- Home
- Jobs
- Security Services
- Security Analyst, Managed Detection & Response

Security Analyst, Managed Detection & Response at At-Bay
Remote (US)Full-timeRemoteSecurity ServicesPosted about 1 month ago
Apply with PipelineAbout the Role
<p><img style="display: block; margin-left: auto; margin-right: auto; max-width: 100%;" src="https://www.at-bay.com/wp-content/uploads/2024/01/202401_header_greenhouse_sec_1.png" alt="" width="700"></p>
<p><strong>Why you should join our At-Bay Managed Detection and Response Security team:</strong></p>
<p>At-Bay is a fast-growth InsurSec company (Insurance x Cybersecurity) on a mission to bring innovative products to the market that help protect small businesses from digital risks. As an InsurSec provider, we uniquely combine insurance with mission-critical security technologies, threat intelligence, and human expertise, to bridge the critical security capability gap that exists among SMBs in the community. We believe InsurSec is an $80B market opportunity and we are excited to introduce the Security Analyst (MDR) role to the security team in order to help expand our reach and influence in the business and security community, of which we serve 35,000 customers.</p>
<p>With At-Bay, our customers experience 5X fewer ransomware attacks. This is just the tip of the iceberg! <a href="https://www.at-bay.com/press_releases/at-bay-launches-new-mdr-solution-for-smbs/">Click here</a> to learn more about what we're building. </p>
<p><strong><span data-contrast="auto">Security Analysts provide first-line security monitoring services to At-Bay’s Managed Detection & Response customers with specific responsibilities including:</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559685":120,"335559740":240}"> </span></strong></p>
<ul>
<li><span data-contrast="auto">Operation and tuning of security monitoring tools including Endpoint Detection & Response (EDR), network monitoring, email security, Data Loss Prevention (DLP), Security Information and Event Management (SIEM), security automation tools, and others as needed</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Identification and analysis of anomalous activity in customer technology environments</span></li>
<li>Triage of event data to identity potential indicators of compromise<span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Escalation of potentially malicious activity to engage incident responders where necessary</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Participation in incident investigation, containment, remediation, and recovery activities where necessary</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Developing and maintaining customer relationships to facilitate delivery of MDR services</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Developing and delivering reports on identified activity to customer stakeholders as needed</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
</ul>
<p><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 1">Key skills:</span></span></strong></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559684":-2,"335559685":360,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Previous EDR, MDR, XDR, security monitoring, or incident response experience</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559684":-2,"335559685":360,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Strong oral and written communications skills</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559684":-2,"335559685":360,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Previous hands-on experience performing security operations including several of the following:</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span>
<ul>
<li><span data-contrast="auto">Security monitoring using a variety of endpoint and network tools</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Deployment, tuning, and operation of security tools from vendors such as CrowdStrike, SentinelOne, and others</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Deployment, tuning, and operation of SIEM or other tools used to aggregate and analyze security-relevant data</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Triage and analysis of potential indicators of compromise</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Performing rapid response to contain and/or remediate potentially malicious activity</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Development and analysis of cyber threat intelligence</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Participation in investigations involving digital evidence</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Intrusion detection / cyber threat hunting</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Malware analysis</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
</ul>
</li>
<li data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{"335552541":1,"335559684":-2,"335559685":360,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Previous hands-on experience working in information technology operations (e.g., Network Operations Center, Security Operations Center, Incident Response Team, etc.)</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
</ul>
<p><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 1">Minimum</span><span data-ccp-parastyle="heading 1"> r</span><span data-ccp-parastyle="heading 1">equirements:</span></span></strong></p>
<ul>
<li data-leveltext="•" data-font="Arial" data-listid="2" data-list-defn-props="{"335551500":0,"335552541":1,"335559684":-2,"335559685":720,"335559991":360,"469769226":"Arial","469769242":[8226],"469777803":"right","469777804":"•","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Bachelor’s degree or equivalent</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559685":270,"335559740":240,"335559991":150}"> </span></li>
<li data-leveltext="•" data-font="Arial" data-listid="2" data-list-defn-props="{"335551500":0,"335552541":1,"335559684":-2,"335559685":720,"335559991":360,"469769226":"Arial","469769242":[8226],"469777803":"right","469777804":"•","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Minimum of 2 years of experience in cybersecurity operations, incident response, or another security discipline</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559685":270,"335559740":240,"335559991":150}"> </span></li>
<li data-leveltext="•" data-font="Arial" data-listid="2" data-list-defn-props="{"335551500":0,"335552541":1,"335559684":-2,"335559685":720,"335559991":360,"469769226":"Arial","469769242":[8226],"469777803":"right","469777804":"•","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Willingness to travel as needed to perform job functions</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559685":270,"335559740":240,"335559991":150}"> </span></li>
</ul>
<p><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 1">Preferred requirements:</span></span></strong></p>
<ul>
<li data-leveltext="•" data-font="Arial" data-listid="2" data-list-defn-props="{"335551500":0,"335552541":1,"335559684":-2,"335559685":720,"335559991":360,"469769226":"Arial","469769242":[8226],"469777803":"right","469777804":"•","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Significant undergraduate or graduate coursework in computer science, computer engineering, information systems, or cybersecurity</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559685":270,"335559740":240,"335559991":150}"> </span></li>
<li data-leveltext="•" data-font="Arial" data-listid="2" data-list-defn-props="{"335551500":0,"335552541":1,"335559684":-2,"335559685":720,"335559991":360,"469769226":"Arial","469769242":[8226],"469777803":"right","469777804":"•","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Preferred candidates will have a mix of cybersecurity experience including either security operations or security engineering / architecture</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559685":270,"335559740":240,"335559991":150}"> </span></li>
<li data-leveltext="•" data-font="Arial" data-listid="2" data-list-defn-props="{"335551500":0,"335552541":1,"335559684":-2,"335559685":720,"335559991":360,"469769226":"Arial","469769242":[8226],"469777803":"right","469777804":"•","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Knowledge of cloud environments </span><span data-contrast="auto">including knowledge of cloud security products and services offered by major cloud service providers (e.g., AWS, Azure, Google)</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559685":270,"335559740":240,"335559991":150}"> </span></li>
<li data-leveltext="•" data-font="Arial" data-listid="2" data-list-defn-props="{"335551500":0,"335552541":1,"335559684":-2,"335559685":720,"335559991":360,"469769226":"Arial","469769242":[8226],"469777803":"right","469777804":"•","469777815":"multilevel"}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">One or more industry cybersecurity certifications (e.g., GCIH, Security+, CISSP, etc.)</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559685":270,"335559740":240,"335559991":150}"> </span></li>
</ul>
<p><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 1">Work location:</span></span></strong></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{"335552541":1,"335559684":-2,"335559685":360,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">USA, nationwide</span><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> </span></li>
</ul>
<p><span data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"><em data-stringify-type="italic"><span style="color: rgb(255, 255, 255);" data-ccp-props="{"134245417":false,"201341983":0,"335559740":240}"> #LI-CK1</span></em></span></p>
Related Roles
Security Account Executive (MDR)
At-Bay
Remote (US)RemoteCyber Advisor, Post-Cyber Event Hardening
At-Bay
Remote (US)RemoteBusiness Development Representative
At-Bay
Remote (US)RemoteCyber Analyst, Digital Forensics Incident Response
At-Bay
Remote (US)RemoteSr. Cyber Analyst, Digital Forensics Incident Response
At-Bay
Remote (US)RemoteExecutive Assistant
At-Bay
New York, New York, United States