Abnormal AI is looking for an Embedded Detection Analyst to join our Threat Intelligence team. The Embedded Detection Program partners directly with our highest-value customers to rapidly identify, resolve, and demonstrate measurable improvements in detection performance. This role combines the investigative mindset of a SOC analyst with the customer-focused approach of a detection engineer—you'll own end-to-end customer outcomes by understanding pain points, using our detection analysis platform to identify root causes, implementing tuning solutions, and validating improvement. The ideal candidate will bring SOC or security operations experience, strong analytical skills, hypothesis-driven investigation approaches, and the ability to work systematically with established tools and processes. You'll work at the intersection of security operations, customer success, and detection quality, using our suite of analysis tools and AI-powered productivity enhancers to drive measurable customer value while contributing to the operational playbook that scales this program. Scope and scale: Own detection performance outcomes for 3-5 strategic customer accounts, with responsibility for measurable detection KPIs, cross-customer tuning patterns, and contributions to the programs playbook. As an Embedded Detection Analyst, you are a trusted technical partner for our strategic customers. You are highly motivated to understand what attackers are doing, why detections are behaving unexpectedly, and how to systematically improve customer outcomes. You're driven to stop email attackers and understand email security attack modes, TTPs, and threat patterns. You like to dive into the details of complex detection systems, understand their behavior, and analyze root causes. When detection output is unexpected, you investigate systematically until the issue is identified. You approach technical challenges methodically, following established playbooks while identifying opportunities for improvement and automation. You document your investigations clearly, maintaining comprehensive notes that can be used for future reference and team learning. You are a clear communicator who can explain technical detection issues to both technical and non-technical audiences, particularly customers and GTM stakeholders. You remain calm and responsive during high-pressure situations, including customer escalations and critical misclassifications You are a trusted team member—when you take on tasks, there is confidence they will be completed on time and to specification, with appropriate escalation when needed You primarily operate behind the scenes, partnering closely with GTM and customer-facing teams. While you may occasionally join customer discussions to explain detection findings, your core focus is investigation, tuning, and measurable detection improvement rather than ongoing account management. You measure your success by quantified detection improvements (for example, reduction in false positives/negative,improved precision/recall) across your portfolio of accounts and the entire system, not just by closing individual investigations.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed
Number of Employees
1,001-5,000 employees