Full Job Description
GENERAL FUNCTION:
As a Principal Cyber Threat Analyst on the Detection, Analysis, and Response team, this role is responsible for identifying, investigating, and preventing cyber threats across the enterprise. Unlike a traditional SOC, this team focuses on deep investigations, advanced detection engineering, threat hunting, and rapid response.
The ideal candidate brings deep technical expertise in threat detection, incident response, and security operations, combined with a strong understanding of business processes and the financial services landscape. This role partners closely with threat intelligence, engineering, and business stakeholders to proactively identify risk, improve detection and response capabilities, and secure emerging technologies, including; Endpoint, Network, Identity, AI, CI/CD Supply Chain and Cloud.
Success in this role requires drive, self motivation, initiative, technical depth, and the ability to translate complex threats into actionable outcomes that align with business risk.
ESSENTIAL DUTIES AND RESPONSIBILITIES:
• Incident Response: Monitor system logs, respond to incidents, and preserve forensic evidence; escalate issues with appropriate severity and action items. Serve as a Incident Handler / Commander during incidents.
• Mentorship & Leadership: Guide analysts through investigations and response activities; act as Incident Commander during active incidents and post-action events.
• Technical Oversight: Review alerts, refine triage techniques, coach on detection logic, and lead incident handling and documentation.
• Detection Building: Design playbooks, workflows, and detection content; participate in threat hunting and deep research analysis across all types of infrastructure.
• Collaboration: Work with product owners and vendors to translate business priorities into security initiatives; assist in root cause analysis and remediation.
• Security Strategy: Ensure efforts support threat coverage, automation, and data quality; identify gaps in tooling and recommend solutions.
• Hiring & Training: Participate in interview panels, shape onboarding materials, and mentor junior analysts.
• Continuous Learning: Pursue certifications and training; share insights with the team and foster a learning culture.
• SME Role: Maintain knowledge of security technologies; assist lines of business in developing secure solutions.
• Technical Assistance: Assess, implement, and manage security systems; provide technical assistance in detection and resolution of security problems.
• Project Oversight: Provide expertise and oversight for strategic Cyber projects to enhance capabilities and maturity.
• On-Call Rotation: Participate in on-call rotation to ensure timely response to incidents.
MINIMUM KNOWLEDGE, SKILLS AND ABILITIES REQUIRED:
• Bachelor’s Degree in Computer Science, Information Systems, or other related field, or other relevant experience.
• 6 to 8 years of experience with the analysis/investigation and containment of potential data breaches or cyber security incidents.
• Scripting/Coding experience - Python, Regex, Yara as examples
• Knowledge of current hacking techniques, vulnerability disclosures, data breach incidents, and security analysis techniques
• Knowledge of malware families, botnets, threats by sector, and various attack campaigns and attacker methods, tools/techniques/practices
• Knowledge of cloud technologies including O365
• Common security controls is required including; authentication, encryption, IDS, WAFs, firewalls, HIPS, EDR, EPP, etc.
• Proficient in both Linux and Windows operating systems.
• Understanding of application protocols
• Strong analytical, tactical and critical thinking ability.
• Ability to handle multiple competing priorities in a fast-paced environment.
• Ability to communicate effectively across multiple levels
• Preferred CISSP, GIAC, or other relevant certification
Position not available for immigration sponsorship
#LI-MB1
Principal Cyber Threat Analyst
Total Base Pay Range 96,500.00 - 207,500.00 USD Annual
The base salary for this position is reflective of the range of salary levels for all roles within this pay grade across the U.S. Individual salaries within this range will vary based on factors such as role, relevant skillset, relevant experience, education and geographic location. In addition to the base salary, this role is eligible to participate in an incentive compensation plan, with any such payment based upon company, line of business and/or individual performance.
LOCATION -- Virtual, Michigan 00000
Attention search firms and staffing agencies: do not submit unsolicited resumes for this posting. Fifth Third does not accept resumes from any agency that does not have an active agreement with Fifth Third. Any unsolicited resumes – no matter how they are submitted – will be considered the property of Fifth Third and Fifth Third will not be responsible for any associated fee.