Cybersecurity Senior Threat Analyst
Job Description
Hybrid in Wilmington, DE, with a role built for independent, advanced technical leadership. This Senior Threat Analyst position operates as a senior technical escalation layer for complex cybersecurity events and investigations, with hands-on ownership across detection, threat intelligence, vulnerability analysis, threat hunting, penetration testing support, and audit technical response. The role also helps raise the team’s capability through standards, coaching, and measurable operational improvements.
What you bring matters here: advanced security operations expertise, the ability to evaluate complex evidence, and the communication skills to translate technical findings into actionable recommendations for technical and nontechnical stakeholders.
Open for at least five days from the posting date.
Responsibilities
- Serve as the senior technical escalation point for complex, high-impact, or ambiguous cybersecurity events, independently leading investigation, scoping, evidence analysis, containment, mitigation, eradication, recovery validation, and post-incident technical review.
- Conduct advanced threat intelligence analysis with minimal oversight, correlating intelligence sources, campaigns, vulnerabilities, attacker behaviors, targeting information, and environmental exposure.
- Develop actionable intelligence to support detection, incident response, threat hunting, vulnerability prioritization, and management decision-making.
- Define and lead proactive threat-hunting activities and establish detection priorities.
- Develop, test, tune, validate, and review security-monitoring rules, queries, correlation logic, and use cases, including identifying telemetry gaps and reducing false positives.
- Lead complex vulnerability analysis using exploitability, active threat intelligence, asset criticality, exposure, attack paths, business context, and existing controls.
- Perform validation, remediation review, retesting, and technical closure.
- Independently perform or lead assigned penetration tests, security assessments, and technical testing activities with minimal oversight, including preparation, execution, analysis, documentation, remediation guidance, and retesting.
- Provide senior technical support for internal and external audits, regulatory examinations, and control assessments by identifying required evidence, validating control operation, responding to complex technical requests, explaining security processes and findings, and supporting remediation of audit issues.
- Provide advanced technical support for cybersecurity platforms, integrations, queries, dashboards, scripts, automation, and analytical workflows, and lead technical evaluations of security products and capabilities.
- Establish and improve standards for investigation, incident response, threat hunting, detection, vulnerability analysis, and technical documentation.
- Develop and review procedures, playbooks, runbooks, and analytical guidance.
- Mentor Cybersecurity Threat Analyst I and II personnel by reviewing complex work, providing technical coaching, and helping develop capabilities across investigation, detection, threat intelligence, vulnerability analysis, scripting, incident response, and penetration testing.
- Lead significant operational improvement initiatives in collaboration with cybersecurity engineering, infrastructure, application, cloud, identity, data, audit, risk, and other teams to resolve complex security issues and improve controls.
- Develop advanced threat assessments, vulnerability reports, incident summaries, technical briefings, metrics, and recommendations, and communicate significant findings to management and stakeholders.
- Use approved AI-assisted capabilities for advanced analysis, threat research, detection development, vulnerability analysis, scripting, automation, and documentation, and evaluate generated conclusions for accuracy, provenance, unsupported assumptions, and potential security impact before use.
- Perform other duties as assigned.
Requirements
- Bachelor’s degree in cybersecurity, information technology, computer science, or a related field, or an equivalent combination of education, training, and progressively responsible experience.
- Minimum of 5 years of cybersecurity, security operations, incident response, threat analysis, vulnerability management, penetration testing, system administration, networking, or related security experience.
- Demonstrated experience independently leading complex cybersecurity investigations or technical response activities.
- Advanced working knowledge of security monitoring, incident response, threat intelligence, vulnerability management, threat hunting, and common attacker techniques.
- Strong understanding of TCP/IP networking, DNS, web protocols, authentication, operating systems, cloud environments, and enterprise security technologies.
- Significant hands-on experience with technologies such as SIEM, EDR/XDR, SOAR, vulnerability management, threat intelligence, and comparable enterprise security platforms.
- Demonstrated ability to develop advanced security queries, detections, analytical content, scripts, or automation using AQL, KQL, SPL, SQL, Python, PowerShell, APIs, or comparable tools.
- Ability to evaluate incomplete or conflicting evidence and develop defensible technical conclusions.
- Ability to perform technical activities during high-pressure security events with minimal oversight.
- Demonstrated ability to mentor personnel and communicate complex technical issues effectively.
- Working knowledge of AI and machine-learning capabilities and threats relevant to cybersecurity, including governance, privacy, reliability, security, and human-review considerations.
- One or more advanced or role-relevant certifications such as CISSP, GCIH, GCIA, GCFA, CEH, or comparable credentials preferred.
Technologies
- SIEM, EDR/XDR, SOAR, AQL, KQL, SPL, SQL, Python, PowerShell, APIs, TCP/IP, DNS, AI, machine-learning
Work Arrangement
- Hybrid role in the Wilmington, DE office.
Why This Role Matters
- Acts as the team’s senior technical escalation layer for complex events, advanced analysis, and technical response.
- Provides independent technical depth across threat intelligence, penetration testing, audit support, detection engineering, threat hunting, and vulnerability analysis.
- Helps develop the analyst bench and gives management technical leverage without a direct people-management requirement.
Company Culture & Background Screening
- Company Culture at The Bancorp Bank: https://www.thebancorp.com/company/company-culture/
- The Bancorp Bank, N.A. is an Equal Opportunity Employer and does not discriminate based on protected categories in recruitment, hiring, training, promotion, or other employment terms.
- Employment includes successful background check completion, including credit, criminal, education, employment, OFAC, and social media background history.
Tags: #LI-PJ1, #LI-Hybrid