← Back to Jobs
Technology
Cyber Security Research Eng. 3 (Phishing & Threat Analytics)
Apex SystemsCharlotte, NC🇺🇸United StatesPosted 25 Jul 2026
Quick Overview
Work Type
Hybrid
Level
Mid Senior
Job Description
Job#: 3043812
Job Description:
Cyber Security Research Engineer
Phishing, Threat Analytics & Incident Response
Location
Job Summary
The Cyber Security Research Engineer is responsible for the research, analysis, detection, disruption, and mitigation of phishing threats and advanced cyber attacks targeting employees, customers, and enterprise systems. This role serves as a key contributor within Threat Analytics, Cyber Threat Intelligence, Incident Response, and Security Operations functions.
The ideal candidate will possess strong expertise in phishing detection, threat hunting, security analytics, incident response, digital forensics, and adversarial analysis. This individual will leverage enterprise security tools, develop detection logic, investigate cyber threats, and provide actionable recommendations that improve the organization's security posture.
This role requires a highly analytical and investigative mindset with the ability to think like an adversary, identify emerging attack techniques, and develop scalable solutions to detect and mitigate future threats.
Key Responsibilities
Phishing Detection & Threat Analytics
Threat Analytics, Detection Engineering & Emerging Threat Research
Phishing & Email Security
The ideal candidate is a highly technical cybersecurity professional with expertise in phishing detection, threat analytics, incident response, digital forensics, and adversarial analysis. They possess strong investigative skills, experience developing detection content and analytics, and a deep understanding of modern cyber threats targeting enterprise organizations.
Successful candidates will demonstrate the ability to analyze complex security events, disrupt phishing campaigns, conduct threat hunting activities, leverage security analytics platforms, and develop long-term detection and mitigation strategies. Experience supporting large-scale enterprise security operations, emerging AI-related threats, and security automation initiatives is highly desirable.
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.
Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.
If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at or . Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.
UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.
Job Description:
Cyber Security Research Engineer
Phishing, Threat Analytics & Incident Response
Location
- Charllotte, NC / Dallas, TX / Minneapolis, MN / Chandler, AZ / Des Moines. IA, Raleigh, NC
Job Summary
The Cyber Security Research Engineer is responsible for the research, analysis, detection, disruption, and mitigation of phishing threats and advanced cyber attacks targeting employees, customers, and enterprise systems. This role serves as a key contributor within Threat Analytics, Cyber Threat Intelligence, Incident Response, and Security Operations functions.
The ideal candidate will possess strong expertise in phishing detection, threat hunting, security analytics, incident response, digital forensics, and adversarial analysis. This individual will leverage enterprise security tools, develop detection logic, investigate cyber threats, and provide actionable recommendations that improve the organization's security posture.
This role requires a highly analytical and investigative mindset with the ability to think like an adversary, identify emerging attack techniques, and develop scalable solutions to detect and mitigate future threats.
Key Responsibilities
Phishing Detection & Threat Analytics
- Play a key role in phishing disruption efforts impacting customers, employees, and the company brand.
- Develop and enhance detection logic, processes, and procedures used to identify phishing campaigns and threat actor activity.
- Review, analyze, and correlate security logs from multiple data sources.
- Create and maintain detection content including:
- Regular Expressions
- YARA Rules
- Threat Detection Logic
- Security Analytics Content
- Identify indicators of compromise (IOCs), malicious domains, phishing infrastructure, suspicious URLs, and threat actor patterns.
- Support cyber threat intelligence and threat hunting initiatives.
- Leverage large-scale security analytics and threat intelligence techniques to identify, investigate, and disrupt cyber threats.
- Develop cybersecurity reporting, threat metrics, and operational dashboards supporting security leadership.
- Lead or participate in computer security incident response activities for moderately complex security events.
- Conduct technical investigations involving:
- Phishing Incidents
- Malware Activity
- Credential Theft
- Account Compromise
- Insider Threat Activity
- Perform post-incident digital forensics to identify attack vectors, root cause, scope, and remediation requirements.
- Analyze endpoint, network, email, identity, and security telemetry to support investigations.
- Document investigative findings and provide recommendations for future prevention.
