
Job Overview
Location
Remote - United States
Job Type
Full-time
Category
Software Engineering
Date Posted
July 2, 2026
Full Job Description
đź“‹ Description
- • Analyze and evaluate anomalous network and system events in a 24x7x365 Security Operations Center (SOC) environment through lead-less threat hunting.
- • Collaborate with MDR Analysts to research and investigate emerging cybersecurity threats and serve as an escalation point for advanced intrusion analysis.
- • Develop detailed incident analysis reports and coordinate across business units and customer environments to resolve security incidents.
- • Design and build operational processes and procedures to enhance overall SOC efficiency and effectiveness.
- • Provide actionable threat and vulnerability analysis based on security events across multiple independent customer environments.
- • Build and maintain test lab environments to research emerging attack techniques and contribute to internal and external threat operations knowledge.
- • Review sandbox technologies to identify additional Indicators of Compromise (IOCs) from artifacts uncovered during forensic analysis.
- • Triaging endpoint events from EDR and NGAV tools while supporting the Incident Response (IR) process.
- • Assess threat indicators in Windows environments, including malware, malicious anomalies, abnormal network activity, root-level compromise, and forensic artifacts.
- • Apply robust understanding of at least two operating systems: Windows, Linux, or macOS.
- • Utilize ELK stack components including Dashboards, Logstash configurations, and search queries for log analysis.
- • Write and execute scripts in PowerShell, Python, and Go to automate analysis tasks and enhance detection capabilities.
- • Work with cloud services including AWS (EC2, S3, IAM) and Microsoft Azure/M365 for threat detection and investigation.
- • Perform leadless threat hunting to uncover new or potential incidents and document findings with precision.
- • Demonstrate excellent problem-solving, critical thinking, and analytical skills to detect anomalous patterns and deconstruct complex security issues.
- • Communicate technical findings clearly and effectively to both technical teams and non-technical stakeholders through written and verbal reporting.
- • Contribute to the continuous improvement of threat detection rules, detection logic, and SOC workflows based on real-world incident data.
- • Maintain up-to-date knowledge of evolving cyber threats, adversary tactics, techniques, and procedures (TTPs).
🎯 Requirements
- • Five (5+) years of experience in an information security role
- • Experience working in a Security Operations Center (SOC)
- • Two (2+) years of experience with triaging endpoint events from EDR, NGAV, and supporting the Incident Response (IR) process
- • Deep knowledge of assessing threat indicators in a Windows environment
- • Robust understanding of at least two of: Windows, Linux, or macOS
- • Familiarity with ELK stack, PowerShell, Python, and Go scripting
🏖️ Benefits
- • Competitive Health, Vision, Dental, and Life Insurance plans
- • Robust 401k plan
- • Discretionary Time Off
- • Other minor perks
Skills & Technologies
See exactly how your profile matches this role — strengths, skill gaps, and what to do about them.
About Blackpoint Cyber, Inc.
Blackpoint Cyber provides managed detection and response (MDR) and network security services to small and midsize businesses and managed service providers. The company combines a proprietary cloud-native security platform with 24/7 analyst-led monitoring to identify, contain, and remediate threats in real time. Core offerings include endpoint detection and response, network traffic analysis, lateral movement detection, and incident response. Founded in 2014 by former U.S. government cyber operators, Blackpoint focuses on reducing dwell time, minimizing business disruption, and delivering actionable threat intelligence to organizations lacking in-house security teams.
Subscribe to the weekly newsletter for similar remote roles and curated hiring updates.
Newsletter
Weekly remote jobs and featured talent.
No spam. Only curated remote roles and product updates. You can unsubscribe anytime.
Similar Opportunities

Crowdtilt, Inc.
2 months ago

Datum Network Inc.
30 days ago

TrueLogic Company
2 months ago

TrueLogic Company
2 months ago