freehire launches on Product Hunt on 26 August.

Follow →

Cyber Threat Detection & Response Analyst

Summary

Monitors and responds to cybersecurity threats using advanced detection tools to protect Cuscal’s digital assets and systems from attacks.

Job Description

We are looking for a Cyber Threat Detection & Response Analyst to identify, analyse and respond to cybersecurity threats that may impact Cuscal.

What is this role about?

As the Cyber Threat Detection & Response Analyst, you will play a critical part in safeguarding Cuscal’s digital assets and ensuring the resilience of its systems against cyberattacks. The analyst will utilise advanced threat detection techniques and tools to detect, investigate, and mitigate potential security incidents, collaborating closely with internal teams and external stakeholders to provide timely responses to emerging threats.

Responsibilities:

  • Monitor security alerts and events generated from multiple sources, including Security Information and Event Management (SIEM) systems, Endpoint Detection and Response (EDR) tools, and other detection technologies.
  • Conduct proactive threat hunting activities to identify suspicious activity within the environment.
  • Analyse network traffic and system logs to identify patterns, trends, and potential threats.
  • Build complex KQL queries to hunt for sophisticated, file-less, and living-off-the-land techniques across SIEM and EDR platforms.
  • Develop custom detection rules, use cases, and threat models based on current threat intelligence and organisational needs. Tune and refine detection logic to reduce false positives while maintaining high sensitivity to true-positive TTPs (Tactics, Techniques, and Procedures).
  • Conduct post-mortem analyses on missed threats to pivot findings into robust, resilient new detection logic.
  • Respond to security incidents by conducting thorough investigations and coordinating with relevant teams for remediation.
  • Provide containment, eradication, and recovery actions to minimise the impact of security incidents.
  • Operationalise threat intelligence feeds, IOCs (Indicators of Compromise), and TTPs directly into actionable detection engineering.
  • Analyse emerging threat actor campaigns and map them to the MITRE ATT&CK framework to identify and close telemetry gaps.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available