{"id":5491384,"shortcode":"F085CC7B9A","title":"Cyber Detection & Response Analyst","remote":true,"location":{"country":"United States","countryCode":"US","city":"San Francisco","region":null},"locations":[{"country":"United States","countryCode":"US","city":"San Francisco","region":null,"hidden":false},{"country":"United States","countryCode":"US","city":"Fremont","region":"California","hidden":false},{"country":"United States","countryCode":"US","city":null,"region":null,"hidden":false}],"state":"published","isInternal":false,"code":null,"published":"2026-01-27T00:00:00.000Z","type":"full","language":"en","department":["Archived departments","Embedded Consulting Services"],"accountUid":"01f327ed-a237-41ce-9eef-7af4dc031d9a","approvalStatus":"approved","workplace":"remote","description":"<p>The Cyber Detection and Response Analyst supports day-to-day detection, investigation, and response activities as part of a Cyber Detection and Response Team (DART). This is a hands-on technical role focused on identifying, analyzing, and responding to cyber threats across the client’s environment, working closely with Security Engineering and broader security stakeholders.</p><p><strong>This role will be a part of a 24/7 team and cover one of two shifts: Sunday-Thursday 9:00 am-5:00 pm PT or Tuesday-Saturday 9:00 am-5:00 pm PT</strong></p><ul><li>Monitor, triage, and investigate security alerts and events across endpoint, network, cloud, and identity systems.<a href=\"https://controlrisksnam-my.sharepoint.com/personal/edward_stall_controlrisks_com/_layouts/15/Doc.aspx?sourcedoc=%7BF0E0B0DC-C166-4E8B-A289-C1123B47028D%7D&amp;file=Cyber%20Detection%20and%20Response%20Team%20Lead%20-%20Discord%20June%202026.docx&amp;action=default&amp;mobileredirect=true\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a></li><li>Support incident response activities including analysis, containment, remediation, and documentation. <a href=\"https://controlrisksnam-my.sharepoint.com/personal/edward_stall_controlrisks_com/_layouts/15/Doc.aspx?sourcedoc=%7BF0E0B0DC-C166-4E8B-A289-C1123B47028D%7D&amp;file=Cyber%20Detection%20and%20Response%20Team%20Lead%20-%20Discord%20June%202026.docx&amp;action=default&amp;mobileredirect=true\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a></li><li>Execute established incident response playbooks and contribute to their continuous improvement. <a href=\"https://controlrisksnam-my.sharepoint.com/personal/edward_stall_controlrisks_com/_layouts/15/Doc.aspx?sourcedoc=%7BF0E0B0DC-C166-4E8B-A289-C1123B47028D%7D&amp;file=Cyber%20Detection%20and%20Response%20Team%20Lead%20-%20Discord%20June%202026.docx&amp;action=default&amp;mobileredirect=true\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a></li><li>Perform threat hunting activities to identify potential compromises and gaps in detection coverage. <a href=\"https://controlrisksnam-my.sharepoint.com/personal/edward_stall_controlrisks_com/_layouts/15/Doc.aspx?sourcedoc=%7BF0E0B0DC-C166-4E8B-A289-C1123B47028D%7D&amp;file=Cyber%20Detection%20and%20Response%20Team%20Lead%20-%20Discord%20June%202026.docx&amp;action=default&amp;mobileredirect=true\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a></li><li>Leverage threat intelligence to inform investigations and detection tuning. <a href=\"https://controlrisksnam-my.sharepoint.com/personal/edward_stall_controlrisks_com/_layouts/15/Doc.aspx?sourcedoc=%7BF0E0B0DC-C166-4E8B-A289-C1123B47028D%7D&amp;file=Cyber%20Detection%20and%20Response%20Team%20Lead%20-%20Discord%20June%202026.docx&amp;action=default&amp;mobileredirect=true\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a></li><li>Collaborate with Security Engineering to tune detection logic and improve security controls.<a href=\"https://controlrisksnam-my.sharepoint.com/personal/edward_stall_controlrisks_com/_layouts/15/Doc.aspx?sourcedoc=%7BF0E0B0DC-C166-4E8B-A289-C1123B47028D%7D&amp;file=Cyber%20Detection%20and%20Response%20Team%20Lead%20-%20Discord%20June%202026.docx&amp;action=default&amp;mobileredirect=true\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a></li><li>Produce clear, concise incident reports and support root cause analysis and remediation efforts.<a href=\"https://controlrisksnam-my.sharepoint.com/personal/edward_stall_controlrisks_com/_layouts/15/Doc.aspx?sourcedoc=%7BF0E0B0DC-C166-4E8B-A289-C1123B47028D%7D&amp;file=Cyber%20Detection%20and%20Response%20Team%20Lead%20-%20Discord%20June%202026.docx&amp;action=default&amp;mobileredirect=true\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a></li><li>Support escalation processes as part of a 24/7 detection and response capability.