Posted 1 week ago

Threat Investigation Analyst

Company: Sentinel
Category: IT

 Downers Grove, Remote

Type: Full Time

Sentinel seeks a Threat Investigation Analyst to join their team. The Threat Investigation Analyst is a key member of the Threat Operations Team and serves as a first responder to cybersecurity incidents. This role is responsible for triaging, investigating, and responding to security alerts to protect customer environments. Analysts evaluate real-world logs, network traffic, and security artifacts to determine malicious versus benign activity and communicate findings clearly to both technical and non-technical stakeholders. Schedule: Friday, Saturday, Sunday and Monday | 4×10 (11:00 PM CST – 9:30 AM CST).
Training & Onboarding: New hires will complete a structured onboarding and training period onsite unless they live outside a 50-mile radius of Sentinel Technologies.
Salary is $60,000 – $65,000. They offer benefit plans including Medical, Dental, Vision, 401K, 529, Life Insurance, Income Protection Short and Long-Term Disability, Medical and Child/Elder Care, Flexible Spending Account Plans, Family Planning Benefits, Financial Education, Identity Theft Protection and Assistance, Legal Services, Employee Assistance Program, Two weeks’ vacation, additional paid time-off for Personal and Sick, certification and hands-on training, and employee discount for product services and entertainment.
Training hours will be Monday through Friday, 8:30 AM CST – 5:00 PM CST and will continue until the employee is prepared to transition to their assigned shift.  Preparedness will be determined through regular performance reviews focusing on readiness to operate independently in the position.

  • During onboarding, employees will:
  • Work closely with their manager, team leads, and senior analysts.
  • Shadow live security investigations and incident response activities.
  • Learn customer environments, security tools, workflows, and response procedures.
  • Develop proficiency in investigation, escalation, documentation, and communication processes.
    • Qualifications:
    • 1+ years of experience in a Security Operations role (SOC, Incident Response, Threat Intel, Malware Analysis, IDS/IPS, etc.) preferred
    • Required minimum certifications: CompTIA Security+
    • Experience with SIEM platforms and security investigations
    • Experience performing daily system monitoring and health checks for various security products
    • Confident triaging alerts and reports of incidents
    • Familiarity with network, endpoint, and host-based security telemetry
    • Understanding of common and emerging attack techniques
    • Understanding basic network protocols and traffic flow in an enterprise environment
    • Strong attention to detail and documentation accuracy
    • The ability to communicate clearly with verbal and written skills
    • Must be able to meet and uphold CJIS requirements