Title: Senior Cyber Threat Analyst
US
Join a dynamic team at the pulse of global markets, where we deliver innovative software and service solutions for essential financial reporting and capital markets transactions. At DFIN, we are a values-driven organization that empowers you to build a fulfilling career while bringing your authentic self to work every day. Our “Win as One” mentality ensures that our team’s success is directly linked to Client, Shareholder and Employee Satisfaction.
Recognized as one of AMERICA'S MOST LOVED WORKPLACES® for five consecutive years and a Built In Best Places to Work for six years, we are committed to our employees’ total well-being. Enjoy competitive compensation, a flexible workplace, comprehensive benefits, and opportunities for professional growth. Bring your passion and talents to DFIN – because being YOU thrives here.
Summary:
The Senior Cyber Threat Analyst will lead efforts to investigate cybersecurity incidents from end-to-end, engaging and coordinating peer teams, stakeholders, and external entities as necessary. This person will play a role of subject matter expert in the areas of incident response, threat hunting, and forensics. The Senior Cyber Threat Analyst will author incident response runbooks and mentor cyber threat analysts in incident response and digital forensics methodologies.
Responsibilities:
- Lead incident response activities to identify, assess, contain, mitigate all observed threats and document all investigational efforts for multiple audiences
- Develop and operationalize incident response runbooks with an emphasis on automation and ability to measure incident response effectiveness (Develop/track KPIs)
- Document and track incident response investigations, including observed IOCs and TTPs, system(s) impacted, criticality and scope of any data exposure, lessons learned, follow-up items
- Act as a liaison between a diverse group of teams including engineering, security, and network & system operations to ensure effective adoption of incident response requirements and operational considerations
- Act as incident manager for all declared cyber security incidents
- Conduct traditional forensic and data acquisition activities utilizing industry standard commercial and open-source toolsets
- Identify, analyze, and interpret trends or patterns in complex data sets
- Work with the functional business areas as needed during incident response investigations
- Develop, customize, and maintain reporting around key metrics related to investigational and threat hunting activities
- Serve as a trusted advisor to the team Lead, Manger, and the SVP, and CISO on sensitive matters warranting confidentiality
- Communicate and present issues/investigation results to peer and executive-level audiences
- Demonstrate subject matter expertise across most technology domains
Qualifications:
- Extensive cybersecurity experience, including 8+ years in investigations and incident response, supported by a bachelor’s degree or equivalent demonstrated expertise.
- Deep hands‑on expertise in incident response, computer forensics, malware analysis, network traffic analysis, and log analysis.
- Strong capability in security operations, including the use of SIEM, SOAR, and EDR platforms, threat intelligence, and frameworks such as MITRE ATT&CK and ATLAS.
- Broad technical knowledge across operating systems (Windows, macOS, Linux/Unix, mobile), modern cloud environments (SaaS, PaaS), and core security technologies such as firewalls and intrusion detection systems.
- Strong analytical, risk‑assessment, and communication skills, with the ability to operate effectively in high‑stress environments, clearly communicate with engineers and leadership, and handle sensitive information in accordance with defined processes.
It is the policy of Donnelley Financial Solutions to select, place, and manage all its employees without discrimination based on race, color, national origin, gender, age, religion, actual or perceived disability, veteran status, actual or perceived sexual orientation, genetic information or any other protected status.
If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access jobs.dfinsolutions.com as a result of your disability. You can request a reasonable accommodation by sending an email to talentacquisition@dfinsolutions.com.
At DFIN, protecting your identity is a top priority. Please be aware of scammers impersonating DFIN recruiters. DFIN recruiters will never request personal information via email or text. You will only receive a text from us if you've already been in contact. All automated messages will come from talentacquisition@dfinsolutions.com. If you ever have doubts about the legitimacy of any communication from us, please do not hesitate to reach out for verification via talentacquisition@dfinsolutions.com (this email is for general TA questions and is not used for updates on your application status). #BI-Remote
Job Segment:
Open Source, Cloud, Linux, Unix, Technology
