Job Summary:
Calance US is seeking a Senior Cybersecurity / Risk Analyst to lead the response to high-priority cybersecurity incidents. This role involves overseeing incident handling, driving continuous improvement through detection logic development, and communicating effectively with technical teams and executives.
Responsibilities:
โข Serve as lead handler for escalated risk and cyber incidents; establish investigation strategy, ensure timely execution, and drive incident closure.
โข Conduct deep-dive analysis of security events using telemetry, endpoint/network evidence, and threat intelligence to determine scope, impact, and root cause.
โข Create, tune, and deploy new detection rules and analytics aligned to evolving threats and suspicious behaviors; reduce false positives and improve signal-to-noise.
โข Perform targeted hunts to discover emerging behaviors and translate findings into actionable detections, controls, and playbooks.
โข Partner with IT and security stakeholders to drive containment, remediation, and recovery actions across endpoints, identities, and cloud services.
โข Contribute to incident response process improvements, documentation standards, and after-action reviews; support development of tabletop exercise scenarios.
โข Produce clear, concise updates for leadership (status, impact, risk, and next steps) and deliver required incident reports and post-incident summaries.
Qualifications:
Required:
โข Four (4) or more years of hands-on cybersecurity experience in incident response, security operations, insider risk, threat detection, or a closely related function.
โข Demonstrated experience leading or handling escalated incidents, including triage, investigation, containment, remediation, and post-incident reporting in complex enterprise environments.
โข Proficiency with security telemetry and investigation workflows across endpoint and network data sources; experience using SIEM analytics (e.g., Splunk) and EDR tooling.
โข Working knowledge across multiple domains such as host analysis, network forensics, cloud environments, UEBA/anomaly detection, intrusion detection, threat research/intelligence, detection engineering, and data analysis.
โข Ability to develop or maintain automation using scripting (e.g., Python, PowerShell, Bash) and/or APIs to improve security operations.
โข Strong written and verbal communication skills, including the ability to produce executive-ready summaries and lead discussions with technical and non-technical stakeholders.
โข Demonstrated integrity and discretion in handling sensitive investigations and confidential data.
Preferred:
โข Experience with Tanium (or comparable endpoint management/telemetry platforms) and building integrations across enterprise security tools.
โข Experience implementing automation or orchestration in security operations (SOAR, APIs, pipelines, scripted workflows) to accelerate response and improve consistency.
โข Experience applying AI-assisted analytics for alert enrichment, correlation/deduplication, prioritization, and operational reporting.
โข Experience with insider risk programs, user/entity behavior analytics (UEBA), and behavior-based detection strategies.
โข Experience investigating and responding to threats in cloud and SaaS environments.
โข Experience mentoring analysts and contributing to training, playbooks, and tabletop exercise development.
โข Relevant industry certifications (e.g., GCIA, GCIH, GCFA, CISSP, or equivalent) and/or a bachelor s degree in a related field.
Company:
A CMMI Level 5 certified company offering IT services and solutions such as cloud, IT staffing, web & mobile development, and more. Founded in 2004, the company is headquartered in Buena Park, USA, with a team of 501-1000 employees. The company is currently Late Stage.