Senior MDR Analyst
The role is a Senior MDR Analyst position within a newly developing US Security Operations Centre capability. It is a fully remote, permanent US-based role operating during West Coast business hours, intended for a highly experienced analyst who can work independently and take ownership of complex security incidents from day one.
The successful candidate will independently investigate, contain, and document complex cyber security incidents. Act as a trusted technical escalation point for US customers. Improve threat detection, response processes, and operational playbooks. Help establish standards and practices for the growing US MDR service.
Core Responsibilities
- End-to-end ownership of incident response, including triage, investigation, containment, remediation, customer communication, and post-incident reviews.
- Advanced analysis of:
- EDR/XDR and SIEM alerts
- Windows, Sysmon, identity, email, cloud, and network telemetry
- PowerShell, persistence mechanisms, credential theft, lateral movement, command-and-control activity, and data exfiltration.
- Threat hunting and detection engineering aligned to MITRE ATT&CK.
- Writing and tuning detection logic and security monitoring content.
- Leading customer-facing discussions and producing executive and technical reports.
- Supporting onboarding activities and validating monitoring coverage.
- Mentoring junior analysts and improving SOC processes.
Technical Requirements
Candidates must demonstrate:
- Significant MDR, MSSP, or mature SOC experience with independent ownership of complex incidents.
- Strong EDR/XDR expertise (e.g. CrowdStrike, Microsoft Defender, SentinelOne).
- Advanced SIEM investigation skills (e.g. Microsoft Sentinel, QRadar, Splunk, Chronicle).
- Windows investigation expertise, including Sysmon and PowerShell analysis.
- Network investigation capability using DNS, firewalls, IDS/IPS, packet captures, Wireshark, Zeek, Snort, or similar tools.
- Email security investigation experience.
- Threat hunting and detection engineering expertise.
- Malware triage and sandbox analysis.
- Automation or scripting experience using Python, PowerShell, or SOAR platforms.
- Excellent customer communication and technical writing skills.
Preferred Background
- Helped launch or scale an MDR/SOC service.
- Worked as a senior technical SME in a distributed team.
- Experience investigating Azure/Entra ID and AWS or Google Cloud environments.
- Exposure to Chronicle SOAR or similar orchestration platforms.
- Certifications such as SC-200, BTL1/BTL2, CySA+, GCIH, GCIA, OSCP, or CISSP.
Ideal Candidate Profile
In practical terms, this role is targeting a senior MDR/SOC professional who can independently lead investigations, communicate directly with customers, conduct threat hunting, build detections, automate workflows, and help shape a new US MDR operation, rather than a traditional analyst focused primarily on monitoring alerts and escalating incidents.
Mention you found this on Data First Jobs — it helps us bring you more roles like this.
Cyber Security Analyst MDR
Avatar International SA
Similar Analytics Jobs
View all Analytics jobs→Typeform
Senior FP&A Analyst
NBCUniversal
Analyst, Intellectual Property
State of Delaware
Management Analyst II
State of Delaware
Administrative Analyst This Position is EXEMPT from the State of Delaware Merit System.
AgileGrid Solutions
Business Analyst
Smart IT Frame LLC
Salesforce Functional Business Analyst - Strong in retail domain
Like this role? Get carefully selected jobs like it, twice a week, straight to your inbox.
Free, no spam. Unsubscribe anytime.