Senior Cyber Threat Analyst
Harbor ITAbout the role
Harbor IT is a security-led managed services provider built for critical, complex environments. We secure, operate, and scale IT for organizations where uptime, security, and compliance are mission-critical, backed by an in-house engineering team and a 24/7/365 US-based Security Operations Center. Security has been our foundation since day one, embedded into every layer of how we manage IT, cyber, AI, and cloud rather than bolted on as an add-on.
Our tier-less SOC, deep vertical expertise, and proprietary Sagan detection engine gives clients fast detection, low false positives, and a high-touch response model. That combination makes Harbor IT a clear choice for managing security in environments where failure is not an option
The Senior Cyber Threat Analyst is an experienced SOC practitioner who independently investigates complex security events, guides incidents through the response lifecycle, and communicates clearly with both technical and non-technical client stakeholders. This role serves as the first point of escalation for junior analysts who need a second set of eyes, assistance with analysis, or guidance on alert tuning, documentation, and response decisions.
The ideal candidate combines deep knowledge of networking, common attack techniques, security telemetry, and remediation practices with the professionalism to explain risks, findings, and recommended actions to clients. The role reports to the SOC Manager and partners closely with SOC analysts, engineering, security operations, reporting teams, and client contacts.
Key Responsibilities
- Monitor, triage, investigate, and resolve security events and incidents within established client service-level agreements.
- Perform advanced analysis across SIEM, EDR, IDS/IPS, firewall, DNS, identity, cloud, operating system, application, and database telemetry.
- Lead or support incidents through the full incident response lifecycle, including preparation, identification, analysis, containment, eradication, recovery, and post-incident improvement.
- Correlate network, endpoint, identity, and log evidence to determine attack scope, impact, root cause, and recommended remediation.
- Recognize common attack techniques and provide practical containment and remediation guidance appropriate to the affected environment.
- Serve as the first escalation point for junior analysts, providing a second review of investigations, validating conclusions, and coaching analysts through complex decisions.
- Advise on alert tuning, detection quality, false-positive reduction, rule logic, thresholds, suppression criteria, and documentation improvements with the Detection Engineering Team.
- Communicate directly and professionally with clients by telephone, email, and meetings, clearly explaining security findings, risk, business impact, response options, and next steps.
- Escalate high-severity or high-impact incidents according to process and exercise sound judgment when available data is incomplete.
- Create and improve investigation notes, client-facing incident communications, detection logic, procedures, and knowledge-base content.
- Remain current on threat actor behavior, vulnerabilities, exploits, defensive techniques, and relevant changes in the threat landscape.
- Participate in a rotating on-call schedule of two weeks on call followed by four weeks off. Employees receive an additional 10% compensation during scheduled on-call periods.
- Serve as a voice of authority during the SOC Manager’s absence.
Required Qualifications
- 3+ years of relevant cybersecurity experience, including hands-on experience in a SOC, incident response, threat detection, managed security, or closely related operational role.
- Deep familiarity with networking fundamentals and traffic analysis, in
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s