Threat Analyst

Dentons Canada

Chicago (IL)

On-site

USD 84,000 - 108,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical
Dental
Vision
401(k)
Paid time off
Discretionary bonuses

Job summary

Dentons US LLP is seeking a Threat Analyst to proactively hunt threats, tune SIEM use cases, and lead investigations of security events across client environments. You will collaborate with teams to enhance security operations, participate in incident response, and help automate detection and response workflows.

The role requires 2+ years in cyber intelligence or threat hunting, strong SIEM and EDR skills, and familiarity with MITRE ATT&CK.

Qualifications

  • Bachelor’s degree or diploma in Computer Science, Information Security, or related field.
  • Minimum 2 years of experience in Cyber Intelligence or Threat Hunting, preferably in a CIRT/SOC; hands-on SIEM content and automation.
  • Direct experience with SIEM, vulnerability scanners, anti-virus solutions, and EDRs.
  • Strong knowledge of threat intelligence and threat hunting including MITRE ATT&CK, kill chain, and IOC lifecycle management.
  • Experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic) and SOAR platforms for playbooks.
  • Scripting proficiency in Python, PowerShell or shell is a plus.

Responsibilities

  • Hunt for threats not detected by existing alerts using dashboards and data analysis.
  • Develop new SIEM use cases and attack vectors to improve detection.
  • Investigate security events and incidents with defined IR procedures.
  • Triage and operationalize threat intelligence from various sources.
  • Correlate threat intel with internal telemetry to guide hunts.
  • Create regular threat hunting and intelligence reports with findings and improvements.
  • Develop automation and SOAR playbooks to streamlineresponse workflows.
  • Contribute to vulnerability management through risk-based remediations.

Skills

Threat hunting
SIEM automation
Incident response
MITRE ATT&CK
Scripting (Python/PowerShell)
EDR tooling

Education

Bachelor's degree in Computer Science or Information Security

Tools

Splunk
Microsoft Sentinel
Elastic
CrowdStrike
Defender for Endpoint

Job description

Select how often (in days) to receive an alert: Create Alert


Chicago, IL, US St. Louis, MO, US Kansas City, MO, US Phoenix, AZ, US Houston, TX, US Dallas, TX, US Atlanta, GA, US Washington DC, DC, US


Aug 23, 2026


Dentons US LLP is currently recruiting for a Threat Analyst. The Information Security Threat Analyst is responsible for proactively hunting for threats within client environments, developing and tuning SIEM use cases, and conducting in-depth investigations of security events. The role involves monitoring and operationalizing threat intelligence, engineering automation and SOAR playbooks to streamline detection and response and maintain comprehensive documentation of threat hunting activities. The analyst collaborates with internal teams to enhance security operations, participates in incident response, and continuously adapts to the evolving cyber threat landscape.


Responsibilities



  • Analyze activity trends using a mix of tools and analytical methodologies to hunt for threats not otherwise detected by configured security alerts.

  • Conduct threat scenario analysis to develop new use cases with relevant attack vectors; develop attack scenarios to formulate hunting strategies to identify threats undetected by existing controls.

  • Perform in-depth investigation of events of interest identified during hunts or from security alerts as defined investigation and response procedures.

  • Monitor, triage, and operationalize threat intelligence from commercial, open-source, ISAC/ISAO, and government sources.

  • Correlate threat intelligence with internal telemetry to identify potential compromise and guide hunts and incident response.

  • Create and deliver regular threat hunting and threat intelligence reports including hypotheses, datasets, findings, false positives, and detection/response improvements.

  • Contribute to the tuning and development of SIEM use cases and other security control configurations to enhance threat detection capabilities.

  • Define and track Security Operations metrics.

  • Design, develop, and maintain automation and SOAR playbooks to streamline alert triage, enrichment, containment, and notification workflows.

  • Automate routine operational tasks (e.g., IOC curation, asset/context lookups, quarantine, user suspension) to reduce MTTD/MTTR.

  • Facilitate vulnerability management by correlating vuln data with exploits-in-the-wild; prioritize remediation based on risk and exposure.

  • Participate in IR exercises to validate processes and IR capabilities.

  • Other duties as assigned to fully meet the requirements of the position.


Required Qualifications



  • Bachelor’s degree/diploma in Computer Science, Information Security, or related field.

