2

Remote Cyber Defense Analyst Jobs (NOW HIRING)

Senior Security Analyst, Cyber Defense

$102K - $132K/yr

A senior member of the Cyber Defense team who leads detection and response work and provides day-to ... 100% remote candidates. What We Offer: At SPS Commerce, we are committed to ensuring that each ...

... to strengthen cyber defense and incident response operations. This role directly supports a ... Analyze logs from multiple sources, including packet captures, correlation engines, parsed security ...

Remote (Must be in Eastern or Central time zone) Owl Cyber Defense is a leader and trusted partner ... Perform market research, competitive analysis, and customer discovery to validate requirements and ...

Our partner is looking for a Cyber Threat Intelligence Analyst based in Netherlands. This remote ... defensive, educational, and professional-development purposes. * Remote working: Ability to work ...

... defense. Our team investigates and responds to security incidents, creates alerting rules ... This is a Remote position, but prefer candidates in the Eastern timezone Cellebrite is an equal ...

Showing results 21-40

Remote Cyber Defense Analyst information

See salary details

$44.5K

$107.5K

$151K

How much do remote cyber defense analyst jobs pay per year?

As of Sep 7, 2026, the average yearly pay for remote cyber defense analyst in the United States is $107,522.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $126,500.00 per year, depending on experience, location, and employer.

What does a remote cyber defense analyst do?

A Remote Cyber Defense Analyst is responsible for monitoring, analyzing, and responding to cybersecurity threats and incidents from a remote location. They work with security tools to detect suspicious activities, investigate potential breaches, and implement protective measures to safeguard an organization’s digital assets. Their role often involves collaborating with other IT and security professionals, providing reports, and staying updated on the latest cyber threats and best practices. By working remotely, they utilize secure connections and specialized software to perform their duties without being physically present at the company's location.

What are the key skills and qualifications needed to thrive as a remote cyber defense analyst?

To thrive as a Remote Cyber Defense Analyst, you need a strong understanding of network security, threat analysis, and incident response, often supported by a degree in cybersecurity or a related field. Familiarity with SIEM tools, intrusion detection systems, and certifications like CompTIA Security+, CEH, or CISSP are typically required. Analytical thinking, attention to detail, and effective communication are essential soft skills for excelling in this role. These skills and qualifications are crucial for proactively identifying and mitigating cyber threats, ensuring the security and resilience of an organization’s digital assets.

How do remote cyber defense analysts typically collaborate with on-site IT teams during a security incident?

Remote Cyber Defense Analysts often work closely with on-site IT teams through secure communication channels like video calls, instant messaging, and incident management platforms. During a security incident, they provide real-time analysis, guide the collection of forensic data, and help coordinate responses such as containment and remediation actions. Effective collaboration relies on clear protocols, regular updates, and thorough documentation to ensure rapid and unified responses. Building strong relationships and maintaining open lines of communication with on-site personnel are essential for seamless teamwork.

What is the difference between Remote Cyber Defense Analyst vs Remote Security Operations Center (SOC) Analyst?

AspectRemote Cyber Defense AnalystRemote Security Operations Center (SOC) Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CEH
Work EnvironmentRemote, often part of cybersecurity teamsRemote, within SOC teams monitoring security alerts
Industry UsageVarious industries including finance, healthcare, techPrimarily in cybersecurity firms and large organizations
Job FocusAnalyzing threats, developing defense strategiesMonitoring security alerts, incident response

The Remote Cyber Defense Analyst and Remote SOC Analyst roles share similar certifications and work environments but differ in focus. The Cyber Defense Analyst emphasizes proactive threat analysis and defense strategy, while the SOC Analyst concentrates on real-time monitoring and incident response within security operations centers.

More about Remote Cyber Defense Analyst jobs

What cities are hiring for Remote Cyber Defense Analyst jobs?

Cities with the most Remote Cyber Defense Analyst job openings:

What are the most commonly searched types of Cyber Defense Analyst jobs?

The most popular types of Cyber Defense Analyst jobs are:

What states have the most Remote Cyber Defense Analyst jobs?

States with the most job openings for Remote Cyber Defense Analyst jobs include:

Infographic showing various Remote Cyber Defense Analyst job openings in the United States as of August 2026, with employment types broken down into 93% Full Time, 4% Part Time, 2% Contract, and 1% Nights. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $107,522 per year, or $51.7 per hour.

Senior Security Analyst, Cyber Defense

Spscommerce

Remote

$102K - $132K/yr

Full-time

Re-posted yesterday


Job description

Description:

SPS Commerce is a leading provider of cloud-based supply chain management solutions, serving a global network of retail trading partners. We foster a collaborative and inclusive work environment where innovation and continuous improvement are highly valued. Join SPS Commerce and be part of a dynamic team that's transforming the global retail supply chain!