</li></ul>","requirements":"<ul><li> 3–5 years of experience in cybersecurity, with a focus on incident response, SOC operations, or cyber defense. <a href=\"https://controlrisksnam-my.sharepoint.com/personal/edward_stall_controlrisks_com/_layouts/15/Doc.aspx?sourcedoc=%7BF0E0B0DC-C166-4E8B-A289-C1123B47028D%7D&amp;file=Cyber%20Detection%20and%20Response%20Team%20Lead%20-%20Discord%20June%202026.docx&amp;action=default&amp;mobileredirect=true\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a></li><li>Hands-on experience with SIEM, EDR/XDR, and log analysis tools (e.g., Splunk, Sentinel, CrowdStrike). <a href=\"https://controlrisksnam-my.sharepoint.com/personal/edward_stall_controlrisks_com/_layouts/15/Doc.aspx?sourcedoc=%7BF0E0B0DC-C166-4E8B-A289-C1123B47028D%7D&amp;file=Cyber%20Detection%20and%20Response%20Team%20Lead%20-%20Discord%20June%202026.docx&amp;action=default&amp;mobileredirect=true\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a></li><li>Practical understanding of incident response methodologies and frameworks such as MITRE ATT&amp;CK and NIST. <a href=\"https://controlrisksnam-my.sharepoint.com/personal/edward_stall_controlrisks_com/_layouts/15/Doc.aspx?sourcedoc=%7BF0E0B0DC-C166-4E8B-A289-C1123B47028D%7D&amp;file=Cyber%20Detection%20and%20Response%20Team%20Lead%20-%20Discord%20June%202026.docx&amp;action=default&amp;mobileredirect=true\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a></li><li>Familiarity with threat hunting, malware analysis, or forensic investigation techniques. <a href=\"https://controlrisksnam-my.sharepoint.com/personal/edward_stall_controlrisks_com/_layouts/15/Doc.aspx?sourcedoc=%7BF0E0B0DC-C166-4E8B-A289-C1123B47028D%7D&amp;file=Cyber%20Detection%20and%20Response%20Team%20Lead%20-%20Discord%20June%202026.docx&amp;action=default&amp;mobileredirect=true\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a></li><li>Exposure to cloud environments (AWS, Azure, or GCP) and modern enterprise architectures is preferred. <a href=\"https://controlrisksnam-my.sharepoint.com/personal/edward_stall_controlrisks_com/_layouts/15/Doc.aspx?sourcedoc=%7BF0E0B0DC-C166-4E8B-A289-C1123B47028D%7D&amp;file=Cyber%20Detection%20and%20Response%20Team%20Lead%20-%20Discord%20June%202026.docx&amp;action=default&amp;mobileredirect=true\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a></li><li>Strong analytical and problem-solving skills, with the ability to communicate technical findings clearly. <a href=\"https://controlrisksnam-my.sharepoint.com/personal/edward_stall_controlrisks_com/_layouts/15/Doc.aspx?sourcedoc=%7BF0E0B0DC-C166-4E8B-A289-C1123B47028D%7D&amp;file=Cyber%20Detection%20and%20Response%20Team%20Lead%20-%20Discord%20June%202026.docx&amp;action=default&amp;mobileredirect=true\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a></li><li>Relevant certifications (e.g., Security+, GCIH, GCIA, or equivalent) are a plus.</li></ul>","benefits":"<ul><li>Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarized in the full job offer.</li><li>We operate a discretionary bonus scheme that incentivizes, and rewards individuals based on company and individual performance.</li><li> Control Risks supports hybrid working arrangements, wherever possible, that emphasize the value of in-person time together - in the office and with our clients - while continuing to support flexible and remote working. </li><li>Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarized in the full job offer.</li><li>Medical Benefits, Prescription Benefits, FSA, Dental Benefits, Vision Benefits, Life and AD&amp;D, Voluntary Life and AD&amp;D, Disability Benefits, Voluntary Benefits, 401 (K) Retirement, Nationwide Pet Insurance, Employee Assistance Program.</li><li>As an equal opportunities employer, we encourage suitably qualified applicants from a wide range of backgrounds to apply and join us and are fully committed to equal treatment, free from discrimination, of all candidates throughout our recruitment process.</li></ul><p><a target=\"_blank\" rel=\"nofollow noreferrer noopener\" class=\"external\"></a><em><strong>The base salary range for this position is $120000-$140000 per year. Exact compensation offered may vary depending on job-related knowledge, skills, and experience.</strong></em></p><p>Control Risks is committed to a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age or veteran status. If you require any reasonable adjustments to be made in order to participate fully in the interview process, please let us know and we will be happy to accommodate your needs.</p><p><em>Control Risks participates in the E-Verify program to confirm employment authorization of all newly hired employees. The E-Verify process is completed during new hire onboarding and completion of the Form I-9, Employment Eligibility Verification, at the start of employment. E-Verify is not used as a tool to pre-screen candidates. For more information on E-Verify, please visit </em><a target=\"_blank\" rel=\"nofollow noreferrer noopener\" class=\"external\"><em>www.uscis.gov.</em></a></p>"}