsDesired Candidate ProfileThe ideal candidate is a highly technical cybersecurity professional with expertise in phishing detection, threat analytics, incident response, digital forensics, and adversarial analysis. They possess strong investigative skills, experience developing detection content and analytics, and a deep understanding of modern cyber threats targeting enterprise organizations.Successful candidates will demonstrate the ability to analyze complex security events, disrupt phishing campaigns, conduct threat hunting activities, leverage security analytics platforms, and develop long-term detection and mitigation strategies. Experience supporting large-scale enterprise security operations, emerging AI-related threats, and security automation initiatives is highly desirable. *Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.**Everforth Apex uses a virtual recruiter as part of the application process. Click here for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at https://www.apexsystems.com/privacy-policy**Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our ‘Welcome Packet’ as well, which an Everforth Apex team member can provide.**Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.**If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at accommodations@apexsystems.com or 804-523-8228. Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.**UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.***Employee Type:** Contract**Location:** Charlotte, NC, US**Job Type:****Date Posted:** July 24, 2026**Pay Range:** $62 - $65 per hour
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst 3 - SOC Analyst
Information Security Analyst 3 - SOC Analyst

Apex Systems • Charlotte (NC)

On-site
Medical benefits
Certification programs
Employee assistance
Security Automation & Detection Engineer
Security Automation & Detection Engineer

Apex Systems • Plano (TX), Northern (KY)

Hybrid
USD 96,000 - 103,000
Security Operations Engineer
Security Operations Engineer

Apex Systems • Mountain View (CA)

Remote
ESPP
401K program
HSA (HDHP plan)
+1
Software Engineer 4 - Java / React
Software Engineer 4 - Java / React

Apex Systems • Charlotte (NC)

On-site
Health insurance
401K with company match
ESPP (employee stock purchase)
Technical Security Consultant
Technical Security Consultant

Apex Systems • Mountain View (CA)

Remote
Senior Java Developer
Senior Java Developer

Apex Systems • Austin (TX)

Hybrid
Network Engineer 3 - LAN / WAN
Network Engineer 3 - LAN / WAN

Apex Systems • Charlotte (NC)

On-site
Application Security Advisor / Trainer
Application Security Advisor / Trainer

Apex Systems • Atlanta (GA)

On-site
USD 110,000 - 121,000
Medical insurance
Dental insurance
Vision insurance
+7
Technical Delivery Manager
Technical Delivery Manager

Apex Systems • Charlotte (NC)

On-site
USD 94,000 - 101,000
401K program
Health Savings Account (HSA)
Employee Assistance Program (EAP)
+1
VP - Lead Backend Engineer
VP - Lead Backend Engineer

Apex Systems • New York (NY)

On-site
USD 150,000 - 250,000
Medical, dental, vision coverage
401K with company match
HSA (Health Savings Account)
+2