Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
ECS Federal LLC logo

Cyber Threat Analyst (Tier 2)

ECS Federal LLC
Posted 5 hours ago
🇺🇸United States🏠Remote📁Engineering & Development
Is this job info correct?

Everforth ECS is seeking a Cyber Threat Analyst (Tier 2) to work remotely . ECS is seeking a Cyber Threat Analyst (Tier 2) to support a multi-tenant Managed Security Services Provider (MSSP) environment protecting commercial customers and internal systems. Please Note: This position is contingent upon contract award. This position serves as a senior investigator within the Security Operations Center, leading complex investigations, supporting incident response activities, improving detection capabilities, and mentoring junior analysts. The ideal candidate possesses strong investigative and incident response experience, is capable of independently managing complex security events, and can operate effectively in a fast-paced MSSP environment supporting multiple customers simultaneously. Responsibilities Lead investigations involving malware, ransomware, business email compromise (BEC), account compromise, insider threats, cloud attacks, and advanced persistent threats. Perform incident response activities including forensic triage, scope determination, evidence collection, containment recommendations, root cause analysis, and post-incident reporting. Serve as the primary escalation point for Tier 1 analysts during complex investigations and security events. Manage multiple concurrent customer investigations while meeting service-level objectives and communication requirements. Coordinate response efforts with customers, IT teams, system administrators, and executive stakeholders. Develop detailed technical incident reports, executive summaries, and customer-facing communications. Conduct forensic triage across endpoints, servers, cloud platforms, email environments, and identity providers. Analyze and correlate telemetry from SIEM, EDR, SOAR, NDR, cloud monitoring platforms, identity providers, email security tools, and threat intelligence sources. Recommend, validate, test, and optimize detection content aligned with MITRE ATT&CK techniques and observed adversary behavior. Conduct targeted threat hunts based on intelligence requirements, active investigations, or emerging threats, and contribute findings to detection improvement efforts. Investigate security events across on-premises, cloud, SaaS, endpoint, network, and identity environments. Analyze attacker behavior and map observed activity to MITRE ATT&CK techniques to support reporting, threat tracking, and investigation activities. Utilize commercial and open-source threat intelligence to enrich investigations and identify emerging threats. Collaborate with Detection Engineering and SOAR teams to improve alert fidelity, reduce false positives, and increase operational efficiency. US. Citizenship with the ability to obtain and maintain a Secret Security Clearance. Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field. Relevant experience may be substituted for education. Minimum of 5 years of cybersecurity experience . Minimum of 3 years supporting Security Operations Center (SOC), MSSP, MDR, Incident Response, Threat Detection, or Cyber Defense operations. Strong understanding of modern attacker methodologies, threat actor tactics, techniques, and procedures (TTPs), and attack lifecycles. Experience investigating cybersecurity incidents from initial detection through containment, eradication, and recovery. Experience operating enterprise SIEM platforms including Microsoft Sentinel, Elastic, Splunk, QRadar, or equivalent technologies. Experience with EDR technologies including Microsoft Defender for Endpoint, CrowdStrike Falcon, Trellix, SentinelOne, or equivalent platforms. Experience with SOAR platforms, case management systems, and security automation technologies. Experience investigating Microsoft 365, Entra ID, Azure, AWS, or hybrid-cloud environments. Experience investigating identity-focused attacks including account compromise, privilege escalation, token abuse, suspicious authentication activity, and MFA-related attacks. Strong understanding of Windows, Linux, networking, DNS, email security, web technologies, and cloud architectures. Experience analyzing firewall, proxy, VPN, DNS, endpoint, NDR, identity, cloud, and authentication logs. Experience creating custom detections using KQL, Sigma, SPL, Elastic Query Language, or equivalent detection technologies. Ability to correlate events from multiple data sources and construct detailed attack timelines. Ability to perform ad hoc scripting and automation using Python, PowerShell, or similar languages. Strong written and verbal communication skills. Ability to independently manage multiple concurrent investigations while meeting customer and operational requirements.

Similar jobs

Similar jobs

Lumen logo

Senior Lead Threat Analyst (Black Lotus Labs)

Lumen

🇺🇸United States21 hours ago
AS

Cloud Threat Analyst

Asrcfh

🇺🇸United StatesYesterday
Sentinel logo

Threat Investigation Analyst

Sentinel

🇺🇸United StatesYesterday
Navy Federal Credit Union logo

Senior Intelligence Analyst - Threat Management Unit

Navy Federal Credit Union

🇺🇸United States4 days ago
Mii logo

Cybersecurity Threat & Incident Response Analyst

Mii

🇺🇸United States5 days ago
All1033Allia logo

Cyber Threat Analyst

All1033Allia

🇺🇸United States1 weeks ago