
Sr. Embedded Detection Analyst
Abnormal AI · United States
- Hybrid
- Full-time
- $150,000 / year
- United States
Job highlights
- Own detection performance for strategic customers.
- Investigate and resolve security detection issues.
- Tune systems for optimal detection efficacy.
- Collaborate with GTM and customer teams.
- Drive measurable detection improvements.
About the role
About The Role
Abnormal AI is looking for a Sr. Embedded Detection Analyst to join our Threat Intelligence team. This role involves partnering directly with high-value customers to identify, resolve, and improve detection performance. You will act as a technical partner, understanding customer pain points, using our detection analysis platform, and implementing tuning solutions. The ideal candidate has SOC or security operations experience, strong analytical skills, and a systematic approach to problem-solving.
You'll work at the intersection of security operations, customer success, and detection quality, leveraging our AI-powered tools to drive customer value and contribute to the program's operational playbook. You will own end-to-end customer outcomes and measurable detection KPIs for 3-5 strategic customer accounts.
What You Will Do
- Own detection performance outcomes for 3-5 strategic customer accounts, ensuring high efficacy aligned with customer risk tolerance.
- Serve as a reliable resource for customer detection issues, handling escalations for false positives and negatives.
- Monitor and analyze misclassification patterns using internal detection analysis dashboards and tools.
- Perform incident triage and alert correlation to diagnose detection issues (false positives or missed threats) using IOCs and TTPs.
- Design and implement detection tuning strategies based on customer-specific signals, attack patterns, threat intelligence, and behavioral characteristics.
- Fine-tune detection thresholds and configurations to optimize precision while maintaining coverage against emerging threats.
- Generate and present impact reports demonstrating measurable detection improvements to customers and internal stakeholders.
- Maintain alignment with Sales and Customer Success leads to understand customer pain points and renewal risks.
- Document detection issues, investigation findings, and tuning approaches in a structured, reusable format.
- Review audit logs and analyze system interactions using internal and external tools, including AI-based analytical tools.
- Identify cross-customer patterns and contribute tuning methodologies to the operational playbook.
- Submit D360 CFN reports and AISM submissions to improve global detection coverage.
- Provide feedback to the tooling team on analysis gaps, needed capabilities, and opportunities for automation.
- Support training of other team members by sharing investigation insights and developing repeatable methodologies.
- Leverage AI tools (e.g., ChatGPT, Claude) in workflows and investigations to accelerate research, automate tasks, and improve problem-solving.
Must Haves
- 7+ years of experience in SOC operations, detection engineering, incident response, email security analysis, or related cybersecurity role.
- Experience with security monitoring and detection platforms (SIEM, EDR, email security tools, etc.).
- Experience in email attack analysis, identifying and leveraging IOCs and TTPs.
- Deep understanding of precision/recall metrics and their business impact.
- Proven experience triaging security alerts, performing root cause analysis, and tuning detection logic.
- Ability to perform standardized data analysis procedures and follow established runbook methodologies.
- Proficiency with AI tools (ChatGPT, Claude, etc.) for productivity enhancement and task automation.
- Experience in technical writing, adapting communications for various audiences.
- Proven ability to collaborate with customers or stakeholders on technical security issues.
- Ability to remain calm and responsive during high-pressure situations.
- Outcome-oriented mindset focused on customer impact and detection improvement.
- Strong ownership mentality, ability to work within established processes, and identify improvements.
Nice to Have
- Background in email security, phishing detection, anti-abuse systems, or email threat containment.
- Basic SQL knowledge for writing queries and data filtering.
- Familiarity with Python, data analysis scripting, or notebook environments.
- Understanding of threat intelligence, IOCs, and threat hunting concepts.
- Familiarity with the MITRE ATT&CK framework and common email attack vectors.
- Security certifications (e.g., Security+, CISSP).
- Previous experience in technical account management or customer-facing security roles.
- Experience using AI tools and automation to solve security problems.
- Experience documenting investigation methodologies and training team members.
Key skills/competency
- SOC Operations
- Detection Engineering
- Incident Response
- Email Security Analysis
- Threat Intelligence
- SIEM
- EDR
- IOCs and TTPs
- Precision/Recall Metrics
- AI Tools
Skills & topics
- Sr. Embedded Detection Analyst
- SOC Operations
- Detection Engineering
- Incident Response
- Email Security
- Threat Intelligence
- SIEM
- EDR
- Cybersecurity
- AI Security Tools
How to get hired
- Tailor your resume: Highlight experience in SOC operations, detection engineering, and email security analysis. Quantify your achievements with metrics like reduced false positives.
- Showcase AI proficiency: Detail your experience using AI tools for security tasks, automation, and problem-solving in your application.
- Emphasize customer collaboration: Demonstrate your ability to work with customers or stakeholders on technical security issues and translate findings into business value.
- Prepare for technical and behavioral questions: Be ready to discuss your systematic approach to investigations, root cause analysis, and handling high-pressure situations.
- Research Abnormal AI: Understand their mission, threat intelligence focus, and commitment to AI-driven security solutions.
Technical preparation
Behavioral questions
Frequently asked questions
- What is an Embedded Detection Analyst at Abnormal AI?
- An Embedded Detection Analyst at Abnormal AI is a crucial role within the Threat Intelligence team. You'll partner directly with key customers to enhance their security detection capabilities, investigating issues, tuning systems, and demonstrating measurable improvements in detection performance using Abnormal AI's platform and AI tools.
- What specific experience is required for the Sr. Embedded Detection Analyst role at Abnormal AI?
- The role requires a minimum of 7 years of experience in cybersecurity, specifically within SOC operations, detection engineering, incident response, or email security analysis. Experience with security monitoring platforms like SIEM and EDR, and a strong understanding of email attack vectors (IOCs, TTPs) are essential. Proficiency with AI tools is also a must-have.
- How does Abnormal AI leverage AI in this role?
- AI is integral to this role. You will use Abnormal AI's internal AI-powered productivity enhancers and detection analysis platform. Additionally, proficiency with external AI tools like ChatGPT and Claude is required for accelerating research, automating tasks, and enhancing problem-solving within your investigations.
- What kind of customer interaction is involved in the Sr. Embedded Detection Analyst position?
- While you partner closely with customers and their GTM stakeholders, the focus is on technical investigation and detection improvement, not primary account management. You may occasionally join customer discussions to explain findings, but your core responsibility is behind-the-scenes analysis and tuning.
- How is success measured for an Embedded Detection Analyst at Abnormal AI?
- Success is measured by quantifiable improvements in detection performance across your assigned customer accounts. This includes metrics like reducing false positives/negatives and improving precision/recall, demonstrating tangible value and impact rather than just completing tasks.
- What are the key technical skills for this role?
- Key technical skills include expertise in security monitoring and detection platforms (SIEM, EDR), deep knowledge of email attack analysis (IOCs, TTPs), understanding of detection metrics (precision/recall), and proficiency in root cause analysis and detection tuning. Familiarity with AI tools is also critical.
- Does Abnormal AI offer opportunities for growth within the Threat Intelligence team?
- Yes, this role contributes to scaling the program by developing the operational playbook and training other team members. Your feedback on tooling will also shape the roadmap, indicating opportunities for contribution and influence within the team and the company's security solutions.