Abnormal Security Logo

Abnormal Security

Cyber Defense Analyst

Posted 15 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
145K-170K Annually
Mid level
Remote
Hiring Remotely in USA
145K-170K Annually
Mid level
The Cyber Defense Analyst is responsible for monitoring, investigating, and responding to security alerts, leading incident response, and improving automation in a hybrid environment.
The summary above was generated by AI
About the Role

We at Abnormal AI are  looking for a hands-on Security Operations/ Cyber Defense Analyst who thrives in a fast-paced, engineering-driven environment. You’ll be responsible for monitoring, investigating, and responding to security alerts across cloud, endpoint, identity, and application layers. You’ll work closely with detection engineers, cloud security, and IT teams to protect our hybrid environment from threats in real time.

This is not a “click-through-the-console” SOC role — we’re looking for someone who can think critically, automate relentlessly, and own incidents end-to-end.

Key Responsibilities
  • Detection & Triage:
    • Monitor alerts from tools like SIEM, EDR, IAM, CSPM, CDR etc.
    • Perform initial triage, enrichment, and correlation across multiple data sources.
    • Identify false positives and fine-tune rules with detection engineering.
  • Incident Response:
    • Lead containment, eradication, and recovery for endpoint, cloud, and identity incidents.
    • Document and communicate incidents through SOAR/Jira/ServiceNow workflows.
    • Perform root cause analysis and propose permanent preventive controls.
  • Threat Hunting & Analysis:
    • Proactively hunt using hypotheses mapped to MITRE ATT&CK.
    • Investigate anomalies across CloudTrail, Okta, GitHub, and other telemetry sources.
    • Collaborate with threat intelligence to identify emerging TTPs.
  • Automation & Process Improvement:
    • Build or enhance playbooks in SOAR (Torq or equivalent).
    • Create custom enrichment scripts and automations (Python, Bash, etc.).
    • Suggest new detection logic and operational improvements.
  • Reporting & Metrics:
    • Track and report operational metrics (MTTD, MTTR, incident categories).
    • Maintain documentation and lessons learned.
Required Skills & Qualifications
  • 3–5 years of hands-on SOC or Incident Response experience in a cloud-first or hybrid environment.
  • Strong understanding of attacker lifecycle, MITRE ATT&CK, and threat actor TTPs.
  • Experience with EDR (CrowdStrike preferred), SIEM (Splunk preferred), and SOAR (Torq, XSOAR, or Phantom).
  • Familiarity with AWS, Okta, and SaaS platforms.
  • Proficiency in writing queries and automations using Python, SPL, or equivalent.
  • Excellent analytical and investigative skills — capable of operating independently with minimal hand-holding.
  • Strong documentation and communication skills for technical and executive audiences.
Nice to Have
  • Experience with CSPM/CDR/VM tools.
  • Knowledge of Containers and Kubernetes security.
  • Relevant certifications like CEH, Security+, GCIH, GCIA, or AWS Security Specialty.
What Success Looks Like
  • You consistently deliver high-quality triage with minimal false positives.
  • You automate repetitive tasks instead of manually doing them twice.
  • You can take a vague alert and turn it into a well-documented case with actionable findings.

#LI-EM5

  • You make measurable improvements to detection coverage, response time, or tooling maturity.

At Abnormal AI, certain roles are eligible for a bonus, restricted stock units (RSUs), and benefits. Individual compensation packages are based on factors unique to each candidate, including their skills, experience, qualifications and other job-related reasons. 

Base salary range:
$144,500$170,000 USD

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

Top Skills

AWS
Bash
Cdr
Cspm
Edr
Git
Okta
Python
SIEM
Soar

Similar Jobs

Yesterday
Remote
United States
Senior level
Senior level
Big Data • Marketing Tech • Analytics
The Lead Cyber Defense Analyst oversees security operations, responds to cybersecurity events, manages analyst team performance, and collaborates on incident response and threat detection.
Top Skills: AWSAzureCloudtrailCloudwatchCrowdstrike FalconDefender For CloudEdrFirewallsGCPGuarddutyMicrosoft DefenderPalo Alto XsoarProxiesQradarSIEMSplunkWiz.Io
56 Minutes Ago
Remote or Hybrid
New York, NY, USA
86K-95K Annually
Junior
86K-95K Annually
Junior
Productivity • Sales • Software
The Tech Customer Success Manager will drive customer growth and retention through strategic engagement with clients, leveraging product knowledge and AI-driven insights to enhance collaboration and success with monday.com.
Top Skills: Monday.Com
58 Minutes Ago
Remote or Hybrid
Atlanta, GA, USA
Mid level
Mid level
Productivity • Sales • Software
As an Implementation Consultant, you will manage software implementation projects, train clients, and enhance their use of monday.com products while maintaining strong relationships with stakeholders.
Top Skills: APIsGraphQLMonday.Com

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account