  • Minimum 2 years of experience in Cyber Intelligence or as a Threat Hunter, ideally within a CIRT/SOC; hands-on experience with SIEM content and automation development.

  • Direct prior experience with core security technologies such as SIEM, vulnerability scanners, anti-virus solutions, and EDRs.

  • Strong knowledge of threat intelligence and threat hunting, including MITRE ATT&CK, kill chain, hypothesis-driven methods, and IOC lifecycle management.

  • Demonstrated experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic): data onboarding, parsing, correlation rules, dashboards, and tuning.

  • Experience with SOAR platforms (e.g., Splunk SOAR, Microsoft Sentinel automation, Swimlane) and building playbooks for enrichment and response.

  • Strong analytical and investigative skills; knowledge of technical security controls and mitigations.

  • Experience with advanced endpoint analytics and EDR tooling (e.g., CrowdStrike, Defender for Endpoint, Sophos).

  • Good working knowledge of common security threats, industry best practices, and security technologies.

  • 24x7 on-call availability for high severity incidents.

  • Knowledge of digital forensics, malware analysis, penetration testing and ethical hacking.

  • Proficiency in scripting languages (Python, PowerShell, shell) is a plus.

  • Industry certifications are a strong asset (e.g., GIAC, Microsoft SC-200, Splunk Enterprise Security, AWS/Azure security certs).


Chicago Only DOE: $83,850 - $107,950


Washington DC Only DOE: $86,900 - $111,850


Dentons US LLP offers a competitive salary and benefits package including medical, dental, vision, 401k, profit sharing, short-term/long-term disability, life insurance, tuition reimbursement, paid time off, paid holidays and discretionary bonuses.


Dentons US LLP is an Equal Opportunity Employer - Disability/Vet. Pursuant to local ordinances, we will consider for employment qualified applicants with arrest and conviction records.


If you need any assistance seeking a job opportunity at Dentons US, LLP, or if you need reasonable accommodation with the application process, please call our Talent Acquisition Specialist at +1 314 259 5898 or contact us at dentonsusstaffrecruitment@dentons.com.


About Dentons

Redefining possibilities. Together, everywhere. For more information visitwww.dentons.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Analyst
Threat Analyst

Dentons • Chicago (IL)

On-site
USD 84,000 - 108,000
Senior Information Security Analyst (SecOps)
Senior Information Security Analyst (SecOps)

DLA Piper • Chicago (IL)

Hybrid
USD 94,000 - 131,000
Hybrid work arrangement
Medical/dental/vision insurance
401(k)
Senior Information Security Analyst (SecOps)
Senior Information Security Analyst (SecOps)

DLA Piper • Atlanta (GA)

Hybrid
USD 94,000 - 131,000
Medical/dental/vision insurance
401(k)
Hybrid work schedule
Senior Information Security Analyst (SecOps)
Senior Information Security Analyst (SecOps)

DLA Piper • Austin (TX)

Hybrid
USD 94,000 - 131,000
Medical Insurance
Dental Insurance
401(k) Plan
+1
Senior Information Security Analyst (SecOps)
Senior Information Security Analyst (SecOps)

DLA Piper • Baltimore (MD)

Hybrid
USD 94,000 - 131,000
Senior Information Security Analyst (SecOps)
Senior Information Security Analyst (SecOps)

DLA Piper • Maryland

Hybrid
USD 94,000 - 131,000
Medical/Dental/Vision Insurance
401(k)
Threat Hunter & SIEM/SOAR Automation Engineer
Threat Hunter & SIEM/SOAR Automation Engineer

Dentons • Chicago (IL)

On-site
USD 84,000 - 108,000
Senior Analyst, Information Security
Senior Analyst, Information Security

Phase2 Technology • Houston (TX)

On-site
USD 120,000 - 170,000
Medical insurance plans
Dental insurance
Vision insurance
+1
Senior Analyst, Information Security
Senior Analyst, Information Security

Phase2 Technology • Austin (TX)

On-site
USD 120,000 - 190,000
Health insurance
401(k) plan
Paid time off
+4
Threat Hunter - Chandler, Az
Threat Hunter - Chandler, Az

Motion Recruitment • Chandler (AZ)

On-site
USD 55,000 - 110,000
Medical Insurance
Dental Benefits
Vision Benefits
+2