Cybersecurity Threat & Incident Response Analyst
Indexed description
The ideal candidate has hands-on experience with incident investigations, Microsoft security technologies, log analysis, endpoint security, and stakeholder communication. This position requires strong analytical skills, attention to detail, and the ability to manage investigations from initial detection through closure.
Responsibilities
- Investigate and respond to cybersecurity incidents across endpoints, identities, email, and cloud environments, managing the full response lifecycle from detection through resolution.
- Review and analyze alerts from SIEM, EDR, DLP, and other security monitoring platforms, distinguishing genuine threats from false positives and translating findings into clear, actionable next steps.
- Lead incident triage, including evidence collection, root cause analysis, and thorough documentation that supports informed decision-making and long-term improvements.
- Investigate data loss prevention alerts, identifying patterns of unauthorized access, policy violations, data exposure, and potential exfiltration.
- Coordinate containment and remediation activities across teams, ensuring threats are addressed efficiently and normal operations are restored.
- Conduct in-depth threat investigations, using behavioral and technical indicators to assess risk and protect sensitive organizational data.
- Maintain accurate incident metrics and build detailed investigation records, capturing findings and response actions to support reporting and continuous improvement.
- Contribute to after-hours incident response activities as needed, bringing the same rigor and focus to time-sensitive situations.
- Degree in Cybersecurity, IT, or Computer Science and/or 3+ years of experience (IT or Cybersecurity);
- Experience working with SIEM, EDR, and DLP platforms
- Strong understanding of attacker techniques and the MITRE ATT&CK framework
- Experience performing log analysis and security investigations
- Experience with a ticketing system (e.g., ServiceNow, Jira)
- Strong attention to detail and ability to communicate findings clearly
- CompTIA Security+, CySA+, or similar certification
- Hands-on experience with KQL, SPL, or similar query languages
- Experience developing security use cases or investigation playbooks.
- Familiarity with cyber threat intelligence, IOC analysis, and attacker TTP research.
- Knowledge of data classification, information protection, and data governance concepts.
MiTek Perks
- Generous time off including Paid Time Off, 13 annual holidays, and volunteer time off
- Day One Medical/Rx, Dental and Vision Plans
- Family friendly benefits including Paid Caregiver Leave, Paid Parental Leave and Adoption Reimbursement
- Performance/Incentive bonuses
- Career advancement, training opportunities, Employee Resource Groups, and tuition reimbursement
- Retirement programs including Matching 401(k) Contributions and Profit Sharing
- Employer paid Short-Term Disability, Long-Term Disability and Life Insurance
- myFlexPay partner – allows you to track, manage and access your pay anytime
MiTek is an E-Verify and Drug and Tobacco-Free Workplace.
We are an equal opportunity employer; and all qualified applicants will receive consideration for employment without regard to race, color, creed, religion, national origin, ethnicity, physical or mental disability, sex (including pregnancy, sexual orientation, gender identity or expression, or transgender status), age (40 and over), genetic information (including family medical history), veteran status, or any other protected characteristic.
For accommodation to assist with completing this application, please contact Human Resources at +1 314-434-1200.
www.mii.com
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search