Enter a job title or keyword

Cybersecurity Threat Analyst I (Hybrid)


Job Location:

Sioux Falls, SD - USA

Monthly Salary: Not provided by the employer
Posted: 29 September 2026 (4 days ago)
Application Deadline: 30 December 2026
Vacancies: 1 Vacancy

Job Summary

Position Summary

Work Arrangement:

***This position is available as a hybrid position in our Sioux Falls SD or Wilmington DE office.***

At The Bancorp weve spent more than 25 years driving innovation in the financial services industry. As one of the first banks to embrace fintech we combine technology expertise and a forward-looking approach to deliver creative real-world solutions. We work side by side with our partners to help them grow and innovate with confidence. Across Fintech Solutions Institutional Banking Commercial Lending and Real Estate Bridge Lending we provide the people processes technology and banking capabilities that turn bold ideas into outcomes.

Join a team that brings urgency and rigor to every challenge and plays a direct role in driving growth for our clients and the communities we serve.

The Cybersecurity Threat Analyst I role is responsible for monitoring security alerts logs and threat intelligence under general supervision to identify suspicious activity. Performs initial triage using established procedures documents findings creates or updates tickets and escalates events requiring deeper investigation or response.

Supports routine vulnerability management asset review investigation reporting and security awareness activities. Uses approved artificial intelligence (AI) tools for research query development evidence summarization and documentation while validating outputs following data-handling requirements and protecting confidential information.

Key Responsibilities
  • Monitors security alerts from approved tools and performs initial triage using documented procedures and playbooks.
  • Reviews relevant firewall email web domain name system (DNS) endpoint and other logs to gather evidence and identify indicators of suspicious activity.
  • Creates and updates tickets documents actions taken and escalates incidents based on defined severity and escalation criteria.
  • Supports incident response activities under guidance including evidence collection basic scoping containment tracking and follow-up documentation.
  • Reviews threat intelligence alerts and indicators of compromise for relevance to the environment and escalates significant findings.
  • Runs approved vulnerability scans and reviews results to identify potential issues duplicates and items requiring validation.
  • Collects and reviews asset information including configurations and running processes to support investigations and vulnerability management.
  • Operates security monitoring tools and performs routine configuration or tuning tasks under guidance.
  • Participates in change management activities and follows established security operations procedures.
  • Communicates technical findings clearly to cybersecurity team members internal partners and vendors.
  • Assists with security product evaluations and recommends improvements based on documented requirements.
  • Supports security metrics trend reporting and assigned security awareness activities.
  • Uses approved AI-assisted capabilities to enrich alerts correlate indicators summarize evidence and support basic investigation tasks.
  • Uses approved AI assistance to draft basic queries investigation notes reports scripts and stakeholder communications.
  • Validates AI-generated content against authoritative sources and follows approved-use data-handling human-review documentation and auditability requirements.
  • Maintains awareness of emerging threats including AI-enabled phishing social engineering and enterprise AI misuse and escalates relevant findings.
  • Performs other duties as assigned.
Qualification Requirements
  • Associate or bachelors degree in cybersecurity information technology computer science or a related field or an equivalent combination of education training and experience.
  • Internships academic labs help desk system administration network support or security operations experience may qualify as relevant experience.
  • Foundational understanding of cybersecurity principles common threats Transmission Control Protocol/Internet Protocol (TCP/IP) networking and Windows Linux or macOS operating systems.
  • Basic familiarity with security logs monitoring tools vulnerability management concepts and ticketing workflows.
  • Ability to follow documented procedures maintain accurate records recognize when additional assistance is needed and escalate promptly.
  • Basic scripting command-line or query skills or a demonstrated willingness to learn tools such as Python PowerShell or SQL.
  • Familiarity with generative AI and machine learning concepts used in cybersecurity including common capabilities limitations privacy risks and the need for human validation.
  • Clear written and verbal communication sound organization and the ability to work effectively in a collaborative environment.
  • Coursework an internship a lab environment or hands-on experience related to security operations threat analysis incident response or vulnerability management preferred.
  • Familiarity with one or more security technologies such as security information and event management (SIEM) endpoint or extended detection and response (EDR/XDR) security orchestration automation and response (SOAR) threat intelligence vulnerability scanning or ticketing platforms preferred.
  • Basic knowledge of network traffic firewalls intrusion detection or prevention packet analysis cloud services databases or data visualization tools preferred.
  • An entry-level certification such as CompTIA Security Network CySA Microsoft SC-900 or a comparable vendor credential or a willingness to pursue one preferred.
  • Basic experience with scripting application programming interfaces (APIs) or low-code automation to collect organize or validate security data preferred.
  • Familiarity with approved AI-assisted workflows for security research documentation query development or analysis preferred.
  • Awareness of AI-specific security risks and safeguards including prompt injection sensitive-data leakage malicious automation and AI-generated social engineering preferred.

What Success Looks Like

  • Within the first 90 days works the alert queue independently using established playbooks.
  • Documents investigations clearly enough that a senior analyst can pick up the case without a conversation.
  • Escalates at the right threshold neither sitting on something urgent nor passing up work the analyst is equipped to handle.
  • By the end of the first year has progressed meaningfully toward a foundational security certification.
  • Navigates the SIEM and endpoint tooling without supervision.
  • Contributes to tuning suggestions and threat hunting work rather than only consuming assignments.
  • Treats AI-assisted output as a draft rather than an answer and consistently validates results against primary evidence before acting.

Why This Role Matters

  • This position is the programs intake layer.
  • Alerts threat intelligence feeds scan output and asset discovery data all land here first and anything missed or under-documented at this stage does not get caught somewhere else.
  • This position protects senior capacity.
  • Detection engineering forensics and threat hunting require uninterrupted focus which is impossible while working a live queue.
  • Level 1 ownership of steady-state triage is what lets senior analysts go deep and it is why routine monitoring and ticket flow keep running when responders pull away to an active incident.
  • This position closes the feedback loop.
  • No one sees false positives more often than the analyst in the queue daily and those observations are the raw input for tool tuning.
  • The same applies to the vulnerability and asset data reviewed here which keeps the programs picture of its own environment accurate.
  • This position creates the record.
  • Good case documentation makes work transferable across shifts and up to incident response while thin documentation means the work gets redone.
  • This position is where AI governance actually happens.
  • Approved-use and human-review requirements are policy on paper until someone applies them at the point of use and the highest-volume routine AI usage in the department sits in this seat.
  • This position is the programs bench developing future senior analysts on the Banks own tooling and escalation thresholds.
Additional Information

This job will be open and accepting applications for a minimum of five days from the date it was posted.

Working at The Bancorp Bank N.A. and Benefits Information: Culture & Background Screening


Required Experience:

IC


About Company

For over 20 years, The Bancorp has been providing nonbank companies with the people, processes and banking technology that are essential in meeting their individual needs

View Profile View Profile