Bestman Solutions
Oct 10, 2025
Full time
Senior Threat Detection Analyst Permanent | Hybrid We're looking for an experienced Threat Detection Senior Analyst to join a global leader in data science and customer insights. The team supports some of the world's most recognized brands, using data to drive smarter business decisions, and ensuring that data stays secure is central to everything they do. In this role, you'll take ownership of detection and response across complex, hybrid environments - from on-prem systems to modern cloud platforms. You'll play a key part in advancing the company's threat detection capabilities and ensuring that security operations stay one step ahead of emerging threats. What You'll Do Lead the creation and optimization of detection rules, alerting logic, and use cases across SIEM, EDR, and SOAR platforms. Analyze and investigate alerts across cloud and on-prem infrastructures to identify real threats and eliminate false positives. Strengthen visibility across Azure, AWS, and GCP environments, ensuring comprehensive monitoring and detection coverage. Drive threat hunting activities and develop hypotheses based on attacker TTPs and frameworks like MITRE ATT&CK. Collaborate with incident response, engineering, and intelligence teams to contain and resolve security incidents. Support continuous improvement of detection strategies and mentor analysts to uplift overall team capability. What You'll Bring Solid background in threat detection, SOC operations, or incident response. Deep understanding of SIEM, EDR, and cloud-native security tooling (eg, Microsoft Sentinel, Defender, GuardDuty, Chronicle). Hands-on experience developing and tuning detection content for cloud and hybrid environments. Strong grasp of adversarial tactics and techniques and how they translate to real-world detection logic. Excellent analytical and communication skills, with a calm and structured approach to problem-solving. Nice to Have Experience in threat hunting or purple teaming. Familiarity with automation or detection-as-code approaches. Certifications such as GCDA, GCIH, or AZ-500 are a plus.