About this role
About the Role We are seeking an Offensive Security Analyst to plan, conduct, and document iterative, hypothesis-based threat hunts, and to analyze anomalies across the full spectrum of cyber threats. This role will also support incident response, digital forensics, and malware analysis to detect and mitigate threats affecting the organization. What You'll Do
- Plan, conduct, and document iterative, hypothesis-based threat hunts.
- Analyze and investigate anomalies for potential risk across the full spectrum of cyber threats.
- Review and analyze Security Information and Event Management (SIEM) alerts to develop hunt hypotheses.
- Propose, discuss, and document custom searches for automated detection of threat actor activity based on hunt findings.
- Utilize open-source intelligence to inform hunt hypothesis development.
- Track and document cybersecurity incidents from detection to resolution.
- Provide computer forensic support during investigations, including evidence seizure, computer forensic analysis, and data recovery.
- Conduct malware analysis including static and dynamic analysis of complex malware.
- Proactively assess the compute environment for patterns and anomalies, tagging events for Tier 1 & 2 monitoring.
- Collect and analyze data from compromised systems using EDR agents and custom scripts.
- Attend daily Agile Scrum meeting and report progress on activities.
- Support the development of deliverables including Hunt Hypotheses, Hunt Reports, Detection Logic, and Incident Reports.
- Respond to cybersecurity major incidents and assist with mitigation, remediation, and post incident reviews. What We're Looking For
- Experience in offensive security or threat hunting across multiple platforms and threat vectors.
- Proficiency with SIEMs and log analysis.
- Knowledge of malware analysis (static/dynamic) and digital forensics.
- Experience with endpoint detection and response (EDR) telemetry.
- Strong analytical and documentation skills; ability to communicate findings clearly.
- Familiarity with agile methodologies (Scrum) and cross-functional collaboration.
- Ability to operate in fast-paced, incident-driven environments.