Cyber Threat Analyst

Tokio Marine HCC

$87K — $131K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2+ years of experience in cyber incident response or related fields.
  • Bachelor's degree in cyber security, Computer Science, or Information Technology.
  • Strong leadership skills with advanced technical knowledge in cyber security.
  • Preferred certifications (CISSP, CISM, GCFE, etc.) are a plus.
  • Ability to manage threat actor communications professionally.

Responsibilities

  • Assist with written communications to threat actors during ransomware engagements.
  • Maintain detailed logs of communications, negotiation notes, and case records.
  • Track actor responses and deadlines to keep the engagement team informed.
  • Prepare updates and summaries for engagement leads and supporting teams.
  • Conduct research on threat actor groups and tactics relevant to extortion cases.

Benefits

  • Remote work opportunity for flexibility and work-life balance.
  • Professional growth through engaging in high-stakes cyber security initiatives.
  • Access to industry recognition and preferred certifications for career advancement.
  • Collaboration with senior analysts and expertise in the field.
Full Job Description
Job Title: Cyber Threat Analyst
Location: Remote, USA
Reports to: Managing Director
Employment Type: Full time
Job Req ID: 2026
Req Begin Date: 8/11/2026


Job Summary

Join us in shaping the future of TMHCC-CPLG as a contributor in our cyber extortion and threat intelligence function, Vector3. You will support ransomware and cyber extortion engagements by managing threat actor communications, documenting demands and responses, and helping the team maintain clear, professional, and timely negotiation records. You will also perform light threat intelligence research on threat actor trends, tactics, techniques, and tooling to support engagement strategy and case context.

You will work closely with senior analysts, engagement leads, and related teams to help turn direct communications and threat observations into useful operational support for active matters.

Key Responsibilities

Relying on extensive security knowledge and advanced technical expertise, this role is accountable for the following responsibilities

Relying on advanced knowledge and strong leadership skills, this role is accountable for the following responsibilities:

Threat Actor Communications and Case Support:
Support ransomware and cyber extortion engagements by assisting with direct written communications to threat actors under the direction of engagement leads. Draft, organize, and maintain communication logs, negotiation notes, timelines, demands, concessions, and other case records. Track actor responses, deadlines, proof-of-life requests, and other case developments to help keep the engagement team informed. Coordinate professionally with internal stakeholders and external partners to ensure communications are accurate, timely, and well documented.

Preferred advanced degrees or certifications (CISSP, CISM, GCFE, GCFA, GREM, GBFA, GCIH, CFCE, CCE) are a plus

Experience

2+ years of professional experience in cyber incident response, threat intelligence, investigations, customer communications, or a related analytical role.

Education

Minimum 4 Year's bachelor's degree in cyber security, Computer Science, Information Technology related degree.

Business Controls and Policies

Comply with all corporate policies and procedures.

Cost Management
Develop innovative ways to improve financials.

Competencies

Planning
Contribute to the development of both short-term and long-term plans for designated area of the organization. Technical Excellence Develop the ability to manage threat actor communications, maintain precise case records, and perform accurate supporting research with minimal supervision. Write, or is a major contributor to, technical reports and documentation. Demonstrate strong attention to detail when handling communications, indicators, and case records.
Documentation and Process Support:
Prepare concise updates, summaries, and handoff notes for engagement leads and supporting teams. Support the maintenance of negotiation templates, playbooks, and operating procedures. Contribute to process improvements that increase consistency, responsiveness, and quality across communications and intelligence support.
Threat Intelligence Research:
Research threat actor groups, campaigns, malware families, tactics, techniques, and procedures that are relevant to active extortion cases. Collect and summarize open-source and internal intelligence that may help frame communication strategy or improve understanding of the threat. Maintain actor notes, reference material, and intelligence artifacts in approved repositories and tracking systems.

  • Pay Transparency
    The pay range for this position is $87,400-$131,000 which includes geographic adjustments, where applicable. The pay range is the range THMCC, in good faith, believes is the range of compensation for this role at the time of this posting. The hired applicant will be offered pay within the entire range based on the candidate's geographic location, qualifications, work experience, education, and/or skill level. The Company is fully committed to ensuring equal pay opportunities for equal work regardless of color, race, sex, national origin, sexual orientation, religion, age, veteran status, disability, pregnancy, citizenship status, genetic information, or any other basis protected by federal, state, or local pay equity laws.
    California 1212Use CA Fair Chance language.
    The Company will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable federal, state and local laws, such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC
    • 1033(e))(the "VCCLEA"), which restricts financial institutions and insurers such as TMHCC from employing individuals with certain types of criminal convictions. Where the hiring and employment of individuals is not restricted by the foregoing, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law such as the California Fair Chance Act, the Los Angeles Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance, the San Diego Fair Chance Ordinance, and the San Francisco Fair Chance Ordinance.]

    As an insurance company, we comply with certain federal, state and local laws such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC
    • 1033(e)), which restricts our ability to employ individuals with certain types of criminal convictions. Where not restricted by law and for criminal history not covered by this law, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law.

    You do not need to disclose your criminal history or participate in a background check until a conditional job offer is made to you. After making a conditional offer and running a background check, if the Company is concerned about a conviction that is directly related to the job, you will be given the chance to explain the circumstances surrounding the conviction or challenge the accuracy of the background report. The Company will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable federal, state and local laws, such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC
    • 1033(e))(the "VCCLEA"), which restricts financial institutions and insurers such as TMHCC from employing individuals with certain types of criminal convictions. Where the hiring and employment of individuals is not restricted by the foregoing, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law such as the California Fair Chance Act, the Los Angeles Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance, the San Diego Fair Chance Ordinance, and the San Francisco Fair Chance Ordinance.]

Similar Jobs

More Jobs at Tokio Marine HCC

More Information Technology Jobs

Find similar Cyber Threat Analyst jobs: