Threat Detection and Response Analyst
Saige Partners
Job Description Join us at Saige Partners, where we aim to shape your future and be the solution that propels your career forward! For more information, feel free to reach out to Christine Gonzalez via email at View email address on click.appcast.io Position: Security Detection and Response Lead(Contract Role) Onsite in San Jose, CA What You'll Do Lead enterprise-wide security monitoring and threat detection across SIEM, EDR, network, endpoint, and cloud security platforms.
• Design, implement, validate, tune, and optimize detection rules, correlation logic, dashboards, and alerting use cases.
• Continuously improve detection quality and reduce false positives to strengthen operational efficiency and signal-to-noise ratio.
• Ensure effective log ingestion, parsing, normalization, field extraction, and telemetry coverage across critical systems and infrastructure.
• Support onboarding and integration of new log sources, security tools, and telemetry pipelines into the security monitoring environment.
• Lead investigation and response activities for security incidents across enterprise systems.
• Serve as the technical lead during high-severity incidents, coordinating containment, eradication, recovery, and cross-functional response efforts with IT, cloud, and infrastructure teams.
• Perform advanced analysis to determine incident scope, root cause, impact, and recommended remediation actions.
• Conduct post-incident reviews and drive improvements to detections, playbooks, and response procedures based on lessons learned.
• Lead proactive threat hunting efforts using SIEM, NDR, EDR, CASB, and cloud telemetry to identify advanced or evasive threats.
• Investigate suspicious behaviors including lateral movement, privilege escalation, persistence, and data exfiltration attempts.
• Map detections, investigations, and threat hunting activities to the MITRE ATT&CK framework.
• Mentor and guide SOC analysts and incident responders in threat analysis, investigation techniques, and response workflows.
• Develop, maintain, and improve incident response runbooks, threat models, triage procedures, and detection documentation.
• Track and report on security operations metrics such as MTTD, MTTR, detection coverage, and recurring incident trends.
• Partner with IT, infrastructure, engineering, and vulnerability management teams to prioritize remediation and strengthen overall security posture.
• Collaborate across technical and non-technical teams to ensure rapid, effective response to security incidents and continuous improvement of detection and response capabilities. Requirements
Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field; Master's degree preferred.
• 6-8 years of experience in security operations, threat detection, incident response, or related cybersecurity roles.
• Hands-on experience with SIEM platforms such as Splunk, including rule creation, correlation logic, dashboarding, and log analysis.
• Strong experience investigating alerts and incidents across endpoint, network, operating system, and cloud environments.
• Deep understanding of incident response methodologies, threat investigation workflows, and root cause analysis.
• Solid knowledge of enterprise log sources including Windows/Linux servers, firewalls, IDS/IPS, endpoints, and cloud-native services.
• Strong knowledge of detection engineering, MITRE ATT&CK techniques, adversary behaviors, and threat hunting methodologies.
• Experience with cloud environments such as AWS, Azure, or similar, including security monitoring and logging services.
• Familiarity with SOAR, automation, or orchestration tools is a plus.
• Strong analytical, problem-solving, and decision-making skills in fast-paced operational environments.
• Excellent written and verbal communication skills, with the ability to clearly present findings to both technical and non-technical stakeholders.
• Ability to lead incident response efforts, mentor team members, and collaborate effectively across diverse global teams.
• Relevant certifications such as CISSP, GCIH, GCIA, Security+, Splunk Security certifications, or comparable credentials are a plus. Join our team and help shape the future of enterprise storage technology. Your work will have a global impact, powering performance-driven solutions for the world's most demanding applications. About Saige Partners: Recognized as one of the fastest-growing technology and talent companies in the Midwest, Saige Partners believes in nurturing individuals with a zeal for success. We're committed to building careers, not just jobs. Our belief in our employees as our most valuable asset is reflected in our comprehensive benefits package and convenient weekly payment solutions, promoting health and a positive work-life balance. Explore this opportunity and more at Job Requirements NVMe Solid State Drives (SSDs)
Meet Your Recruiter Christine Gonzalez
• Design, implement, validate, tune, and optimize detection rules, correlation logic, dashboards, and alerting use cases.
