Source Job

Europe

  • Monitor threats and investigate suspicious activities using logs and detection systems.
  • Analyze attack patterns and build detailed threat scenarios from collected data.
  • Improve detection and blocking mechanisms for automated attacks and malicious behaviors.

SQL Elasticsearch Threat Intelligence Web Application Security

20 jobs similar to Threat Research Analyst

Jobs ranked by similarity.

$160,000–$220,000/yr
US

  • Synthesize data from a wide range of internal and external sources to develop a comprehensive picture of threats affecting cloud, AI, and developers.
  • Analyze and track state-backed and financially motivated attackers targeting cloud ecosystems.
  • Communicate novel findings and in-depth analyses of cyber threat activity to multiple audiences and in multiple formats.

Wiz enables teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. It is one of the fastest-growing startups, trusted by over 65% of the Fortune 100, with a culture that values world-class talent.

US Unlimited PTO

  • Design, develop, and maintain secure cloud environments for distributed LogRhythm deployments.
  • Act as a technical escalation point for SIEM engineers, solving complex security and infrastructure issues.
  • Build automation and operational tooling using PowerShell, SQL, Bash, or Python.

The company specializes in cybersecurity and managed SIEM services, focusing on protecting and scaling distributed LogRhythm environments. They offer a remote work environment with a collaborative culture and opportunities for professional growth.

Australia

  • Design and optimize threat detection capabilities using SIEM, SOAR, EDR, and NDR technologies.
  • Develop automation playbooks and cybersecurity data solutions to improve detection accuracy.
  • Collaborate with customer teams to close detection gaps and adapt defenses to emerging threats.

Our partner is a cybersecurity firm focused on building threat detection capabilities for enterprise environments. They foster a collaborative, engineering-led culture with significant autonomy for engineers.

$123,850–$161,000/yr
US

  • Monitor, detect, and respond to security events across enterprise environments using the SIEM.
  • Build and maintain dashboards, visualizations, and KPIs that demonstrate SIEM effectiveness and security visibility.
  • Use frameworks such as MITRE ATT&CK to contextualize detections and identify coverage gaps.

Horizon3.ai is a fast-growing, remote cybersecurity company that provides production-safe autonomous pentests through its NodeZero platform to organizations of all sizes. We are a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.

United States

  • Analyze, investigate, document, and report on security alerts and potential incidents in customer environments.
  • Serve as an incident coordinator for urgent security events requiring response, containment, and remediation.
  • Stay up-to-date on security training, certifications, and emerging threats while providing security consultation to customers.

CyberSheath is a rapidly growing Managed Security Services Provider offering cybersecurity compliance and threat mitigation for the Defense Industrial Base. The company is expanding its team and fosters a fully remote work environment with a focus on security operations.

$170,000–$240,000/yr
US Unlimited PTO

  • Design, build, and maintain static and dynamic file analysis pipelines processing artifacts at scale.
  • Operate and extend threat indicator enrichment systems for real-time file metadata extraction.
  • Build and maintain threat graph intelligence systems modeling relationships between indicators and actors.

Censys provides real-time Internet intelligence and threat insights to global governments and over 50% of the Fortune 500. They are a growing, research-driven company focused on building comprehensive maps of the internet with a collaborative culture.

$75,600–$97,200/yr
Ireland

  • Triage, investigate, and respond to alerts from the Huntress platform daily.
  • Perform tactical review of EDR telemetry, log sources, and forensic artifacts to determine root causes and provide remediations.
  • Contribute to detection engineering and collaborate with a passionate team dedicated to protecting companies from cyber-attacks.

Huntress is a cybersecurity company founded in 2015 by former NSA cyber operators, providing enterprise-grade cybersecurity to businesses of all sizes. They secure over 5M endpoints and 14M identities worldwide with a 24/7 human-led SOC and a remote-first culture.

Australia 12w maternity 12w paternity

  • Triage and investigate intrusions, analyze logs and forensic artifacts to determine root causes.
  • Perform dynamic malware analysis and refine detection capabilities to address emerging threats.
  • Collaborate with product and engineering teams to evolve human-led agentic workflows.

Huntress is a cybersecurity company founded in 2015 by former NSA cyber operators, making enterprise-grade security accessible to businesses of all sizes. They secure over 5 million endpoints and 14 million identities worldwide with a remote-first team and a 24/7 human-led Security Operations Center.

Costa Rica

  • Analyze EDR telemetry, alerts, and log sources across Endpoint, Identity, Network, and Cloud/SaaS domains.
  • Publish and review threats for customers using concisely written communication to convey key indicators and remediation context.
  • Improve and innovate Detection Operations workflows through orchestration and automation to manage high volumes of telemetry.

Zscaler accelerates digital transformation to make customers more agile, efficient, resilient, and secure. They are an AI-forward enterprise using the world's largest security data lake, with a culture of execution centered on customer obsession, collaboration, and accountability.