- Collaborate with security operations, engineering, risk, and threat intelligence teams to improve response capabilities.
- Utilize offensive security methodologies and adversarial techniques to improve detection and response capabilities.
- Apply attacker-focused thinking to identify emerging threats and develop hunting strategies.
- Research threat actor tactics, techniques, and procedures (TTPs).
- Support vulnerability analysis, cyber threat investigations, and security research initiatives.
- Conduct analysis involving:
- Exploitation Techniques
- Vulnerability Research
- Security Assessments
- Adversary Emulation
- Threat Simulation Activities
- Develop proof-of-concept methodologies and custom techniques to assess security controls and improve threat detection capabilities.
- Utilize enterprise security platforms to investigate and respond to security events, including:
- SIEM Platforms
- IDS/IPS Technologies
- Endpoint Security Solutions
- Email Security Gateways
- Web Security Gateways
- Security Detection and Mitigation Devices
- Develop automated detection capabilities, security analytics, YARA rules, and alerting logic.
- Improve phishing detection and threat monitoring through security automation and enhanced detection engineering.
- Identify detection gaps and recommend improvements to monitoring capabilities.
- Support integration and optimization of enterprise security tools and monitoring technologies.
- Perform security risk assessments and technical reviews to ensure compliance with corporate security standards and best practices.
- Identify security vulnerabilities, control gaps, and areas of elevated risk.
- Evaluate remediation alternatives and recommend long-term mitigation strategies.
- Provide security consulting and guidance to internal business and technology teams.
- Support enterprise security engineering programs involving:
- Application Security
- Vulnerability Management
- Threat Modeling
- Security Assessments
- Security Control Validation
- Security Monitoring
- Assist with design, testing, implementation, and maintenance of security solutions across networking, cloud, authentication, email, internet, application, and endpoint environments.
- Research emerging threats involving:
- Generative AI
- Large Language Models (LLMs)
- AI-Assisted Phishing
- AI-Enabled Social Engineering
- Support security analytics initiatives involving AI-driven threat detection and security assessment automation.
- Assist in evaluating AI-related security risks and developing mitigation strategies.
- Contribute to security research involving prompt engineering abuse, AI threat activity, and emerging cyberattack techniques.
- Support AI security testing and threat intelligence initiatives designed to improve organizational cyber defense capabilities.
- Support cloud security monitoring, investigation, and threat response activities.
- Assist with monitoring and threat detection across cloud platforms and hybrid enterprise environments.
- Support DevSecOps and modern security operations initiatives that enhance visibility, automation, and incident response effectiveness.
- Participate in security engineering efforts focused on platform automation and security tool integration.
- Collaborate with peers, security engineers, analysts, threat intelligence teams, and managers to resolve issues and achieve objectives.
- Provide guidance and mentorship to junior security engineers and analysts.
- Communicate complex technical findings to both technical and non-technical stakeholders.
- Support a fast-paced, high-demand environment while balancing multiple priorities.
- Drive continuous improvement of phishing detection, threat analytics, incident response, and security monitoring capabilities.
- 4+ years of Cyber Security Research experience or equivalent demonstrated through work experience, military experience, education, or training.
- Advanced Information Security technical skills.
- Experience detecting, investigating, and disrupting phishing attacks targeting employees, customers, or enterprise brands.
- Experience creating and maintaining:
- Regular Expressions
- YARA Rules
- Detection Logic
- Threat Analytics Content
- Experience reviewing and correlating security logs from multiple security platforms.
- Experience supporting security investigations and incident response activities.
- Hands-on experience with:
- SIEM Platforms
- IDS/IPS Technologies
- Endpoint Security Solutions
- Email Security Gateways
- Web Security Gateways
- Security Detection Technologies
- Experience with host and network log analysis supporting incident response and threat hunting.
- Strong analytical, investigative, and problem-solving skills.
- Ability to manage complex security issues and develop long-term solutions.
Threat Analytics, Detection Engineering & Emerging Threat Research
- Experience leveraging security analytics, large-scale data analysis, and threat intelligence techniques to identify and disrupt cyber threats.
