Cybersecurity Senior Analyst
Summary
Senior Cybersecurity Analyst owning day-to-day security operations—SIEM tuning, MDR management, incident response, and SOAR automation—at Thumbtack's remote Philippines hub, using Python, SIEM, and cloud (AWS/GCP) tooling.
Thumbtack helps millions of people confidently care for their homes.
Thumbtack is the one app you need to take care of and improve your home — from personalized guidance to AI tools and a best-in-class hiring experience. Every day in every county of the U.S., people turn to Thumbtack to complete urgent repairs, seasonal maintenance and bigger improvements. We help homeowners know which projects to do, when to do them and who to hire from our growing community of 300,000 local service businesses. If making an impact inspires you, join us. Imagine what we’ll build together.
About the Cybersecurity Team
The Security Engineering team at Thumbtack is focused on enabling innovation at scale by making the secure path the easiest path. We believe strong security is not a blocker to velocity, but a force multiplier when it is designed into systems, platforms, and developer workflows from the start.
We partner closely with Product, Engineering, Platform, and Data teams to shape system design, guide architectural decisions, and evolve Thumbtack’s security posture as the company scales. Through collaboration, automation, and thoughtful tradeoffs, we help ensure Thumbtack can ship fast, innovate boldly, and maintain customer trust.
About the role
As Thumbtack scales, the volume and variety of security telemetry grows with it, spanning cloud infrastructure, SaaS applications, endpoints, and identity systems. We’re looking for a Cybersecurity Senior Analyst to help build and operate a detection and response capability that is fast, high-fidelity, and increasingly automated.
In this role, you’ll be a cornerstone of our day-to-day security operations, treating detections as code, tuning our SIEM for signal over noise, partnering closely with our MDR provider, and automating response workflows so that human attention is reserved for the incidents that matter most. You’ll combine hands-on security operations with an engineering mindset, continuously finding ways to improve our detections, processes, and tooling as Thumbtack evolves.
While security operations will be your primary focus, you’ll also support the broader security program and flex into areas such as GRC, third-party risk, and vulnerability management as needed.
What you’ll do
Own day-to-day security operations: monitoring, triage, and investigation of security alerts across our production, corporate, and SaaS environments.
Manage and continuously improve our SIEM: log source onboarding, parsing and normalization, detection rule development and tuning, and cost/coverage optimization.
Manage our MDR (Managed Detection & Response) partnership: escalation workflows, SLAs, detection feedback loops, and quality of response.
Lead security incidents end-to-end: triage, scoping, containment, eradication, recovery, and blameless post-incident reviews.
Build automation that reduces manual toil and response times: SOAR playbooks, detection-as-code pipelines, enrichment integrations, and response scripting.
Conduct proactive threat hunting informed by threat intelligence and knowledge of Thumbtack’s environment.
Define, track, and report on operational metrics (e.g. MTTD, MTTR, alert fidelity, coverage against ATT&CK) and use them to drive improvement.
Apply AI tools to accelerate security operations, and continuously adapt our detections, processes, and tooling to address evolving and novel threats, including AI-related risks.
Partner with Security Engineering, Platform, IT, and Compliance to close detection gaps and improve our overall security posture.
Support the broader security program as needed: GRC (audit support, evidence collection, control monitoring), endpoint security, network security, third party risk reviews, vulnerability management (scanning, triage, and remediation coordination), etc.
In order to be successful, you must bring
6+ years of experience in security operations, detection & response, or a related security engineering discipline.
Deep hands-on experience operating and tuning a SIEM, including detection engineering and log pipeline management.
Experience managing or working closely with an MDR/MSSP partner, including escalation design and holding vendors accountable to quality and SLAs.
Strong incident response skills across cloud-native environments (AWS and/or GCP), SaaS applications, endpoints, and identity systems.
Fluency with AI tools in daily security work, and the adaptability to evolve detections, processes, and tooling to address novel and emerging threats, including AI-related risks.
Scripting and automation proficiency (e.g. Python), with experience building SOAR playbooks, detection-as-code, or similar automation.
Risk-based, analytical thinking: the judgment to prioritize what matters, tune out noise, and articulate trade-offs between coverage, fidelity, and effort.
Working familiarity with adjacent security domains, including GRC and compliance frameworks (e.g. SOC 2, PCI DSS), third party risk assessment, and vulnerability management, with the flexibility to support them as needed.
Excellent written and verbal communication skills, including clear incident communications, and the ability to collaborate effectively with a distributed, primarily US-based team
Actual offered salaries will vary and will be based on various factors, such as calibrated job level, qualifications, skills, competencies, and proficiency for the role.
Thumbtack embraces diversity. We are proud to be an equal opportunity workplace and do not discriminate on the basis of sex, race, color, age, pregnancy, sexual orientation, gender identity or expression, religion, national origin, ancestry, citizenship, marital status, military or veteran status, genetic information, disability status, or any other characteristic protected by federal, provincial, state, or local law. We also will consider for employment qualified applicants with arrest and conviction records, consistent with applicable law.
Thumbtack is committed to working with and providing reasonable accommodation to individuals with disabilities. If you would like to request a reasonable accommodation for a medical condition or disability during any part of the application process, please contact: recruitingops@thumbtack.com.
For information about how Thumbtack collects, uses, and shares personal information about job applicants, please see our Job Applicant Privacy Policy.
We put as much craftsmanship into candidate safety as we do into the hiring experience itself. While scammers may try to impersonate our team, we’ll never ask you for money, banking info, or SSNs during hiring. Check out our blueprint on how to spot the fakes.
As published by ashby
Full Name, Email, Resume
- Preferred First Name optional
- Phone Number
- Cover Letter upload · optional
- Which best describes your experience working with a Managed Security Service Provider (MSSP)? choose one
- Briefly describe how you have applied AI tools in your day-to-day Security Operations work. written answer
- Upon signing a job offer, how many days would you need to render before you can start?
- Given the nature of this role supports our US operations, are you amenable to working a graveyard shift aligned with US Central Time (CT) hours, following Philippine holidays? yes / no
- Which best describes the geographic scope of the stakeholders and teams you’ve supported in your cybersecurity roles? choose one
- Thumbtack currently supports remote work in a number of locations across the United States, Ontario and the Philippines. Using the drop down list below, please select the location you intend to work from. If you are not currently located in or able to work from a location listed below, please select "Location not listed." choose one
- If you selected "Location not listed" above, please use the text box below to let us know where you intend to work from. optional
- Please run a speed test via tack.speedtestcustom.com and paste below the link to the result. written answer
- This role is open only to candidates who are currently residing anywhere in the Philippines. Are you authorized to work in the said country? yes / no
- Have you worked in Thumbtack Philippines before? If yes, please specify your role and the dates of your employment.
- Do you have any relatives or any person that you are in a familial relationship with who is currently employed or has an active application at Thumbtack? If yes, indicate the name of the employee/s or applicant/s (please indicate the job they applied to) and the nature of your relationship with them.Note: Failure to disclose this information in this application form may affect your candidacy for this role, or can be a cause of corrective action as indicated in our discipline manual, once hired.
- By joining Thumbtack, would there be any conflict of interest with your current or last employer or employment agreement (this includes non-compete clause, dual corporate/freelance employment, similar business, etc.)? If yes, please elaborate below. written answer