$152,000–$152,000/yr
US

  • Build and maintain Synapse collection pipelines through Storm queries, automation, and data models.
  • Diagnose and resolve complex defects in Synapse tooling and collection systems independently.
  • Support threat hunting and adversary tracking using telemetry and malware analysis techniques.

Dragos is a global leader in OT cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first mission-driven team built on authenticity, transparency, and trust.

Canada

  • Monitor and triage alerts across endpoint, network, cloud, runtime, and identity data sources.
  • Perform structured investigations on escalated or ambiguous alerts to build coherent timelines.
  • Participate in incident response, including evidence collection and containment actions.

AlphaSense provides AI-driven market intelligence and search to help enterprises make informed decisions. The company has over 2,000 employees globally and fosters a culture of innovation and collaboration.

US 3w PTO 17w maternity 17w paternity

  • Hunt through first-party data and telemetry to identify and expose new malicious cyber activity and campaigns.
  • Cluster, track, attribute, and disrupt malicious cyber threats with advanced tradecraft.
  • Develop and integrate new intelligence sources, tools, and systems to produce a comprehensive threat picture.

GreyNoise Intelligence is a mission driven security startup focused on helping organizations understand and mitigate risks from Internet scanning and exploitation. It is a high-growth Series-A startup with a remote-first culture emphasizing transparency, honesty, and continuous learning.

US

  • Perform investigations of security incidents using digital forensics and data analytics.
  • Apply coding, data analytics, and investigative skills to hunt, detect, and respond to threats.
  • Build automation and detection models to identify anomalous activity and support response efforts at scale.

Maleda Tech is a technology staffing and consulting firm that provides security engineering services. They are hiring for a contract role supporting a major technology organization.

$140,000–$180,000/yr
US

  • Apply deep expertise in cyber threat intelligence, analyzing advanced threat actors and attack methodologies.
  • Lead strategic threat intelligence initiatives, developing methodologies and providing thought leadership.
  • Convey complex intelligence findings through reports and briefings to diverse technical and executive audiences.

NBCUniversal is a leading media and entertainment company, creating and distributing content across film, television, streaming, and theme parks. As a subsidiary of Comcast Corporation, it employs a large global workforce and fosters an inclusive culture with a commitment to community engagement.

Brazil

  • Triage and evaluate threat information from multiple simulated sources to determine relevance and credibility.
  • Analyze simulated threat actors and their TTPs to assess potential organizational risk.
  • Produce actionable intelligence assessments and brief decision-makers on technical findings.

They provide simulation-based cyber threat intelligence training and analysis. They are a partner company that hires remote analysts for professional development.

$150,000–$210,000/yr
US

  • Design, build, and maintain cybersecurity data pipelines using Cribl, managing data flows from source systems into SIEM and data lake platforms.
  • Develop and integrate connectors for security data ingestion, configure parsing, routing, and transformation, and support SIEM architecture and operations.
  • Troubleshoot complex pipeline issues, create documentation, and collaborate with cross-functional teams to ensure data accuracy, security, and performance.

Cribl is a cybersecurity and data engineering company that helps organizations manage and optimize security data pipelines for SIEM and data lake environments. As a growing company with a small team, they emphasize independent problem-solving, collaboration, and a culture that values technical excellence and clear communication.

Global

  • Monitor, triage, and investigate security incidents across Kraken's infrastructure and client instances.
  • Develop and automate detection capabilities and incident response processes.
  • Collaborate with engineering and product teams to improve security posture and respond to incidents.

We power some of the most innovative global developments in energy by creating technology that redefines utilities. We are a growing global team committed to improving the lives of one billion humans within the decade.

$70,000–$100,000/yr
US Unlimited PTO

  • Monitor SIEM, EDR/XDR, and other security platforms for threats and respond to incidents.
  • Engineer and maintain SIEM integrations, detection rules, and security automation.
  • Collaborate with IT, Engineering, and Product teams to embed security into systems.

EMEA

  • Act as the security overlay on EMEA opportunities, engaging customers on security, privacy, and compliance.
  • Lead security conversations with CISOs and security architects, translating ClickHouse architecture into controls frameworks.
  • Design secure deployment patterns, run threat modelling, and own compliance workstreams through production readiness.

ClickHouse is a fast-growing private cloud company that provides real-time analytics, data warehousing, observability, and AI workloads. With over 4,000 customers and 250% year-over-year ARR growth, it is recognized on the 2025 Forbes Cloud 100 list.

Ireland

  • Analyze data to identify confirmed relationships and document threat actor tactics.
  • Initiate communication with international government agencies and foster cross-departmental engagement.
  • Respond promptly to user needs and stay abreast of industry trends.

Kodex revolutionizes how organizations handle sensitive subpoenas and data requests from law enforcement and government agencies. Founded by a former FBI agent and backed by leading investors, the company has become the industry standard for secure data exchange with a platform supporting over 15,000 government agencies in 190 countries.