Jobs and Careers
OP
Senior Threat Detection Analyst
OPSWATSpainfull_timeVerifiedPosted 10 Jun 2025
About the role
<p><span>OPSWAT</span>, a global leader in IT, <span>OT</span>, and <span>ICS</span> critical infrastructure cybersecurity, delivers an end-to-end platform that gives public and private sector organizations and enterprises the critical advantage needed to protect their complex networks, secure their devices, and ensure compliance. Over the last 20 years our commitment to innovative technology has earned the trust of more than 1,700 organizations, governments, and institutions globally, solidifying our role in protecting the world’s critical infrastructure and securing our way of life.</p><p><strong>The Position</strong></p>
<p>The Senior Threat Detection Analyst leads the organization’s threat analysis and detection engineering efforts, utilizing an existing sandbox product as the primary detection software to identify and mitigate cyber threats. This role focuses on analyzing Indicators of Compromise (IOCs) generated by the sandbox, developing advanced detection capabilities within the sandbox environment, and leading technical initiatives to enhance security operations. The ideal candidate will excel in leveraging the sandbox product for real-time threat detection, mentoring junior analysts, and optimizing detection workflows, with minimal focus on broader threat intelligence activities.</p>
<p> </p>
<p><strong>What You Will be Doing</strong></p>
<ul>
<li><strong>Threat Analysis Using Sandbox Product:</strong></li>
</ul>
<p></p>
<p>o Perform in-depth analysis of IOCs (e.g., malicious IPs, domains, file hashes, and behavioral patterns) generated by the organization’s sandbox product to identify and characterize cyber threats.</p>
<p>o Investigate suspicious activities, such as malware behavior and network anomalies, directly within the sandbox environment to assess threat severity, scope, and impact.</p>
<p>o Prioritize detected threats based on sandbox outputs to guide response actions.</p>
<ul>
<li><strong>Detection Engineering Within Sandbox Environment:</strong></li>
</ul>
<p>o Develop, tune, and optimize detection rules, signatures, and alerts within the sandbox product to enhance its threat detection capabilities.</p>
<p>o Configure the sandbox product to integrate IOCs and behavioral indicators into broader security workflows, ensuring seamless detection across the organization’s infrastructure.</p>
<p>o Enhance sandbox detection algorithms and settings to improve the accuracy and efficiency of IOC generation for real-time threat identification.</p>
<ul>
<li><strong>Leadership and Mentorship:</strong></li>
</ul>
<p>o Mentor junior analysts in threat analysis and detection engineering techniques specific to the sandbox product, fostering expertise in its use.</p>
<p>o Lead technical initiatives to advance the organization’s threat detection capabilities, focusing on maximizing the sandbox product’s effectiveness.</p>
<p>o Promote a collaborative team environment, driving knowledge-sharing and skill development in sandbox-based detection.</p>
<ul>
<li><strong>Sandbox Optimization and Process Improvement:</strong></li>
</ul>
<p>o Lead efforts to optimize the sandbox product’s configuration, ensuring high-quality IOC outputs and efficient detection workflows.</p>
<p>o Develop scripts or automation tools (e.g., in Python or PowerShell) to streamline IOC analysis and detection rule deployment within the sandbox environment.</p>
<p>o Evaluate and recommend enhancements to the sandbox product to strengthen its role as the primary detection software.</p>
<ul>
<li><strong>Threat Intelligence Collaboration:</strong></li>
</ul>
<p>o Correlate sandbox-generated IOCs with external threat intelligence feeds to validate detection findings, but focus primarily on immediate threat analysis and response.</p>
<p>o Provide limited threat intelligence insights to support team awareness, without leading broader intelligence initiatives.</p>
<ul>
<li><strong>Continuous Improvement and Expertise:</strong></li>
</ul>
<p>o Stay current on evolving cyber threats, malware trends, and advancements in sandbox-based detection technologies.</p>
<p>o Lead training sessions on sandbox-driven threat analysis and detection engineering for the cybersecurity team.</p>
<p>o Participate in industry forums to stay informed on best practices for sandbox-based detection solutions.</p>
<p> </p>
<p></p>
<p><strong>What We Need from You</strong><strong> </strong></p>
<ul>
<li><strong>Education:</strong></li>
</ul>
<p></p>
<p>o Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent work experience.</p>
<p>o Advanced certifications (e.g., GCIH, CEH, OSCP, or equivalent) are highly preferred.</p>
<ul>
<li><strong>Experience:</strong></li>
</ul>
<p>o 5+ years of experience in threat analysis, detection engineering, or related cybersecurity roles, with at least 2 years in a senior or leadership capacity.</p>
<p>o Extensive hands-on experience using sandbox products (e.g., Cuckoo Sandbox, CrowdS
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s