• Continuously improve detection quality and reduce false positives to strengthen operational efficiency and signal-to-noise ratio.
• Ensure effective log ingestion, parsing, normalization, field extraction, and telemetry coverage across critical systems and infrastructure.
• Support onboarding and integration of new log sources, security tools, and telemetry pipelines into the security monitoring environment.
• Lead investigation and response activities for security incidents across enterprise systems.
• Serve as the technical lead during high-severity incidents, coordinating containment, eradication, recovery, and cross-functional response efforts with IT, cloud, and infrastructure teams.
• Perform advanced analysis to determine incident scope, root cause, impact, and recommended remediation actions.
• Conduct post-incident reviews and drive improvements to detections, playbooks, and response procedures based on lessons learned.
• Lead proactive threat hunting efforts using SIEM, NDR, EDR, CASB, and cloud telemetry to identify advanced or evasive threats.
• Investigate suspicious behaviors including lateral movement, privilege escalation, persistence, and data exfiltration attempts.
• Map detections, investigations, and threat hunting activities to the MITRE ATT&CK framework.
• Mentor and guide SOC analysts and incident responders in threat analysis, investigation techniques, and response workflows.
• Develop, maintain, and improve incident response runbooks, threat models, triage procedures, and detection documentation.
• Track and report on security operations metrics such as MTTD, MTTR, detection coverage, and recurring incident trends.
• Partner with IT, infrastructure, engineering, and vulnerability management teams to prioritize remediation and strengthen overall security posture.
• Collaborate across technical and non-technical teams to ensure rapid, effective response to security incidents and continuous improvement of detection and response capabilities. Requirements
Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field; Master's degree preferred.
• 6-8 years of experience in security operations, threat detection, incident response, or related cybersecurity roles.
• Hands-on experience with SIEM platforms such as Splunk, including rule creation, correlation logic, dashboarding, and log analysis.
• Strong experience investigating alerts and incidents across endpoint, network, operating system, and cloud environments.
• Deep understanding of incident response methodologies, threat investigation workflows, and root cause analysis.
• Solid knowledge of enterprise log sources including Windows/Linux servers, firewalls, IDS/IPS, endpoints, and cloud-native services.
• Strong knowledge of detection engineering, MITRE ATT&CK techniques, adversary behaviors, and threat hunting methodologies.
• Experience with cloud environments such as AWS, Azure, or similar, including security monitoring and logging services.
• Familiarity with SOAR, automation, or orchestration tools is a plus.
• Strong analytical, problem-solving, and decision-making skills in fast-paced operational environments.
• Excellent written and verbal communication skills, with the ability to clearly present findings to both technical and non-technical stakeholders.
• Ability to lead incident response efforts, mentor team members, and collaborate effectively across diverse global teams.
• Relevant certifications such as CISSP, GCIH, GCIA, Security+, Splunk Security certifications, or comparable credentials are a plus. Join our team and help shape the future of enterprise storage technology. Your work will have a global impact, powering performance-driven solutions for the world's most demanding applications. About Saige Partners: Recognized as one of the fastest-growing technology and talent companies in the Midwest, Saige Partners believes in nurturing individuals with a zeal for success. We're committed to building careers, not just jobs. Our belief in our employees as our most valuable asset is reflected in our comprehensive benefits package and convenient weekly payment solutions, promoting health and a positive work-life balance. Explore this opportunity and more at Job Requirements NVMe Solid State Drives (SSDs)
Meet Your Recruiter Christine Gonzalez
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Threat Detection and Response Analyst in San Jose, CA vacancy
$80 - $85 per hour
...Job Description Job Title : Threat Detection & Response Analyst Position Description : Protingent Staffing has an exciting contract Threat Detection & Response Analyst with our client located in San Jose, CA. Job Responsibilities: Monitor, triage, and investigate...SuggestedContract work$80 - $85 per hour
Protingent is looking for a Threat Detection & Response Analyst for a contract position located in San Jose, CA. The role involves monitoring and investigating security alerts, analyzing security event logs, and supporting incident response activities. Candidates should...SuggestedContract work$156k - $316.8k
