SlipstreamJobsFresh Startup & VC-Backed Jobs

Cybersecurity Senior Analyst

Thumbtack - Remote - Remote - posted 2026-08-28

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Thumbtack is seeking a Cybersecurity Senior Analyst to build and operate a detection and response capability across the company's growing security infrastructure. You'll be a cornerstone of day-to-day security operations, responsible for monitoring, triaging, and investigating security alerts across production, corporate, and SaaS environments. Key responsibilities include owning SIEM management—log source onboarding, parsing, normalization, detection rule development, and cost/coverage optimization. You'll manage the MDR (Managed Detection & Response) partnership, including escalation workflows, SLAs, and detection feedback loops. You'll lead security incidents end-to-end from triage through post-incident review, and build automation to reduce manual toil and response times using SOAR playbooks, detection-as-code pipelines, and response scripting. You'll conduct proactive threat hunting informed by threat intelligence and Thumbtack's environment, define and track operational metrics (MTTD, MTTR, alert fidelity, coverage), and apply AI tools to accelerate security operations. You'll partner with Security Engineering, Platform, IT, and Compliance teams to close detection gaps and improve security posture. As needed, you'll support the broader security program including GRC, third-party risk assessment, and vulnerability management. Required qualifications: 6+ years in security operations, detection & response, or related security engineering; deep hands-on SIEM experience including detection engineering and log pipeline management; experience managing or working closely with MDR/MSSP partners; strong incident response skills across cloud-native environments (AWS/GCP), SaaS, endpoints, and identity systems; fluency with AI tools; scripting/automation proficiency (Python, SOAR playbooks, detection-as-code); risk-based analytical thinking; working familiarity with GRC, compliance frameworks (SOC 2, PCI DSS), third-party risk, and vulnerability management; excellent communication skills and ability to collaborate with distributed, primarily US-based teams.

Similar roles