Cybersecurity Threat Analyst I
Cyber Threat Analysis
Cybersecurity Analysis
Cybersecurity Tools
Data Analysis
Data Security
Endpoint Security
Incident Response
Information Security
Information Technology (IT)
InfoSec
Risk Management
Security
Security Alert Triage
Security Automation
Security Information And Event Management
Security Monitoring
Security Operations
Threat Analysis
Threat Intelligence
Threat Investigation
Job Description
The Cybersecurity Threat Analyst I supports daily security monitoring by reviewing alerts and logs, performing initial triage, documenting evidence, and escalating events for deeper investigation. The role also assists with vulnerability management and incident response activities under guidance, using approved AI tools with validation and human review.
Location and Work Arrangement
Sioux Falls, SD (hybrid). This position is also available as a hybrid role in the Wilmington, DE office.
Responsibilities
- Monitor security alerts from approved tools and perform initial triage using documented procedures and playbooks.
- Review relevant firewall, email, web, DNS, endpoint, and other logs to collect evidence and identify indicators of suspicious activity.
- Create and update tickets, document actions taken, and escalate incidents based on defined severity and escalation criteria.
- Support incident response activities under guidance, including evidence collection, basic scoping, containment tracking, and follow-up documentation.
- Review threat intelligence alerts and indicators of compromise for relevance to the environment and escalate significant findings.
- Run approved vulnerability scans and review results to identify potential issues, duplicates, and items requiring validation.
- Collect and review asset information, including configurations and running processes, to support investigations and vulnerability management.
- Operate security monitoring tools and perform routine configuration or tuning tasks under guidance.
- Participate in change management activities and follow established security operations procedures.
- Communicate technical findings clearly to cybersecurity team members, internal partners, and vendors.
- Assist with security product evaluations and recommend improvements based on documented requirements.
- Support security metrics, trend reporting, and assigned security awareness activities.
- Use approved AI-assisted capabilities to enrich alerts, correlate indicators, summarize evidence, and support basic investigation tasks.
- Use approved AI assistance to draft basic queries, investigation notes, reports, scripts, and stakeholder communications.
- Validate AI-generated content against authoritative sources and follow approved-use, data-handling, human-review, documentation, and auditability requirements.
- Maintain awareness of emerging threats, including AI-enabled phishing, social engineering, and enterprise AI misuse, and escalate relevant findings.
- Perform other duties as assigned.
Required Qualifications
- Associate or bachelor’s degree in cybersecurity, information technology, computer science, or a related field, or an equivalent combination of education, training, and experience.
- Internships, academic labs, help desk, system administration, network support, or security operations experience may qualify as relevant experience.
- Foundational understanding of cybersecurity principles, common threats, TCP/IP networking, and Windows, Linux, or macOS operating systems.
- Basic familiarity with security logs, monitoring tools, vulnerability management concepts, and ticketing workflows.
- Ability to follow documented procedures, maintain accurate records, recognize when additional assistance is needed, and escalate promptly.
- Basic scripting, command-line, or query skills, or a demonstrated willingness to learn tools such as Python, PowerShell, or SQL.
- Familiarity with generative AI and machine learning concepts used in cybersecurity, including common capabilities, limitations, privacy risks, and the need for human validation.
- Clear written and verbal communication, sound organization, and ability to work effectively in a collaborative environment.
- Coursework, an internship, a lab environment, or hands-on experience related to security operations, threat analysis, incident response, or vulnerability management preferred.
- Awareness of AI-specific security risks and safeguards, including prompt injection, sensitive-data leakage, malicious automation, and AI-generated social engineering preferred.
Preferred Qualifications
- Familiarity with one or more security technologies, such as SIEM, EDR/XDR, SOAR, threat intelligence, vulnerability scanning, or ticketing platforms.
- Basic knowledge of network traffic, firewalls, intrusion detection or prevention, packet analysis, cloud services, databases, or data visualization tools.
- An entry-level certification, such as CompTIA Security+, Network+, CySA+, Microsoft SC-900, or a comparable vendor credential, or willingness to pursue one preferred.
- Basic experience with scripting, APIs, or low-code automation to collect, organize, or validate security data.
- Familiarity with approved AI-assisted workflows for security research, documentation, query development, or analysis preferred.
Technologies
TCP/IP, Windows, Linux, macOS, SIEM, EDR/XDR, SOAR, Python, PowerShell, SQL, CompTIA Security+, CompTIA Network+, CompTIA CySA+, Microsoft SC-900, APIs, packet analysis, cloud services, databases, data visualization tools
How Success Is Measured
- Within the first 90 days, works the alert queue independently using established playbooks.
- Documents investigations clearly enough for a senior analyst to pick up the case without a conversation.
- Escalates at the right threshold, neither holding urgent matters nor passing up work the analyst is equipped to handle.
- By the end of the first year, progresses meaningfully toward a foundational security certification.
- Handles SIEM and endpoint tooling without supervision.
- Contributes to tuning suggestions and threat hunting rather than only consuming assignments.
- Treats AI-assisted output as a draft and consistently validates results against primary evidence before acting.
Why This Role Matters
- Serves as the program’s intake layer for alerts, threat intelligence feeds, scan output, and asset discovery data.
- Protects senior capacity by enabling steady-state triage while senior teams focus on deeper detection engineering, forensics, and threat hunting.
- Creates the record through case documentation that supports transfer across shifts and up to incident response.
- Implements AI governance at the point of use, ensuring approved-use and human-review requirements are applied consistently.
- Acts as the program’s bench by developing future senior analysts on the Bank’s tooling and escalation thresholds.
Additional Information
- This job will be open and accepting applications for a minimum of five days from the date it was posted.
Company Culture and Background Screening
- The Bancorp Bank, N.A. is an EQUAL OPPORTUNITY EMPLOYER and does not discriminate on the basis of race, color, religion, gender, gender identity, sexual orientation, pregnancy, citizenship, national origin, age, disability, genetic information, veteran status, or other protected categories with respect to recruitment, hiring, training, promotion, and other terms and conditions of employment.
- Employment with The Bancorp Bank, N.A. includes successfully passing a background check including credit, criminal, education, employment, OFAC, and social media background history.