...Responsibilities The mission of TikTok's Global Security Organization is to build and earn... ...remains safe from external or internal threats, and that we comply with global regulations... ...experience. As part of the Threat Detection and Response function, the Detection Engineering...SuggestedTemporary workWork experience placementLocal area- Fortinet, Inc. is seeking a Security Operations Centre (SOC) Analyst for its FortiCloud SOC-as-a-Service team in Sunnyvale, California. This highly technical role involves monitoring security events, assessing risks, and collaborating with global customers to enhance their...Suggested
$72.96k - $115.2k
...Job Description Incident Response Center (Analyst) Job Title - IRC Analyst Summary... ...layer of defense responsible for quick detection and incident response using various monitoring... ..., MOPs, Runbooks, and Playbooks. Threat Intelligence, Critical Event...SuggestedFull timeTemporary workRemote workFlexible hoursShift workNight shift- Job Overview Engineering Manager - Threat Detection Engineering & Threat Research Teams HPE Threat Labs seeks an experienced engineering... ...both technical innovation and operational excellence. Responsibilities Wear dual hats: oversee software engineering projects to implement...Work experience placement
$120k - $180k
...CICD Engineer CrowdStrike is looking for a CICD engineer to join the AIDR (AI detection and response) platform team. You'll be instrumental in building and supporting our development team's SDLC (software development lifecycle) process by building and maintaining CI...Work experience placementWork at officeLocal area- POSITION SUMMARY The Information Security Analyst reports to Executive Director of ITSS... ...This position focuses on threat and vulnerability management with exposure... ...identification, protection and compliance, threat detection, incident response plan development and annual review,...Work at officeMonday to Friday
- We are seeking a dynamic and proactive Incident Response Analyst to join our team at [Datacenter]. This role is essential for maintaining... ...high humidity, high temperature, CRAC/CRAH alarms Water leak detection or environmental sensor deviations Assess the severity and...Night shift
$187.7k - $275.28k
...organizations trust Proofpoint to stop threats, prevent data loss, and build resilience... ...Bold in how we dream and innovate Responsive to feedback, challenges and opportunities... ...strategy, push forward advanced threat detection and defense capabilities, and take point...Work at officeFlexible hours$154k - $220k
...intelligent systems to stay ahead of evolving threats. We believe in transparency and value... ...Engineering. You will join the team responsible for building the world's largest cloud security... ...systems, including expertise in anomaly detection event correlation and incident...Full timeWork at officeLocal areaWorldwide3 days per week$23 - $29 per hour
Information Security Analyst I - Santa Clara, CA WhiteDog is seeking... ...critical duties and responsibilities that must continue to be performed... ...incident. Provide threat and vulnerability analysis as... ...solutions (firewall and intrusion detection systems). Knowledge of TCP/...Hourly payFull timeWork at officeRemote work$120k - $180k
## Engineer III, SDET - AI Detection and Response (AIDR) (Hybrid)Applylocations: USA - Sunnyvale, CA: USA - Austin, TX: USA - Redmond, WAtime type: Full timeposted on: Posted 2 Days Agojob requisition id: R28442As a global leader in cybersecurity, CrowdStrike protects...Contract workWork experience placementWork at officeLocal area$238.25k
...Immigration sponsorship is not available for this position Responsibilities: Be responsible for working with business... ...and cost impacts; and Utilizing Production Monitoring and Detection to ensure that bill runs, invoices, and workflows are functioning...Work at officeRemote work- ...Title: SOC Analyst Location: San Jose, CA 95134 Schedule: Onsite M-F... ...level cybersecurity professional responsible for monitoring, analyzing, and responding... ...Sentinel and Splunk to detect, investigate, and remediate security threats. The analyst will perform advanced...Contract workShift work
$100k - $145k
...in machine learning and behavioral-based detection, allow our customers to not only defend... ...Science Machine Learning Operations and Response Team is looking for a Detection Engineer... ...questions and concerns regarding customer threat detectionsWhat You'll NeedRequired:...Work experience placementWork at officeLocal areaRemote work$117k - $143k
...Security Operations Centre (SOC) Analyst Fortinet is looking for a Security... ...security events, identifying threats, assessing risks, and working with... ...– Saturday), 8am – 4pm. Responsibilities: Monitor SOC alerts to detect potential threats Use threat intelligence...Work experience placementWeekend workWeekday work$70k - $100k
...infrastructure, validate emerging threats, and support remediation and... ...detail-oriented Security Analyst - Threat Hunting /... ...analysis, and online fraud detection, along with strong analytical... ...fully remote candidates. Responsibilities Proactively conduct threat...Work at officeRemote workWorldwideFlexible hours- ...Data Analyst Job Duties: Design and build new data set processes for modeling... ...exp) o Has done some kind of fraud detection – model detection, o Could have Finance... ...· What will this person’s day-to-day responsibilities be? Ability to explore data source, reporting...
