Job Title: Cyber Threat Analyst Location: Remote, USA Reports to: Managing Director Employment Type: Full time Job Req ID: 2026 Req Begin Date: 8 /11/2026 About Vector3 Vector3, Inc., is an incident response firm supporting TMHCC Cyber and Professional Lines Group (CPLG) . Vector3 specializes in responding to Business Email Compromise (BEC) and Ransomware incidents, helping insured organizations investigate, contain, and recover from cyber events. About TMHCC Tokio Marine HCC (TMHCC) brings 50 years of service to the specialty insurance industry, today offering over 100 products to commercial customers in 180 countries around the world. Every policy we write is special, enabling our clients to do amazing things. From insuring the crops that feed us to the rock concerts that entertain us, to rescuing international travelers in trouble. Organic growth and over 60 successful acquisitions have grown our 2023 Gross Written Premium (GWP) to over $7.5 Billion. Our workforce has grown to 4,300 worldwide … big, but not so big that you cannot make a difference. Our Good Company values, including integrity, empowerment, and commitment to customer service, and a culture of innovation, communication, and collaboration make TMHCC a great place to work. What We Offer Competitive salary and employee benefit package Strong learning culture Growth perspectives 6% 401K match 20 days of PTO and 2 Floating Days Paid parental leave An opportunity to love what you do Job Summary Join us in shaping the future of TMHCC-CPLG as a contributor in our cyber extortion and threat intelligence function, Vector3. You will support ransomware and cyber extortion engagements by managing threat actor communications, documenting demands and responses, and helping the team maintain clear, professional, and timely negotiation records. You will also perform light threat intelligence research on threat actor trends, tactics, techniques, and tooling to support engagement strategy and case context. You will work closely with senior analysts, engagement leads, and related teams to help turn direct communications and threat observations into useful operational support for active matters. Key Responsibilities Relying on extensive security knowledge and advanced technical expertise, this role is accountable for the following responsibilities Relying on advanced knowledge and strong leadership skills, this role is accountable for the following responsibilities: Threat Actor Communications and Case Support: Support ransomware and cyber extortion engagements by assisting with direct written communications to threat actors under the direction of engagement leads. Draft, organize, and maintain communication logs, negotiation notes, timelines, demands, concessions, and other case records. Track actor responses, deadlines, proof-of-life requests, and other case developments to help keep the engagement team informed. Coordinate professionally with internal stakeholders and external partners to ensure communications are accurate, timely, and well documented. Preferred advanced degrees or certifications (CISSP, CISM, GCFE, GCFA, GREM, GBFA, GCIH, CFCE, CCE) are a plus Experience 2+ years of professional experience in cyber incident response, threat intelligence, investigations, customer communications, or a related analytical role. Education Minimum 4 Year's bachelor's degree in cyber security, Computer Science, Information Technology related degree. Business Controls and Policies Comply with all corporate policies and procedures. Cost Management Develop innovative ways to improve financials. Competencies Planning Contribute to the development of both short-term and long-term plans for designated area of the organization. Technical Excellence Develop the ability to manage threat actor communications, maintain precise case records, and perform accurate supporting research with minimal supervision. Write, or is a major contributor to, technical reports and documentation. Demonstrate strong attention to detail when handling communications, indicators, and case records. Documentation and Process Support: Prepare concise updates, summaries, and handoff notes for engagement leads and supporting teams. Support the maintenance of negotiation templates, playbooks, and operating procedures. Contribute to process improvements that increase consistency, responsiveness, and quality across communications and intelligence support. Threat Intelligence Research: Research threat actor groups, campaigns, malware families, tactics, techniques, and procedures that are relevant to active extortion cases. Collect and summarize open-source and internal intelligence that may help frame communication strategy or improve understanding of the threat. Maintain actor notes, reference material, and intelligence artifacts in approved repositories and tracking systems. Pay Transparency The pay range for this position is $87,400-$131,000 which includes geographic adjustments, where applicable. The pay range is the range THMCC, in good faith, believes is the range of compensation for this role at the time of this posting. The hired applicant will be offered pay within the entire range based on the candidate’s geographic location, qualifications, work experience, education, and/or skill level. The Company is fully committed to ensuring equal pay opportunities for equal work regardless of color, race, sex, national origin, sexual orientation, religion, age, veteran status, disability, pregnancy, citizenship status, genetic information, or any other basis protected by federal, state, or local pay equity laws. California → Use CA Fair Chance language. The Company will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable federal, state and local laws, such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC 1033(e))(the “VCCLEA”), which restricts financial institutions and insurers such as TMHCC from employing individuals with certain types of criminal convictions. Where the hiring and employment of individuals is not restricted by the foregoing, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law such as the California Fair Chance Act, the Los Angeles Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance, the San Diego Fair Chance Ordinance, and the San Francisco Fair Chance Ordinance.] As an insurance company, we comply with certain federal, state and local laws such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC 1033(e)), which restricts our ability to employ individuals with certain types of criminal convictions. Where not restricted by law and for criminal history not covered by this law, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law. You do not need to disclose your criminal history or participate in a background check until a conditional job offer is made to you. After making a conditional offer and running a background check, if the Company is concerned about a conviction that is directly related to the job, you will be given the chance to explain the circumstances surrounding the conviction or challenge the accuracy of the background report. The Company will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable federal, state and local laws, such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC 1033(e))(the “VCCLEA”), which restricts financial institutions and insurers such as TMHCC from employing individuals with certain types of criminal convictions. Where the hiring and employment of individuals is not restricted by the foregoing, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law such as the California Fair Chance Act, the Los Angeles Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance, the San Diego Fair Chance Ordinance, and the San Francisco Fair Chance Ordinance.] Applying our Mind Over Risk philosophy to writing insurance allows our customers to take on opportunity with confidence. That philosophy defines our way of thinking, unites us as a team, and differentiates us from our competitors. We are much more than just an insurance company; we are a good company. Equal Opportunity Employer TMHCC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity, genetic information, marital status, medical condition, national origin, physical or mental disability, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. #CPLG1 #VA-LI
Senior Lead Threat Analyst (Black Lotus Labs)
Lumen
Senior Intelligence Analyst - Threat Management Unit
Navy Federal Credit Union
Cybersecurity Threat & Incident Response Analyst
Mii
Cyber Threat Operations Analyst - Assistant Vice President
Db
Cyber Threat Analyst
All1033Allia
Sr Staff Threat Intelligence Analyst
NBCUniversal