Major League Baseball (MLB)→
Incident Response & Intel Analyst… at Major League… · New York
Entry LevelOn-siteFull-timeNew York, NY$52k–$62k/yr
Skills
incident responsethreat intelligencefraud investigationosintsocial media monitoringmitre att&ck frameworkindicators of compromise (iocs)adversary tacticstechniquesprocedures (ttps)threat intelligence methodologiesintelligence reportingforeign language proficiency - spanishforeign language proficiency - russianforeign language proficiency - farsiforeign language proficiency - mandarin
Job Description
Summary: Major League Baseball (MLB) is seeking an Incident Response and Threat Intelligence Analyst responsible for detecting, investigating, and responding to cybersecurity incidents and digital threats. This role will enhance digital risk protection, conduct confidential investigations, and develop incident-response playbooks to strengthen organizational defenses.
Responsibilities:
- Support security and fraud incident response activities in coordination with the virtual Security Operations Center (vSOC) and internal stakeholders, including identification, containment, remediation, and post-incident analysis
- Enhance digital risk protection, threat intelligence, and social media monitoring programs, delivering timely and actionable intelligence to support operational response and threat modeling
- Conduct highly confidential digital and fraud investigations and produce clear, defensible investigative reports
- Monitor and analyze the cyber threat and fraud landscape using OSINT, deep/dark web sources, industry tools, internal telemetry, and the MITRE ATT&CK framework to identify relevant threats, vulnerabilities, indicators of compromise (IOCs), and adversary tactics, techniques, and procedures (TTPs)
- Analyze system logs, transaction data, and user behavior to identify anomalies, high-risk patterns, and indicators of fraud; assess impact and develop mitigation and prevention strategies
- Develop, maintain, and document incident-response playbooks, threat-intelligence processes, fraud workflows, policies, and procedures to improve operational consistence and effectiveness
- Assist in producing threat intelligence briefs, metrics, and reports that communicate risk, trends, and business impact to technical and non-technical stakeholders
- Support security awareness initiatives, including training programs and internal phishing campaigns, to strengthen organizational security and fraud resilience
- Collaborate across teams to fulfill intelligence requests, support adversary simulation efforts, and align threat intelligence with evolving business objectives
- Identify opportunities for security automation and SOAR-driven orchestration to improve response time, intelligence quality, and operational scalability across incident response, intelligence, and fraud programs
- Monitor and identify instances of illegal streaming and piracy utilizing threat intelligence monitoring platforms, and manage the submission and execution of takedown efforts to support anti-piracy and brand protection initiatives
Required Qualifications:
- Bachelor's or Master's degree (completed or in progress) in Cybersecurity, Information Security, Software Engineering, or a related field
- Demonstrated experience supporting incident response and conducting in-depth cyber, fraud, or digital investigations using OSINT, social media platforms, industry tools, and internal data sources
- Strong understanding of malicious adversaries, threat actors, and campaigns, including indicators of compromise (IOCs) and adversary tools, techniques, and procedures (TTPs)
- Ability to handle highly sensitive and confidential information with discretion and professionalism
- Excellent organizational, time management, documentation, and communication skills, with the ability to clearly articulate complex technical concepts, attack methods, and investigative findings to both technical and non-technical audiences
- Familiarity with threat intelligence methodologies, analytical frameworks (e.g., MITRE ATT&CK), and intelligence reporting best practices
Preferred Qualifications:
- Foreign language proficiency in Spanish, Russian, Farsi, and/or Mandarin is a plus
Required Skills: Incident response, Threat intelligence, Fraud investigation, OSINT, Social media monitoring, MITRE ATT&CK framework, Indicators of compromise (IOCs), Adversary tactics, techniques, procedures (TTPs), Threat intelligence methodologies, Intelligence reporting, Foreign language proficiency - Spanish, Foreign language proficiency - Russian, Foreign language proficiency - Farsi, Foreign language proficiency - Mandarin