$114.4k - $142.95k
...we want to make smarter, greener, in a responsible and sustainable way. Our technology starts... ...) to influence distributor purchases.* Detection of any future supply issues, and resolution... ...AnalystAnalytics ConsultantOperations Analyst #J-18808-Ljbffr STMicroelectronicsLive inWork at office- ...systems to stay ahead of evolving threats. We believe in transparency and... ...are looking for an Insider Risk Analyst – SkillBridge Intern to join our... ...data through proactive detection, behavioral analysis, and rapid incident response. This role is unique in its scope...InternshipWork at officeLocal areaRemote work
$151.5k - $245.03k
...as a senior technical expert in the Product Security Incident Response Team (PSIRT), driving deep technical analysis, root cause determination... ...alignment with product, engineering, legal, privacy, and threat intelligence teams on vulnerability response strategies....Full timeWork at office$70k - $72k
...Risks is looking for a dedicated GSOC Analyst to join our renowned security team... ...night shift, 7:00 pm-7:00 am. Key Responsibilities: Act as the initial point of... ...control systems, and alarm systems to detect and respond to potential threats swiftly. Conduct real‑time...Flexible hoursShift workNight shiftDay shift$87k - $139.5k
...We are seeking a driven and analytical MDR Shift Analyst to join the Unit 42 Managed Detection and Response (MDR) team at Palo Alto Networks. In this role, you... ...help monitor customer environments, detect potential threats, and respond to cyber incidents affecting our...Remote workVisa sponsorshipWork visaShift work$153k - $170k
Senior Analyst, Corporate Real Estate Cohesity Santa Clara, CA, US... ...defend against cybersecurity threats with comprehensive data... ...backup snapshots, AI-based threat detection, monitoring for malicious behavior... ...Real Estate (CRE Finance) is responsible for providing strategic...Hourly payFull timeWork at office2 days per week3 days per week- GSOC Security Analyst The Global Security Operations Center (GSOC)... ...of GSOC Account Manager, is responsible for assisting company personnel... ...systems and sources to detect potential risks Notifying and... ...of leadership Able to analyze threats for real time impact to the client...Weekly payDaily paidLocal areaWorldwideShift workDay shift
- ...breach containment platform identifies and contains threats across hybrid multi-cloud environments - stopping the... ...wellgoverned People data platform. The People Data Analyst is an individual contributor responsible for building, maintaining, and evolving the People data...Contract workImmediate start10 hours per week
$172.1k - $258.6k
...Legal Data Analyst, Applied Data Science Imagine what you could do here. At Apple,... ...that drive operational excellence. Responsibilities Leverage AI tools and techniques... ...Use AI-assisted data profiling, anomaly detection, and pattern recognition to identify data...Contract workRelocation$92.8k - $136.07k
...People Data Analyst Proofpoint is a global leader in human- and agent-centric cybersecurity... ...organizations trust Proofpoint to stop threats, prevent data loss, and build resilience... ...Bold in how we dream and innovate Responsive to feedback, challenges and...Flexible hours- ...domains and websites, validating real-world threats, and pursuing takedown actions during... ...of Bolster’s protection platform. Responsibilities Review and assess emerging phishing, impersonation... ..., redirects, and related artifacts to detect attack patterns and emerging abuse...Flexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Threat Detection and Response Analyst. Be the first to apply!
Related searches

