Threat Detection & Response Analyst

SkyePoint DecisionsBethesda, MD
$95,000 - $110,000Remote

About The Position

SkyePoint Decisions is seeking a Threat Detection & Response Analyst to support a cybersecurity program by monitoring enterprise systems for malicious activity, investigating security events, and responding to cybersecurity incidents. The Analyst leverages security monitoring tools, threat intelligence, and incident response procedures to identify and mitigate threats impacting information systems, networks, cloud environments, and applications. This position works closely with Incident Response personnel, Vulnerability Management Analysts, Security Engineers, RMF teams, and system owners to strengthen cybersecurity defenses and protect mission-critical systems and sensitive research data. The role contributes to continuous monitoring, threat hunting, incident investigation, and security operations activities. This position is fully remote.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • Minimum 5 years of experience in cybersecurity operations, threat detection, security monitoring, incident response, or Security Operations Center (SOC) environments.
  • Experience applying MITRE ATT&CK techniques and adversary behaviors during investigations, threat hunting, or detection activities.
  • Experience investigating cybersecurity incidents and analyzing security events.
  • Knowledge of cyber threat tactics, techniques, and procedures (TTPs)
  • Knowledge of Security Operations Center (SOC) processes
  • Knowledge of Incident Response methodologies
  • Knowledge of Network security concepts
  • Knowledge of Endpoint security technologies
  • Familiarity with NIST RMF (SP 800-37)
  • Familiarity with NIST SP 800-53 Rev. 5
  • Familiarity with FISMA
  • Familiarity with Federal cybersecurity requirements
  • Strong analytical, troubleshooting, and communication skills.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Public Trust.

Nice To Haves

  • Security+ certification
  • CySA+ certification
  • GCIH (GIAC Certified Incident Handler) certification
  • GCIA (GIAC Certified Intrusion Analyst) certification
  • CISSP certification
  • CEH (Certified Ethical Hacker) certification
  • GSEC certification
  • CASP+ certification
  • CISM certification
  • Experience supporting HHS or other Federal civilian agencies.
  • Experience working in a Security Operations Center (SOC) environment.
  • Knowledge of MITRE ATT&CK Framework methodologies.
  • Experience supporting cloud security operations within Azure, AWS, or Google Cloud environments.
  • Familiarity with Continuous Diagnostics and Mitigation (CDM) initiatives.
  • Experience protecting healthcare, biomedical, or research-focused environments.

Responsibilities

  • Conduct proactive threat hunting activities using intelligence-driven and hypothesis-based methodologies.
  • Analyze threat actor tactics, techniques, and procedures (TTPs) to identify potential compromise within environments.
  • Map observed adversary behaviors, indicators, and attack patterns to the MITRE ATT&CK framework to support detection engineering, threat hunting, and risk analysis.
  • Provide threat findings, indicators, and investigations supporting RMF activities, risk assessments, POA&M development, continuous monitoring, and cybersecurity governance processes.
  • Monitor security tools, dashboards, and alerts to identify potential cybersecurity threats and suspicious activity.
  • Analyze events from endpoint, network, cloud, and security monitoring platforms.
  • Perform triage of security alerts to determine validity, severity, and potential impact.
  • Identify indicators of compromise (IOCs), attack patterns, and emerging threats.
  • Escalate significant security events in accordance with established procedures.
  • Investigate cybersecurity incidents, security events, and anomalous activity.
  • Conduct forensic review of logs, alerts, and system data to determine root cause and scope.
  • Correlate information from multiple security tools and data sources.
  • Document findings, recommendations, and lessons learned from investigations.
  • Support post-incident reviews and corrective action planning.
  • Provide threat and incident-related information supporting risk assessments and POA&M management activities.
  • Assist with audit readiness and security assessment activities when requested.

Benefits

  • Certification incentive program
  • PTO
  • Floating federal holiday options
  • HMO and High Deductible plans with Health Savings Accounts [HSAs]
  • Flex Spending Accounts [FSAs]
  • Full Dental Plans
  • Vision
  • ST/LT Disability
  • Life Insurance
  • 401k matched
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service