Paranoids Forensic and Incident Response Operations (FIRE) Night Shift Lead

Yahoo

United States

Hybrid

USD 128,000 - 267,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid work options

Job summary

Yahoo is seeking a senior SOC/IR professional to join The Paranoids FIRE team. You will lead complex investigations during the weekday night shift, protect corporate and user data, and mentor junior analysts using AI-augmented tools and telemetry.

Ideal candidates have 5+ years in security operations, strong macOS/Linux forensics experience, and a solid grasp of MITRE ATT&CK. The role emphasizes automation, collaboration with engineering, and a commitment to high-quality incident response.

Qualifications

  • 5+ years of experience as a SOC/Incident Response Analyst.
  • In-depth experience with macOS and Linux systems and security architectures.
  • Strong background in forensics, log analysis, and malware triage.
  • Experience as shift lead or project lead in security operations.
  • Excellent communication skills for non-technical stakeholders.
  • Familiarity with MITRE ATT&CK framework.
  • Experience using AI assistants or LLMs for scripting or documentation.

Responsibilities

  • Act as a shift lead and resource for colleagues.
  • Perform threat hunting using Databricks and AI models.
  • Develop and deliver table-top exercises.
  • Participate in regular threat hunting exercises.
  • Assess high-priority incidents and drive remediation across Yahoo units.
  • Work with IDS, firewalls, EDR, and related security technologies.
  • Tune detection signatures with engineering and develop AI-augmented playbooks.
  • Evaluate new log sources for detection value.
  • Automate repetitive IR tasks with AI tooling.
  • Participate in 24x7 on-call rotation.

Skills

SOC experience
Communication skills
Leadership
MITRE ATT&CK
AI tooling
MacOS/Linux

Tools

SIEM
Telemetry platforms
Python

Job description

It takes powerful technology to connect our brands and partners with an audience of hundreds of millions of people. Whether you’re looking to write mobile app code, engineer the servers behind our massive ad tech stacks, or develop algorithms to help us process trillions of data points a day, what you do here will have a huge impact on our business—and the world.

A Little About Us

We are the information security team at Yahoo; known as "The Paranoids". As part of the Paranoids Forensics and Incident Response Operations Team (FIRE), we protect Yahoo and its users from dedicated adversaries, working on the front lines monitoring for, hunting for, and responding to threats, we ensure that our users and company are kept safe.

A Lot About You

You are a senior security professional with extensive experience in incident response and digital forensics. You excel in high-pressure environments and are available to work the weekday night shift (5pm-1am EST or 8 PM–6 AM ET, Monday through Thursday). You are committed to protecting sensitive corporate and user data by applying advanced technical, behavioral, and investigative solutions. You have an eye for detail, a mindset for automation, and an interest in using emerging technologies to stay ahead of sophisticated attackers. During your time here we will give you the opportunity to take ownership of key processes supporting the mission of finding suspicious and malicious activity. Expect for you to lead key processes and mentor junior analysts in the pursuit of malicious activity. Enable you to stop advanced attackers by providing access to world-class telemetry and AI-augmented tools. Provide you with a positive work-life balance through a structured 4-day night shift schedule. Encourage you to follow complex investigations through to final remediation and post-mortem analysis. Challenge you to push the bounds of our security program and your own technical talents.

Key Responsibilities
  • Act as a shift lead and resource for colleagues, guiding them through multifaceted work problems and complex investigations.
  • Perform proactive research and threat hunting, utilizing Databricks and the help of AI models to identify subtle security anomalies at Internet scale.
  • Work with the team to develop and deliver table-top exercises
  • Participate in regular threat hunting exercises
  • Assess high-priority security incidents and drive remediation efforts across Yahoo business units.
  • Work with a variety of security technologies including IDS, firewalls, EDR, etc
  • Contribute to the overall security posture of Yahoo
  • Partner with engineering teams to tune detection signatures and develop AI-augmented playbooks for faster 'badness' identification.
  • Evaluate new log sources for security detection value and develop potential use cases
  • Continue to focus on process improvement, specifically automating repetitive IR tasks using some of our AI tooling.
  • Work on special projects as needed
  • Participate in a 24x7 on-call rotation for critical escalations.
Requirements
  • 5+ years of experience as a SOC/Incident Response Analyst, with a proven track record of handling complex investigations.
  • In-depth experience with macOS and Linux systems, services, and security architectures.
  • Strong background in security fundamentals, including network/host forensics, log analysis, and malware triage.
  • Knowledge and experience acting as a shift lead or project lead within a security operations environment.
  • A passion for the field of information security and incident response.
  • Deep understanding of common network services, vulnerabilities, and modern attack patterns (MITRE ATT&CK).
  • Excellent written and verbal communication skills, with the ability to communicate complex technical findings to non-technical stakeholders.
  • Experience using AI assistants or LLMs (e.g., Gemini) for script generation, code review, or complex technical documentation.
Preferred Qualifications
  • Experience with Event Monitoring (SIEM) solutions and large-scale telemetry platforms.
  • Experience in shell scripting, Python, or similar languages for security automation and tool development
  • Experience with using LLM’s and AI tooling for data analysis and detection creation.

