Full-Time

MDR Threat Analyst

Posted on 11/20/2024

SentinelOne

SentinelOne

1,001-5,000 employees

Autonomous cybersecurity solutions for endpoints

Cybersecurity
AI & Machine Learning

Compensation Overview

$80k - $100kAnnually

Senior

Phoenix, AZ, USA

Category
Cybersecurity
IT & Security
Requirements
  • At least 5 years of experience as a security operations practitioner, with a focus on one or more of the following areas: SOC operations, security monitoring, incident investigation and response, malware analysis, threat hunting, and threat intelligence.
  • A detailed technical understanding of the current threat landscape, including widely used attacker TTPs and prominent threat actor groups.
  • Prior experience developing and/or tuning existing detection capabilities (SIEM/EDR/NDR detections).
  • Previous Managed Services/MDR experience.
  • Previous experience developing operational metrics/dashboards/reports, with a focus on detection/alert fidelity.
  • Familiarity with the MITRE ATT&CK framework.
Responsibilities
  • Responsible for the curation of all MDR detection capabilities in order to maximize threat detection coverage while minimizing overall alert volume, including:
  • Ongoing reporting and analysis of the efficacy of all existing detection capabilities.
  • Partnering with SentinelOne detection engineering and threat intelligence teams to improve these detection capabilities, as needed.
  • Proactively identifying additional detection capabilities/sources for possible inclusion in MDR service scope.
  • Supporting the overall SentinelOne response to new emerging threats (such as ‘zero day’ vulnerabilities and supply chain attacks).
  • Partnering with other internal stakeholders to share information and coordinate the response to these emerging threats.
  • Identifying the appropriate actions that can be performed by the MDR team to effectively protect customers against these emerging threats.
  • Developing communications to customers about these emerging threats, and the steps we are taking to protect them.
  • Curate threat intelligence (IOCs and TTPs) identified by the MDR team, and partner with other teams to integrate this intelligence into SentinelOne products and services.
  • Integrate relevant threat intelligence and research from other SentinelOne groups into MDR operations.

SentinelOne offers security solutions designed to protect endpoints, cloud environments, and identities from cyber threats. Their main product is an AI-powered platform that integrates various security functions, including prevention, detection, response, remediation, and forensics. This platform works by using artificial intelligence to identify both known and unknown threats, such as malware and ransomware, in real-time. When a threat is detected, SentinelOne can automatically respond to eliminate it quickly. What sets SentinelOne apart from its competitors is its fully automated response capabilities and its recognition as a leader in endpoint protection by Gartner. The company's goal is to provide comprehensive security that adapts to the ever-changing landscape of cyber threats, ensuring that enterprise customers, including those in finance, healthcare, and government, are well-protected.

Company Stage

IPO

Total Funding

$677.6M

Headquarters

Mountain View, California

Founded

2013

Growth & Insights
Headcount

6 month growth

8%

1 year growth

23%

2 year growth

39%
Simplify Jobs

Simplify's Take

What believers are saying

  • Recognition through awards like Pax8 MVP and Global Partner's Choice underscores SentinelOne's industry leadership and innovation.
  • The launch of Singularity Cloud Workload Security for Serverless Containers demonstrates the company's commitment to securing modern cloud environments.
  • Collaborations with major players like AWS and Ooredoo Group expand SentinelOne's influence and customer base.

What critics are saying

  • The significant drop in stock price since its IPO could indicate market volatility and investor uncertainty.
  • The highly competitive cybersecurity market requires continuous innovation to maintain leadership and market share.

What makes SentinelOne unique

  • SentinelOne leverages AI-driven real-time malware and ransomware detection, setting it apart from traditional signature-based cybersecurity solutions.
  • The company's focus on Extended Detection and Response (XDR) positions it as a leader in comprehensive threat management.
  • Strategic partnerships with industry leaders like Aon and NetApp enhance its service offerings and market reach.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Medical, Vision, Dental, 401(k), Commuter, Health and Dependent FSA

Unlimited PTO

Industry leading gender-neutral parental leave

Paid Company Holidays

Paid Sick Time

Employee stock purchase program

Disability & life insurance

Employee assistance program

Gym membership reimbursement

Cell phone reimbursement

Numerous company-sponsored events