Cyber Threat Detection & Response Analyst

McKesson Corporation

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Richmond, VA
Salary
$98,900–$164,900 / yr
Employment
Full-time
Posted
4 days ago
Freshness
Confirmed live today

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $149k
This role $132k
$88k most similar roles pay here $203k

This role pays less than 68% of similar roles. Most pay $122,818–$174,708 — the shaded band above. At the midpoint, this role pays about $132k versus about $149k for comparable roles.

Based on 240 similar postings.

Employer

About McKesson Corporation

McKesson Corporation is a premier American healthcare services company that distributes pharmaceuticals, medical-surgical supplies, and provides technology to the healthcare industry.

McKesson Corporation currently has 85 open roles on FindRole.

Listed pay typically runs $125,050–$205,650 across 58 roles with salary data.

Most-posted roles

View all roles at McKesson Corporation

At a glance

TL;DR · Cyber Threat Detection & Response Analyst

Cyber Threat Detection & Response Analyst The Cyber Threat Detection & Response Analyst joins the security team to implement and support detection engineering and response enablement solutions. This role involves onboarding and normalizing logs, building and tuning detection rules, supporting alert triage, and maintaining the health of platforms such as SIEM, EDR/XDR, and SOAR. The analyst will also develop automation playbooks, execute test plans for detection workflows, and collaborate with infrastructure teams to resolve telemetry issues. Key technical requirements include experience with SIEM, EDR, IDS/IPS, firewalls, and threat intelligence feeds. Candidates should possess skills in Python, PowerShell, or Bash, along with familiarity with KQL or SPL query languages. The role focuses on the critical task of mapping detections to the MITRE ATT&CK framework to identify and mitigate emerging threats across cloud, network, and endpoint environments.

What you'll do

  • Implement and maintain log collection for endpoints, network devices, cloud services, and identity systems.
  • Onboard data sources and manage the performance, parsing, and normalization of SIEM and EDR/XDR platforms.
  • Create, implement, and tune detection rules to improve alert fidelity and reduce noise.
  • Support incident response by collecting evidence, assisting with containment, and coordinating engineering fixes.
  • Develop and test SOAR playbooks to automate and streamline repetitive security response tasks.
  • Execute test plans for detections and response workflows to identify gaps and improve coverage.
  • Map detections to common tactics and techniques using frameworks like MITRE ATT&CK.
  • Document all work including use cases, runbooks, change records, and technical specifications.

What we're looking for

  • Bachelor's degree in computer science, information security, engineering, or a related field (or equivalent experience).
  • 4+ years of relevant experience in cybersecurity and/or IT operations.
  • Experience with security monitoring tools including SIEM, EDR/XDR, IDS/IPS, and logging agents.
  • Proficiency in onboarding log sources and managing telemetry pipelines for Windows, Linux, and cloud environments.
  • Ability to create, tune, and document detection rules while following change management processes.
  • Basic scripting skills in Python, PowerShell, or Bash and willingness to learn query languages like SPL/KQL.
  • Familiarity with security frameworks such as MITRE ATT&CK, NIST, or CIS Benchmarks.
  • Security+, SSCP, or other foundational certifications (preferred); TDR/SecOps specific certifications (preferred).

More like this

Similar roles

Cyber Defense Response Analyst II

CME Group

Chicago, IL 36 days ago $93,900–$156,500
Digital Forensics Incident Response Malware Analysis Python Pandas REST APIs AWS GCP Azure Q Radar Sentinel Splunk Chronicle ArcSight KAPE EnCase Cellebrite FTK Magnet Axiom Autopsy Ghidra Ida Pro PEStudio x64dbg SIEM

Cyber Security Analyst

Leidos

Adelphi, MD 38 days ago $87,100–$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 38 days ago $87,100–$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 38 days ago $87,100–$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Security+ CE CSSP-Infrastructure Support Vulnerability Management Network Security
4+ yrs exp Hybrid

Cyber Defense Analyst III

CME Group

Chicago, IL 8 days ago $103,500–$172,500
Python PowerShell SOAR GCP AWS Git CI/CD Detection-as-Code REST APIs JSON XML MITRE ATT&CK Linux Windows macOS SIEM
4+ yrs exp

Defensive Cyber Operations Analyst

Leidos

Washington, DC 52 days ago $87,100–$157,450
Cyber Network Defense Security Operations Center (SOC) SIEM Splunk Elastic IDS/IPS Firewalls PCAP Cyber Kill Chain Data Correlation Technical Writing
2+ yrs exp Hybrid