The material job duties and responsibilities of this role include those listed above as well as adhering to Yahoo policies; exercising sound judgment; working effectively, safely and inclusively with others; exhibiting trustworthiness and meeting expectations; and safeguarding business operations and brand integrity.

At Yahoo, we offer flexible hybrid work options that our employees love! While most roles don’t require regular office attendance, you may occasionally be asked to attend in-person events or team sessions. You’ll always get notice to make arrangements. Your recruiter will let you know if a specific job requires regular attendance at a Yahoo office or facility. If you have any questions about how this applies to the role, just ask the recruiter!

Yahoo is proud to be an equal opportunity workplace.

All qualified applicants will receive consideration for employment without regard to, and will not be discriminated against based on age, race, gender, color, religion, national origin, sexual orientation, gender identity, veteran status, disability or any other protected category.

Yahoo will consider for employment qualified applicants with criminal histories in a manner consistent with applicable law.

Yahoo is dedicated to providing an accessible environment for all candidates during the application process and for employees during their employment.

If you need accessibility assistance and/or a reasonable accommodation due to a disability, please submit a request via the Accommodation Request Form (www.yahooinc.com/careers/contact-us.html) or call +1.866.772.3182.

Requests and calls received for non-disability related issues, such as following up on an application, will not receive a response.

We believe that a diverse and inclusive workplace strengthens Yahoo and deepens our relationships.

When you support everyone to be their best selves, they spark discovery, innovation and creativity.

The compensation for this position ranges from $128,250.00 - $266,875.00/yr and will vary depending on factors such as your location, skills and experience.

The compensation package may also include incentive compensation opportunities in the form of discretionary annual bonus or commissions.

Our comprehensive benefits include healthcare, a great 401k, backup childcare, education stipends and much (much) more.

Yahoo serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, Yahoo Advertising offers omnichannel solutions and powerful data to engage with our brands and deliver results.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst

110 Yahoo Holdings Inc. • United States

Hybrid
USD 89,000 - 184,000
Healthcare
401k
Backup childcare
+2
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst

Yahoo • United States

Hybrid
USD 89,000 - 184,000
Flexible hybrid work
On-call rotation
Paranoids Forensic and Incident Response Operations (FIRE) Night Shift Lead
Paranoids Forensic and Incident Response Operations (FIRE) Night Shift Lead

ouryahoo • United States

Hybrid
USD 128,000 - 267,000
Flexible hybrid work
Healthcare benefits
401(k)
Paranoids Forensic and Incident Response Operations (FIRE) Night Shift Lead
Paranoids Forensic and Incident Response Operations (FIRE) Night Shift Lead

110 Yahoo Holdings Inc. • United States

Hybrid
USD 128,000 - 267,000
Healthcare
401(k)
Backup childcare
+1
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst

Yahoo Holdings Inc. in • Baltimore (MD)

Hybrid
USD 89,000 - 184,000
Healthcare
401(k)
Backup childcare
+1
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst

ouryahoo • United States

Hybrid
USD 89,000 - 184,000
Flexible hybrid work options
Healthcare benefits
401k plan
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst

Yahoo Holdings Inc. • Richardson (TX)

Hybrid
USD 89,000 - 184,000
Healthcare
401k
Backup childcare
+1
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst

Yahoo Holdings Inc. • New York (NY)

Hybrid
USD 89,000 - 184,000
Flexible hybrid work options
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst

Yahoo Holdings Inc. • Baltimore (MD)

Hybrid
USD 89,000 - 184,000
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst

Yahoo Holdings Inc. • Reston (VA)

Hybrid
USD 89,000 - 184,000
Flexible hybrid work