Threat Analyst

ForesiteOverland Park, KS

About The Position

The Threat Analyst is an experienced security analyst moving into a specialist threat hunting role. This is not a junior position — candidates already have solid SOC fundamentals and can independently work complex alerts. On the Threat Analyst Team, you execute established threat hunts, write and tune detection logic, assist with clients utilizing Google Threat Intelligence, support active incidents, and serve as an escalation point above the standard analyst line.

Requirements

  • Experience equivalent to a Tier 2 SOC analyst, backed by solid incident response fundamentals and strong log analysis across endpoint, network, identity, and cloud telemetry.
  • Working knowledge of MITRE ATT&CK, Cyber Kill Chain, and the Diamond Model frameworks.
  • Working knowledge of TTPs and the ability to write queries to identify them based on threat intelligence reports, with the aptitude to become proficient in YARA-L 2.0 quickly.
  • Strong written documentation and communication skills for detailing complex hunt findings and client deliverables.
  • Relevant industry certifications (e.g., Security+, CySA+, PenTest+, SecurityX, GIAC, PJPT, PNPT, OSCP, or equivalent).

Nice To Haves

  • Hands-on experience with Google SecOps (Chronicle) and Google Threat Intelligence.
  • Proficiency with at least 2 of the following EDR/XDR consoles: SentinelOne, CrowdStrike, Microsoft Defender, Palo Alto Cortex, Cisco Secure Endpoint / AMP.
  • Scripting ability (e.g., Python) for lightweight automation and data enrichment.

Responsibilities

  • Execute established threat hunts across client environments, applying IOCs and TTPs supplied by senior staff and derived from threat intelligence.
  • Write and tune log-source-specific threat hunting and detection queries in YARA-L 2.0, extending and modifying existing queries to improve coverage.
  • Serve as an escalation point for SOC analysts, taking on complex, anomalous, or ambiguous alerts that exceed standard triage.
  • Provide threat hunting support during active incidents and contribute findings directly to incident response and incident command.
  • Enrich detections and investigations using Google Threat Intelligence and threat reports, while identifying process gaps and recommending improvements to reduce workload and improve response times.
  • Assist senior analysts with insider threat investigations and support the implementation and operation of dark web monitoring capabilities for enterprise clients using Google Threat Intelligence.
  • Document hunt results, detections, and lessons learned for client and internal operational use.

Benefits

  • Comprehensive Health & Wellness: Robust medical insurance options to keep you and your family healthy.
  • Employer-Covered Insurance: We fully provide employer-paid Dental coverage, as well as Short-Term (STD) and Long-Term Disability (LTD).
  • Recharge & Refuel: We believe in a true work-life balance. You’ll start with 3 weeks of paid vacation, plus additional sick leave and paid company holidays to ensure you have time to recharge.
  • Growth & Mentorship: Access to world-class training and mentorship. We support your career trajectory, whether you’re looking to deepen your technical skills or move into leadership.
  • Impactful Work: Help protect global clients using the latest AI-enhanced security tools and GCP native technologies.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service