Senior Cyber Threat Detection and Response Analyst

McKesson Corporation

Confirmed live yesterday High trust
Closes in 4 days Hybrid

Quick summary

Work type
Hybrid
Location
Richmond, VA
Salary
$122,500–$204,100 / yr
Employment
Full-time
Posted
3 days ago
Freshness
Confirmed live yesterday
Closes
Oct 15, 2026 (soon)

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $154k
This role $163k
$103k $215k
below market most similar roles pay here above market

This role pays more than 62% of similar roles. Most pay $122,275–$184,925 — the blue band above. At the midpoint, this role pays about $163k versus about $154k for comparable roles.

Based on 240 similar postings.

Employer

About McKesson Corporation

McKesson Corporation is a premier American healthcare services company that distributes pharmaceuticals, medical-surgical supplies, and provides technology to the healthcare industry.

McKesson Corporation currently has 105 open roles on FindRole.

Listed pay typically runs $122,550–$204,250 across 68 roles with salary data.

Most-posted roles

View all roles at McKesson Corporation

At a glance

TL;DR · Senior Cyber Threat Detection and Response Analyst

The Sr. Cyber Threat Detection and Response Analyst joins the cybersecurity team to implement and support detection engineering and response enablement solutions. This role involves onboarding and normalizing logs from endpoints, network devices, cloud services, and identity systems to maintain the health of SIEM, EDR/XDR, and SOAR platforms. Key responsibilities include building and tuning detection rules, supporting alert triage, and developing automation playbooks to streamline incident response. The analyst will use internal and external research tools to map detections to the MITRE ATT&CK framework. Required skills include experience with Windows and Linux logging, cloud platforms like AWS, Azure, or GCP, and scripting languages such as Python, PowerShell, or Bash. The role solves critical security problems by ensuring high-fidelity monitoring and timely remediation of threats.

What you'll do

  • Implement and maintain log collection for endpoints, network devices, cloud services, and identity systems.
  • Onboard data sources to SIEM and detection platforms while validating parsing and normalization.
  • Create, implement, and tune detection rules and alerts to improve fidelity and reduce noise.
  • Support alert triage and incident response by collecting evidence and assisting with containment tasks.
  • Develop and test automation and orchestration use cases for SOAR playbooks.
  • Execute test plans for detections and response workflows to identify coverage gaps.
  • Map detections to common tactics and techniques using frameworks like MITRE ATT&CK.
  • Document all work performed, including use cases, runbooks, and change records.

What we're looking for

  • Bachelor’s degree in computer science, information security, MIS, engineering, or a related field, or equivalent practical experience.
  • 4+ years of relevant experience in a cybersecurity or IT operations role.
  • 6+ years of experience in cybersecurity and/or IT operations with exposure to security monitoring, detection engineering, or incident response.
  • Experience supporting or implementing monitoring and detection tools such as SIEM, EDR, IDS/IPS, logging agents, or vulnerability scanners.
  • Experience onboarding and supporting log sources and telemetry pipelines for Windows, Linux, network devices, and cloud environments.
  • Basic scripting or automation skills in Python, PowerShell, or Bash.
  • Familiarity with one or more cloud platforms (AWS, Azure, or GCP) and cloud logging/monitoring concepts.
  • Security+, SSCP, or equivalent foundational security certification (preferred); Google Cloud or GIAC certifications (preferred).

More like this

Similar roles

Cyber Threat Detection & Response Analyst

McKesson Corporation

Richmond, VA 13 days ago $98,900–$164,900
SIEM EDR XDR SOAR Python PowerShell Bash KQL SPL AWS Azure GCP MITRE ATT&CK IDS/IPS Firewalls Windows Linux NIST CIS Benchmarks
4+ yrs exp

Cyber Security Analyst

Leidos

Adelphi, MD 47 days ago $87,100–$157,450
Incident Response SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Cyber Kill Chain Vulnerability Management SOC Security+ CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 47 days ago $87,100–$157,450
SIEM IDS Incident Response AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Cyber Kill Chain Vulnerability Management Security+ CE CSSP-Infrastructure Support SaaS SOC Defense-in-Depth
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 47 days ago $87,100–$157,450
Incident Response SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Cyber Kill Chain Vulnerability Management Security+ CE CSSP-Infrastructure Support SaaS SOC TTPs IOCs
4+ yrs exp Hybrid

Information Security Risk Analyst

Lam Research

Tualatin, OR 87 days ago
SIEM KQL SPL SQL Python PowerShell Microsoft Sentinel Splunk Exabeam Securonix Microsoft Defender XDR Azure AWS Google Cloud UEBA MITRE ATT&CK STIX/TAXII MISP Logic Apps Incident Response Threat Hunting
Hybrid

Senior Incident Response Analyst

Leidos

Arlington, VA 21 days ago $131,300–$237,350
Incident Response EDR IDS SIEM Python PowerShell Bash Malware Analysis Computer Forensics Windows Linux Firewalls Proxies Load Balancers VPN ATT&CK Framework Cyber Kill Chain FISMA
10+ yrs exp