Haystack
← Back to Jobs
Technology
SB

Cyber Threat Analyst Phoenix - AZ - Arizona

Sierra Business Solution LLCPhoenix, AZ🇺🇸United StatesPosted 28 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Phoenix, AZ, United States
Posted
Yesterday
ComplianceContinuous ImprovementPenetration TestingProcess ImprovementRequirements GatheringRisk ManagementServiceNowTriage

Job Description

Job Title: Cyber Threat Remediation Analyst

Role Descriptions: Skills & Qualifications 3+ years of experience in security engineering automation engineering SOC operations or detection engineering. Experience with AI assistants LLMs workflow automation or orchestration platforms. Strong understanding of SOC workflows detection operations and analyst processes. Experience developing operational metrics dashboards or performance reporting. Familiarity with process controls workflow governance and operational monitoring concepts. Experience with APIs scripting and system integrations. Strong analytical troubleshooting and problem-solving skills.Roles & ResponsibilitiesRole SummarySupport the optimization adoption and operational maturity of AI-enabled SOC workflows through prompt tuning workflow enhancements automation improvements operational controls and performance measurement. Focus on improving the effectiveness efficiency and reliability of AI-assisted detection investigation and response capabilities.Responsibilities Optimize AI-assisted investigation triage and response workflows. Develop and maintain prompts workflow templates automation logic and operational controls. Analyze workflow performance and identify opportunities to improve effectiveness accuracy and analyst experience. Tune confidence thresholds escalation logic and decision workflows. Support implementation of controls guardrails and monitoring mechanisms for AI-enabled processes. Develop and track operational metrics KPIs and reporting related to workflow performance adoption detection quality and analyst productivity. Incorporate analyst feedback into workflow enhancements and continuous improvement efforts. Support testing validation and rollout of new AI use cases workflows and model updates. Document optimization recommendations performance findings and operational procedures.

Essential Skills: Skills & Qualifications 3+ years of experience in security engineering automation engineering SOC operations or detection engineering. Experience with AI assistants LLMs workflow automation or orchestration platforms. Strong understanding of SOC workflows detection operations and analyst processes. Experience developing operational metrics dashboards or performance reporting. Familiarity with process controls workflow governance and operational monitoring concepts. Experience with APIs scripting and system integrations. Strong analytical troubleshooting and problem-solving skills.Roles & ResponsibilitiesRole SummarySupport the optimization adoption and operational maturity of AI-enabled SOC workflows through prompt tuning workflow enhancements automation improvements operational controls and performance measurement. Focus on improving the effectiveness efficiency and reliability of AI-assisted detection investigation and response capabilities.Responsibilities Optimize AI-assisted investigation triage and response workflows. Develop and maintain prompts workflow templates automation logic and operational controls. Analyze workflow performance and identify opportunities to improve effectiveness accuracy and analyst experience. Tune confidence thresholds escalation logic and decision workflows. Support implementation of controls guardrails and monitoring mechanisms for AI-enabled processes. Develop and track operational metrics KPIs and reporting related to workflow performance adoption detection quality and analyst productivity. Incorporate analyst feedback into workflow enhancements and continuous improvement efforts. Support testing validation and rollout of new AI use cases workflows and model updates. Document optimization recommendations performance findings and operational procedures.

Skills: Cyber Security - GRC - Data Security

Must Have TechnicalFunctional Skills

3 5 years of experience in Cybersecurity, Security Operations, Technology Risk, Governance, Risk & Compliance (GRC), Vulnerability Management, Incident Response, Security Program Management, or a related field.

Experience coordinating remediation efforts, security findings, or risk management activities.

Ability to understand cybersecurity concepts and translate technical information into actionable business outcomes.

Roles & Responsibilities

Threat Remediation Coordination

Manage the end-to-end lifecycle of cyber threat findings from intake through closure.

Coordinate remediation efforts with application, infrastructure, cloud, IAM, and security teams.

Track ownership, remediation milestones, evidence, exceptions, and risk acceptance requests.

Identify blockers, facilitate resolution discussions, and escalate issues as needed.

Prepare status updates and remediation reporting for leadership.

Threat Assessment Support

Support reviews of emerging cyber threats and security findings to determine organizational applicability and exposure.

Facilitate threat applicability assessments with technology teams.

Maintain remediation questionnaires, assessment templates, and supporting documentation.

Document remediation plans, compensating controls, and risk decisions.

Process & Workflow Development

Create and maintain process maps, workflow diagrams, playbooks, and operational procedures.

Partner with ServiceNow teams to improve remediation tracking, workflows, reporting, and intake processes.

Assist with business requirements gathering and process improvement initiatives.

Support workflow automation and operational efficiency efforts.

Governance & Reporting

Maintain remediation dashboards, metrics, scorecards, and executive reporting.

Support governance reviews, audits, and compliance activities.

Monitor remediation aging, SLA performance, and overall program health.

Contribute to the ongoing maturation of the Threat Remediation Program.

Generic Managerial Skills, If any

The Cyber Threat Remediation Analyst serves as the operational coordinator for enterprise threat remediation activities. This role focuses on managing remediation processes, tracking cyber threat findings, facilitating stakeholder engagement, supporting threat applicability assessments, and improving remediation workflows.

Unlike traditional Vulnerability Management roles focused primarily on patching activities, this position supports a broader Threat Remediation Program that incorporates insights from Cyber Threat Intelligence, Incident Response, Red Team assessments, penetration testing, security assessments, and other cybersecurity initiatives.

This role is ideal for someone who enjoys combining cybersecurity knowledge, stakeholder engagement, process improvement, and program execution to help drive meaningful risk reduction across the enterprise. It goes beyond program tracking by helping evaluate threat applicability, assess organizational exposure, and influence remediation decisions in partnership with cybersecurity subject matter experts.

Top 3 Required Skills:

1. Cybersecurity, Security Operations, Technology Risk, Governance, Risk & Compliance (GRC), Vulnerability Management, Incident Response, Security Program Management, or a related field.

2. Threat Remediation Coordination - experience coordinating remediation efforts, security findings, or risk management activities.

3. Threat Assessment Support - Ability to understand cybersecurity concepts and translate technical information into actionable business outcomes.

Similar jobs