Threat Analyst

Foresite
Foresite

IT

Overland Park, KS, USA

Posted on Aug 5, 2026

The Threat Analyst is an experienced security analyst moving into a specialist threat hunting role. This is not a junior position — candidates already have solid SOC fundamentals and can independently work complex alerts. On the Threat Analyst Team, you execute established threat hunts, write and tune detection logic, assist with clients utilizing Google Threat Intelligence, support active incidents, and serve as an escalation point above the standard analyst line.

What you'll do:

  • Execute threat hunts: Execute established threat hunts across client environments, applying IOCs and TTPs supplied by senior staff and derived from threat intelligence.

  • Write & tune detection logic: Write and tune log-source-specific threat hunting and detection queries in YARA-L 2.0, extending and modifying existing queries to improve coverage.

  • Act as an escalation point: Serve as an escalation point for SOC analysts, taking on complex, anomalous, or ambiguous alerts that exceed standard triage.

  • Support incident response: Provide threat hunting support during active incidents and contribute findings directly to incident response and incident command.

  • Drive detection enrichment: Enrich detections and investigations using Google Threat Intelligence and threat reports, while identifying process gaps and recommending improvements to reduce workload and improve response times.

  • Support specialized engagements: Assist senior analysts with insider threat investigations and support the implementation and operation of dark web monitoring capabilities for enterprise clients using Google Threat Intelligence.

  • Document & report findings: Document hunt results, detections, and lessons learned for client and internal operational use.

Who you are:

  • Experience: Experience equivalent to a Tier 2 SOC analyst, backed by solid incident response fundamentals and strong log analysis across endpoint, network, identity, and cloud telemetry.

  • Knowledge of Security Frameworks: Working knowledge of MITRE ATT&CK, Cyber Kill Chain, and the Diamond Model frameworks.

  • Detection & Query Capabilities: Working knowledge of TTPs and the ability to write queries to identify them based on threat intelligence reports, with the aptitude to become proficient in YARA-L 2.0 quickly.

  • Strong Communication: Strong written documentation and communication skills for detailing complex hunt findings and client deliverables.

  • Certifications: Relevant industry certifications (e.g., Security+, CySA+, PenTest+, SecurityX, GIAC, PJPT, PNPT, OSCP, or equivalent).

Nice to have:

  • Hands-on experience with Google SecOps (Chronicle) and Google Threat Intelligence.

  • Proficiency with at least 2 of the following EDR/XDR consoles:

    • SentinelOne

    • CrowdStrike

    • Microsoft Defender

    • Palo Alto Cortex

    • Cisco Secure Endpoint / AMP

  • Scripting ability (e.g., Python) for lightweight automation and data enrichment.

Why Join Foresite?

We are a mission-driven partner helping organizations navigate an increasingly complex threat landscape. Founded by security practitioners, we’ve grown into a global leader in SecOps and MDR by staying true to our core value: radical transparency. When you join Foresite, you are part of a "humans-first" culture where your expertise is valued, and your well-being is a priority. We leverage our Google Cloud Premier SecOps Partnership to stay at the cutting edge, but we know that our greatest asset is our people.

What we offer:

  • Comprehensive Health & Wellness: Robust medical insurance options to keep you and your family healthy.

  • Employer-Covered Insurance: We fully provide employer-paid Dental coverage, as well as Short-Term (STD) and Long-Term Disability (LTD).

  • Recharge & Refuel: We believe in a true work-life balance. You’ll start with 3 weeks of paid vacation, plus additional sick leave and paid company holidays to ensure you have time to recharge.

  • Growth & Mentorship: Access to world-class training and mentorship. We support your career trajectory, whether you’re looking to deepen your technical skills or move into leadership.

  • Impactful Work: Help protect global clients using the latest AI-enhanced security tools and GCP native technologies.