Threat Defense Analyst, L2
Listed on 2026-07-02
-
IT/Tech
Cybersecurity, Security Management & Operations, Network Security, Information Security
- Location 120 Brentwood Commons Way, Suite 500, Brentwood, TN, 37027, United States
- Base Pay $65,000.00 - $70,000.00 / Year
- Employee Type FT Exempt
- Manage Others No
The Fortified Threat Defense Center provides 24x7x365 managed security services for healthcare customers. Members of the Threat Defense team monitor and alert on key security technologies within each customer environment, identify security events, perform analysis, create new and tune existing detection rules, and integrate with client incident response activities. In this role, the Threat Analyst 2 will monitor, detect, analyze, and report on security alerts discovered within Fortified Health Security’s customer infrastructures.
The Threat Analyst 2 will then report all investigated and validated findings to the proper customer in accordance with the approved communication plan.
This position is designated for the swing shift and requires availability Sunday through Wednesday from 3:00 PM CST to 2:00 AM CST.
Essential Job FunctionsThe following duties are normal for this position. The omission of specific statements of duties does not exclude them from being expected of this position if the work is similar, related, or a logical assignment for this position. Other duties may be required.
- Partner with clients on service delivery execution of all LOBs including but not limited to Managed SIEM, Phishing, EDR, IoMT, & DLP.
- Perform and document initial incident investigations.
- Present alerts, metrics, and remediation tasks to customers via approved communication plans.
- Work with associates to continuously improve security services through product tuning and maturity.
- Proactively and iteratively search through logs to detect advanced threats that are unknown to current security solutions.
- Exercise high‑level multi‑tasking skills by managing events in multiple systems, applications, and other priorities.
- Respond to incidents and client inquiries timely and professionally.
- Generate end‑of‑shift reports for documentation and knowledge transfer to subsequent analysts on duty.
- Remain up‑to‑date on latest security threats and events.
- Monitor the “health” of key technologies during the shift.
- Intermediate/Advanced level understanding of incident response, analytical intelligence, playbook management, relationship management, technical presentation, detection & suppression rule management, scripting (Python, Bash, Power Shell), and compliance frameworks (NIST, HIPAA, HITRUST, PCI).
- Advanced level understanding of attack frameworks, troubleshooting & root cause analysis, advanced documentation, emotional intelligence, written & verbal communication, security platform health management, security platform log analysis, Linux OS & events, Windows OS & events, healthcare operational knowledge, endpoint security knowledge, tools & best practices, user security knowledge, tools & best practices, network security knowledge, tools & best practices, cloud security knowledge, tools & best practices, data security knowledge, tools & best practices.
- Fluent in intrusion detection/prevention systems, firewalls, endpoint detection & response systems, anti‑virus systems, DLP, vulnerability management, creating and managing phishing campaigns, and cloud infrastructure.
- Solid understanding of network security concepts and defense in depth.
- Knowledge of security incident and event management (SIEM), log analysis, network traffic analysis, malware investigation/remediation, SIEM correlation logic, and alert generation.
- Demonstrated ability to analyze, triage, and remediate security incidents.
- Advanced knowledge of current threat landscape (threat actors, APT, cyber‑crime, etc.).
- Solid understanding of OSM model, network protocols, and information security concepts.
- 2+ years of direct info sec experience and/or an Associate’s degree in CS/MIS preferred.
- 2+ years hands‑on experience with security tools such as scanners, monitoring and detection, malware protection, security analysis tools, and compliance tools (both network and host‑based solutions).
- 2+ years technical experience in the security aspects of multiple…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).