Incident Response & Intel Analyst (Seasonal)

Major League Baseball (MLB)

New York (NY)

On-site

USD 34,440 - 41,328

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

A major sports organization is seeking an Incident Response and Threat Intelligence Analyst responsible for detecting and investigating cybersecurity incidents. This role involves enhancing digital risk protection, conducting investigations, and developing incident response processes. The ideal candidate holds a degree in Cybersecurity or related fields with experience in cyber investigations, and threat intelligence methodologies. Compensation ranges from $25.00 to $30.00 per hour. Candidates should have excellent communication skills and an understanding of malicious threat actors.

Qualifications

  • Experience supporting incident response and conducting cyber investigations.
  • Ability to handle sensitive information with discretion.
  • Familiarity with threat intelligence methodologies.

Responsibilities

  • Detect and respond to cybersecurity incidents.
  • Enhance digital risk protection and threat intelligence.
  • Conduct confidential investigations and produce reports.
  • Analyze cyber threat landscape for vulnerabilities.
  • Develop and document incident-response processes.
  • Support training programs to strengthen security.
  • Collaborate across teams to fulfill intelligence requests.
  • Monitor illegal streaming and piracy instances.

Skills

Incident response
Threat intelligence
Investigative reporting
Malicious adversaries understanding
Analytical frameworks (MITRE ATT&CK)
Time management
Communication skills
Foreign language proficiency

Education

Bachelor’s or Master’s degree in Cybersecurity, Information Security, Software Engineering

Job description

The Incident Response and Threat Intelligence Analyst is responsible for detecting, investigating, and responding to cybersecurity incidents, fraud, and digital threats impacting the organization and its affiliates. This role integrates incident response, threat intelligence, digital risk protection, and fraud analysis to proactively identify risks, disrupt malicious activity, and strengthen organizational defenses through actionable intelligence, investigations, and well‑documented processes.

Responsibilities
  • Support security and fraud incident response activities in coordination with the virtual Security Operations Center (vSOC) and internal stakeholders, including identification, containment, remediation, and post‑incident analysis.
  • Enhance digital risk protection, threat intelligence, and social media monitoring programs, delivering timely and actionable intelligence to support operational response and threat modeling.
  • Conduct highly confidential digital and fraud investigations and produce clear, defensible investigative reports.
  • Monitor and analyze the cyber threat and fraud landscape using OSINT, deep/dark web sources, industry tools, internal telemetry, and the MITRE ATT&CK framework to identify relevant threats, vulnerabilities, indicators of compromise (IOCs), and adversary tactics, techniques, and procedures (TTPs).
  • Analyze system logs, transaction data, and user behavior to identify anomalies, high‑risk patterns, and indicators of fraud; assess impact and develop mitigation and prevention strategies.
  • Develop, maintain, and document incident‑response playbooks, threat‑intelligence processes, fraud workflows, policies, and procedures to improve operational consistency and effectiveness.
  • Assist in producing threat intelligence briefs, metrics, and reports that communicate risk, trends, and business impact to technical and non‑technical stakeholders.
  • Support security awareness initiatives, including training programs and internal phishing campaigns, to strengthen organizational security and fraud resilience.
  • Collaborate across teams to fulfill intelligence requests, support adversary simulation efforts, and align threat intelligence with evolving business objectives.
  • Identify opportunities for security automation and SOAR‑driven orchestration to improve response time, intelligence quality, and operational scalability across incident response, intelligence, and fraud programs.
  • Monitor and identify instances of illegal streaming and piracy utilizing threat intelligence monitoring platforms, and manage the submission and execution of takedown efforts to support anti‑piracy and brand protection initiatives.
Qualifications & Skills
  • Bachelor’s or Master’s degree (completed or in progress) in Cybersecurity, Information Security, Software Engineering, or a related field.
  • Demonstrated experience supporting incident response and conducting in‑depth cyber, fraud, or digital investigations using OSINT, social media platforms, industry tools, and internal data sources.
  • Strong understanding of malicious adversaries, threat actors, and campaigns, including indicators of compromise (IOCs) and adversary tools, techniques, and procedures (TTPs).
  • Ability to handle highly sensitive and confidential information with discretion and professionalism.
  • Excellent organizational, time management, documentation, and communication skills, with the ability to clearly articulate complex technical concepts, attack methods, and investigative findings to both technical and non‑technical audiences.
  • Familiarity with threat intelligence methodologies, analytical frameworks (e.g., MITRE ATT&CK), and intelligence reporting best practices.
  • Foreign language proficiency in Spanish, Russian, Farsi, and/or Mandarin is a plus.
Pay Range

$25.00-$30.00 per hour

California Residents: Please see our California Recruitment Privacy Policy for more details.

Colorado Residents: Colorado based applicants may redact or remove age‑identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.

Applicants requiring a reasonable accommodation for any part of the application and hiring process, please email us at accommodations@mlb.com. Requests received for non‑disability related issues, such as following up on an application, will not receive a response.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Threat Intelligence Engineer
Threat Intelligence Engineer

Anthropic • Washington, San Francisco (CA)

Hybrid
USD 320,000 - 405,000
Investigator
Investigator

Jackalope Digital LLC • Northern (KY)

Hybrid
USD 110,000 - 170,000
Cybersecurity Intelligence Analyst
Cybersecurity Intelligence Analyst

MidFirst Bank • Oklahoma City (OK)

On-site
USD <120,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Peraton • Reston (VA)

On-site
USD 104,000 - 166,000
Sr. Incident Response Analyst
Sr. Incident Response Analyst

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Threat Intelligence Analyst (Sr., Jr. Multiple Roles)
Threat Intelligence Analyst (Sr., Jr. Multiple Roles)

Fabergent • Herndon (VA)

On-site
USD 110,000 - 140,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Peraton • Herndon (VA)

On-site
USD 104,000 - 166,000
Incident Response Analyst
Incident Response Analyst

Prestige Staffing • City of Yonkers (NY)

On-site
USD 125,000 - 130,000
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

MFI Technologies Incorporated • New York (NY)

On-site
USD 75,000 - 100,000