Full-Time

Threat Analyst

Updated on 2/20/2025

Threatlocker

Threatlocker

501-1,000 employees

Provides enterprise cybersecurity software solutions

Enterprise Software
Cybersecurity

Mid

Orlando, FL, USA

Category
Cybersecurity
IT & Security
Required Skills
TCP/IP
PowerShell
Bash
Python
Development Operations (DevOps)

You match the following Threatlocker's candidate preferences

Employers are more likely to interview you if you match these preferences:

Degree
Experience
Requirements
  • 3 years of experience in Information Technology with 1 year of specialized work in any of the following IT domains: Active Directory, Application Development, Network Administration, Information Security
  • Education in Information Technology or a comparable degree can offset 2 years of required experience for high achieving individuals
  • Experience with virtual machines on VirtualBox, Workstation Pro (Type 2 hypervisor)
  • Bare-metal (type 1) hypervisor experience (ESXi, HyperV)
  • Foundational knowledge of Active Directory infrastructure
  • Proficient in PowerShell and Python
  • Strong understanding of foundational Windows OS components (Windows Firewall, Windows Event Logs, Windows file structure, PowerShell)
  • Strong understanding of networking and security principles (RFC 1918, DNS, well-known ports, TCP/IP, CIA triad and its relevance to Information Security, AAA Framework)
  • Familiar with MITRE ATT&CK framework
  • Knowledge of network security technologies and protocols (TCP/IP, DNS, VPNs, firewalls, etc.)
  • Proficiency in scripting languages such as Python, PowerShell, or Bash
  • Proficiency in custom SNORT, SIGMA, and YARA rule creation
  • Understanding of malware behavior, attack vectors, and vulnerability exploitation techniques
Responsibilities
  • Monitor security tools and systems (SIEM, IDS/IPS, EDR, etc.) for suspicious activity or breaches
  • Analyze security alerts and data to identify potential threats, vulnerabilities, and compromises
  • Build and refine detection capabilities using security tools, threat intelligence, and machine learning models
  • Lead and participate in the response to security incidents (investigating, containing, eradicating, and recovering from threats)
  • Collaborate with cross-functional teams to develop incident handling processes and ensure timely remediation
  • Create detailed post-incident reports, including root cause analysis and recommendations for improvements
  • Develop automated tools and scripts to enhance security detection capabilities and streamline threat detection workflows
  • Maintain and enhance detection tools, including writing custom SNORT, SIGMA, and YARA rules, and updating rulesets in accordance with new threats
  • Conduct forensic analysis and threat hunting to identify malicious activity
  • Review logs from various systems (e.g., firewalls, servers, network devices) to uncover unauthorized activities
  • Research and stay current on emerging threats, vulnerabilities, and cyber-attack techniques
  • Contribute to the enhancement of security monitoring tools, processes, and playbooks
  • Develop automated scripts and tools to improve detection and response efficiency
  • Work closely with DevOps, Network, and Security Engineering teams to ensure secure architectures and systems
  • Leverage internal and external threat intelligence sources to stay informed about the latest security trends and threats
  • Share insights with internal stakeholders to ensure proactive measures are in place
  • Ensure security processes and procedures align with regulatory requirements and industry best practices (e.g., NIST, CIS, ISO 27001)
  • Assist in the preparation of audit reports and security assessments
Desired Qualifications
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Security Essentials Certification (GSEC)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Ethical Hacker (CEH)
  • OffSec Certified Professional (OSCP)
  • CompTIA Certs (Security +, Network +, Pentest +, CASP+)
  • Excellent analytical and problem-solving abilities
  • Ability to work under pressure and manage multiple detection initiatives simultaneously
  • Strong written and verbal communication skills, with an ability to present technical concepts clearly
  • Detail-oriented with the ability to quickly assess security issues and provide appropriate remediation actions

ThreatLocker offers enterprise security software that protects organizations from data breaches and cyber threats. Their main product, ThreatLocker Protect, blocks untrusted software and restricts applications from running unless explicitly allowed, effectively preventing ransomware and other malicious attacks. The company stands out with its fast customer support, responding in under 60 seconds, and its ability to help clients comply with various regulations. ThreatLocker's goal is to enhance clients' cybersecurity while providing cost-effective solutions.

Company Size

501-1,000

Company Stage

Series D

Total Funding

$295M

Headquarters

Maitland, Florida

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • ThreatLocker raised $115 million to drive R&D, support, and marketing efforts.
  • The cybersecurity market is expected to grow at a CAGR of 10.9% from 2023 to 2028.
  • Increased demand for Zero Trust security solutions boosts ThreatLocker's market potential.

What critics are saying

  • Increased competition from emerging cybersecurity startups could challenge ThreatLocker's market position.
  • Rapid workforce expansion may challenge ThreatLocker's company culture and operational efficiency.
  • Potential over-reliance on U.S. based support could be a risk in global expansion.

What makes Threatlocker unique

  • ThreatLocker specializes in Zero Trust endpoint protection and application whitelisting solutions.
  • Their U.S. based support team is known for quick response times under 60 seconds.
  • ThreatLocker Protect blocks untrusted software, preventing ransomware and malicious software exploits.

Help us improve and share your feedback! Did you find this helpful?

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
CityBiz
Dec 6th, 2024
ThreatLocker Wins SDC Award for Cyber Resilience Innovation of the Year

ThreatLocker, a global leader in Zero Trust endpoint protection, is proud to announce it has been awarded the prestigious 2024 SDC Cyber Resilience Innovation of the Year.

CityBiz
Dec 4th, 2024
ThreatLocker Endpoint Protection Platform Recognized for Strong Customer Focus, Product Functionality and Performance in 2024 Gartner Vendor Spectrum Report

ThreatLocker was also recognized as a Strong Performer in the June 28, 2024, Gartner(R) Peer Insights(TM) Voice of the Customer for Endpoint Protection Platforms based on customer reviews and ratings on Gartner(R) Peer Insights(TM).

CityBiz
Dec 4th, 2024
ThreatLocker Announces Sponsorship of InfraGard National Members Alliance

By partnering with INMA, ThreatLocker demonstrates its commitment to advancing cybersecurity best practices and contributing to the collective defense of our nation's infrastructure.

CityBiz
Nov 19th, 2024
ThreatLocker Launches Podcast Series With CyberScoop

With cyberattacks happening daily around the world, ThreatLocker(R) is partnering with CyberScoop to launch a five-part SafeMode Podcast series to tackle challenging cybersecurity issues of the day impacting businesses.

CityBiz
Nov 19th, 2024
ThreatLocker CEO Danny Jenkins Receives OBJ's Most Influential Leader Award

ThreatLocker CEO Danny Jenkins receives obj's Most Influential leader award.