Position Summary:A senior member of the Cyber Defense team who leads detection and response work and provides day-to-day leadership of the SOC. This individual serves as a technical leader - setting the cultural tone, modeling high standards, and managing the SOC queue to keep work prioritized and moving. They collaborate closely across exposure management, security engineering, and cloud security.
This role owns escalated investigations, takes point on escalated incidents, and proactively hunts threats across the enterprise. Success is measured by timely, high-quality investigations, effective incident response, a well-prioritized SOC, and clear documentation that enables consistent operations and continuous improvement.

Key Responsibilities:

  • Lead alert triage and investigation: Serve as the escalation point for alerts raised by the managed SOC and monitoring systems. Pull together the full picture from whatever the investigation calls for: SIEM, EDR, identity and authentication activity, cloud audit trails, network and email telemetry, and other sources as the evidence leads. Reach accurate, defensible determinations under time pressure and decide what warrants escalation to a full incident.
  • Run incident response: Take point on confirmed higher-severity incidents: scoping, containment, coordinating with affected stakeholders, and keeping leadership informed with clear, timely updates. Document incidents thoroughly and drive them to genuine closure, not just ticket closure.
  • Hunt for what monitoring misses: Perform proactive threat hunting informed by current threat intelligence, surfacing coverage gaps and emerging risk before they become incidents.
  • Work AI and automation into the daily craft: Use AI-assisted tooling to accelerate investigation, summarization, and documentation, and identify where AI and automation can reduce repetitive manual work, speed response, or close gaps-partnering with engineering to make it real.
  • Partner across the team: Collaborate with exposure management on triage, prioritization, and remediation tracking, and work with security engineering and cloud security where investigations and detections cross over.
  • Sharpen detections and tooling: Execute established runbooks, identify stale or missing guidance, and feed concrete improvement requests back to engineering to strengthen detections, automations, and documentation.
  • Develop the SOC: Review SOC determination and escalation quality and provide coaching and feedback that helps analysts grow.
  • Participate in the team's on-call rotation.
  • Perform other duties as assigned.

Required Qualifications:

  • 5+ years in security operations, incident response, or threat detection, with senior-level depth in digital forensics and incident response (DFIR) and SOC work.
  • Hands-on investigation experience with a SIEM and an EDR platform-the specific products matter less than the ability to search, pivot across identity, cloud, and network log sources, and scope an incident end to end.
  • Sound evidence-handling practice and forensic fundamentals, including preserving and reasoning over disk, memory, and log artifacts.
  • A working understanding of adversarial behavior (e.g., MITRE ATT&CK).
  • Working familiarity with exposure management workflows-triage, prioritization, and remediation tracking.
  • Clear written and verbal communication, with the judgment to brief both engineers and executives appropriately.
  • A collaborative working style and genuine curiosity about security and technology-a seasoned professional who exercises sound judgment and collaborates effectively across a larger organization.
  • Internal candidates: SOC, security operations, or security engineering experience handling escalated investigations or incident response and working across detection, vulnerability management, or cloud security functions, with at least 1 year of SPS experience.
  • Key Skills: Digital forensics and incident response (DFIR), SIEM/EDR investigation, threat hunting, adversarial behavior analysis (MITRE ATT&CK), cloud security monitoring, cross-team communication and executive briefing.

Preferred Qualifications:

  • Experience with Crowdstrike as an EDR platform.
  • Experience with SOAR platforms.
  • Experience with Crowdstrike NG-SIEM.
  • Cloud security monitoring experience, primarily AWS, with some exposure to Azure and GCP, and container environments such as EKS.
  • Windows Defender XDR.
  • Python programming experience for scripting, automation, or tooling.
  • Familiarity with infrastructure-as-code (e.g., Terraform, CloudFormation) and CI/CD pipelines, and how to investigate and secure them.
  • Familiarity with one or more of Oracle, Snowflake, Databricks, and the Atlassian suite.
  • Proactive threat hunting and threat-intelligence experience.

Location:

This role follows a hybrid work model for candidates based in Minneapolis, MN and is also open to 100% remote candidates.
What We Offer:

At SPS Commerce, we are committed to ensuring that each employee's compensation reflects their unique experiences, performance, and skills in their role. The salary range for this role considers several factors, including education, relevant skills, work history, certifications, location, and more.

The annual salary range for this role is: $108,200.00 - $140,000.00 USD. The actual salary offered will be determined based on the factors listed above and may fall anywhere within the range.

SPS Commerce offers a comprehensive benefits package designed to support employees' health, well-being, and financial security. Benefits are country-specific and aligned with local laws and market practices.

#LI-TB1

Commitment to our Employees:

At SPS we power connections that drive the world of commerce forward, and our success depends on making strong decisions, fostering innovation, delivering unparalleled customer solutions, and driving outstanding business performance. We achieve this by creating an environment where every employee feels a true sense of belonging. We embrace diversity, equity, and inclusion, ensuring everyone feels accepted, valued, and empowered to make a meaningful impact.

We are committed to affirmative action and equal opportunity in all aspects of employment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.