Cybersecurity Threat Analyst I (Hybrid)

Bancorp Bank, TheWilmington, DE
Hybrid

About The Position

The Cybersecurity Threat Analyst I role is responsible for monitoring security alerts, logs, and threat intelligence under general supervision to identify suspicious activity. Performs initial triage using established procedures, documents findings, creates or updates tickets, and escalates events requiring deeper investigation or response. Supports routine vulnerability management, asset review, investigation, reporting, and security awareness activities. Uses approved artificial intelligence (AI) tools for research, query development, evidence summarization, and documentation while validating outputs, following data-handling requirements, and protecting confidential information.

Requirements

  • Associate or bachelor’s degree in cybersecurity, information technology, computer science, or a related field, or an equivalent combination of education, training, and experience.
  • Internships, academic labs, help desk, system administration, network support, or security operations experience may qualify as relevant experience.
  • Foundational understanding of cybersecurity principles, common threats, Transmission Control Protocol/Internet Protocol (TCP/IP) networking, and Windows, Linux, or macOS operating systems.
  • Basic familiarity with security logs, monitoring tools, vulnerability management concepts, and ticketing workflows.
  • Ability to follow documented procedures, maintain accurate records, recognize when additional assistance is needed, and escalate promptly.
  • Basic scripting, command-line, or query skills, or a demonstrated willingness to learn tools such as Python, PowerShell, or SQL.
  • Familiarity with generative AI and machine learning concepts used in cybersecurity, including common capabilities, limitations, privacy risks, and the need for human validation.
  • Clear written and verbal communication, sound organization, and the ability to work effectively in a collaborative environment.

Nice To Haves

  • Coursework, an internship, a lab environment, or hands-on experience related to security operations, threat analysis, incident response, or vulnerability management preferred.
  • Familiarity with one or more security technologies, such as security information and event management (SIEM), endpoint or extended detection and response (EDR/XDR), security orchestration, automation, and response (SOAR), threat intelligence, vulnerability scanning, or ticketing platforms preferred.
  • Basic knowledge of network traffic, firewalls, intrusion detection or prevention, packet analysis, cloud services, databases, or data visualization tools preferred.
  • An entry-level certification, such as CompTIA Security+, Network+, CySA+, Microsoft SC-900, or a comparable vendor credential, or a willingness to pursue one preferred.
  • Basic experience with scripting, application programming interfaces (APIs), or low-code automation to collect, organize, or validate security data preferred.
  • Familiarity with approved AI-assisted workflows for security research, documentation, query development, or analysis preferred.
  • Awareness of AI-specific security risks and safeguards, including prompt injection, sensitive-data leakage, malicious automation, and AI-generated social engineering preferred.

Responsibilities

  • Monitors security alerts from approved tools and performs initial triage using documented procedures and playbooks.
  • Reviews relevant firewall, email, web, domain name system (DNS), endpoint, and other logs to gather evidence and identify indicators of suspicious activity.
  • Creates and updates tickets, documents actions taken, and escalates incidents based on defined severity and escalation criteria.
  • Supports incident response activities under guidance, including evidence collection, basic scoping, containment tracking, and follow-up documentation.
  • Reviews threat intelligence alerts and indicators of compromise for relevance to the environment and escalates significant findings.
  • Runs approved vulnerability scans and reviews results to identify potential issues, duplicates, and items requiring validation.
  • Collects and reviews asset information, including configurations and running processes, to support investigations and vulnerability management.
  • Operates security monitoring tools and performs routine configuration or tuning tasks under guidance.
  • Participates in change management activities and follows established security operations procedures.
  • Communicates technical findings clearly to cybersecurity team members, internal partners, and vendors.
  • Assists with security product evaluations and recommends improvements based on documented requirements.
  • Supports security metrics, trend reporting, and assigned security awareness activities.
  • Uses approved AI-assisted capabilities to enrich alerts, correlate indicators, summarize evidence, and support basic investigation tasks.
  • Uses approved AI assistance to draft basic queries, investigation notes, reports, scripts, and stakeholder communications.
  • Validates AI-generated content against authoritative sources and follows approved-use, data-handling, human-review, documentation, and auditability requirements.
  • Maintains awareness of emerging threats, including AI-enabled phishing, social engineering, and enterprise AI misuse, and escalates relevant findings.
  • Performs other duties as assigned.

Benefits

  • The Bancorp Bank, N.A. is an EQUAL OPPORTUNITY EMPLOYER and will not discriminate on the basis of race, color, religion, gender, gender identity, sexual orientation, pregnancy, citizenship, national origin, age, disability, genetic information, veteran status or other protected category with respect to recruitment, hiring, training, promotion, and other terms and conditions of employment.
  • Employment with The Bancorp Bank, N.A. includes successfully passing a background check including credit, criminal, education, employment, OFAC, and social media background history.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service