- Experience developing cybersecurity reporting, threat intelligence metrics, and operational security dashboards.
- Experience supporting:
- Threat Hunting
- Cyber Threat Intelligence
- Incident Response
- Digital Forensics
- Security Monitoring
- Detection Engineering
- Experience developing automated detection capabilities, security analytics, YARA rules, and security automation workflows.
- Experience integrating and optimizing enterprise security tools to improve phishing and threat detection effectiveness.
- Experience supporting security operations within large enterprise environments.
- Familiarity with AI security research, AI-driven threat detection, security analytics, and AI-related threat investigations.
- Knowledge of:
- Offensive Security Methodologies
- Penetration Testing
- Vulnerability Research
- Adversary Emulation
- Exploitation Techniques
- Red Team Methodologies
- Experience utilizing adversarial thinking during investigations, threat hunting, and incident response activities.
- Experience supporting phishing analysis, email investigations, malicious domain analysis, and cybercrime investigations.
- Experience supporting cloud security monitoring and incident response activities.
- Experience with security engineering, security tool integration, and security automation initiatives.
- Knowledge of DevSecOps principles and modern security operations practices.
- Experience supporting enterprise security programs within highly regulated environments.
Phishing & Email Security
- Phishing Detection
- Phishing Disruption
- Email Threat Analysis
- DMARC
- Email Security Gateways
- Brand Protection
- Malicious Domain Analysis
- Regular Expressions
- YARA Rules
- Security Analytics
- Threat Hunting
- Detection Engineering
- Threat Intelligence
- IOC Analysis
- Security Monitoring
- Alert Tuning
- Cybersecurity Reporting
- Incident Response
- Digital Forensics
- Malware Investigations
- Host Log Analysis
- Network Log Analysis
- Root Cause Analysis
- Threat Investigations
- Penetration Testing
- Ethical Hacking
- Adversary Emulation
- Vulnerability Research
- Security Assessments
- Exploitation Analysis
- Threat Simulation
- SIEM
- IDS/IPS
- Endpoint Security
- Email Security Gateways
- Web Security Gateways
- Security Detection Platforms
- Log Management Technologies
- Application Security
- Vulnerability Management
- Threat Modeling
- Security Engineering
- Cloud Security
- Authentication & Identity Services
- Access Management
- Security Risk Assessment
- AI Security
- Generative AI Security
- LLM Threat Analysis
- AI Threat Intelligence
- Security Analytics Automation
- AI Security Assessment
- GIAC (GCIH, GCIA, GCFA, GCFE, GPEN, GREM)
- CISSP
- GCTI
- OSCP
- Security+
- Other Cyber Defense, Incident Response, Threat Intelligence, or Offensive Security Certifications
The ideal candidate is a highly technical cybersecurity professional with expertise in phishing detection, threat analytics, incident response, digital forensics, and adversarial analysis. They possess strong investigative skills, experience developing detection content and analytics, and a deep understanding of modern cyber threats targeting enterprise organizations.
Successful candidates will demonstrate the ability to analyze complex security events, disrupt phishing campaigns, conduct threat hunting activities, leverage security analytics platforms, and develop long-term detection and mitigation strategies. Experience supporting large-scale enterprise security operations, emerging AI-related threats, and security automation initiatives is highly desirable.
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.
Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.
If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at or . Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.
UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.
Skills
Generative AI
LLM
Penetration Testing
Similar jobs
Data Center Project Manager
TEKsystems c/o Allegis Group · Pierre, United States
22 minutes ago$65 - $80/hrPrincipal Engineer- Wireless Operations
TEKsystems c/o Allegis Group · Denver, United States
22 minutes agoData Center Engineer
TEKsystems c/o Allegis Group · Round Rock, United States
22 minutes ago$40 - $50/hrSystems Engineer
TEKsystems c/o Allegis Group · Grand Haven, United States
22 minutes agoUiPath Developer (Healthcare Experience Required) (W2 Only / No C2C)
TEKsystems c/o Allegis Group · New York, United States
22 minutes ago$65 - $90/hrFortinet Network Engineer (Part Time)
TEKsystems c/o Allegis Group · Garner, United States
22 minutes ago$60 - $70/hr