711,236open jobs
42,355companies
99,593added this week
Browse all
Location
In office
Seniority
Senior

Confirmed on the employer's own hiring board on Sep 23, 2026. First seen by Alion on Sep 23, 2026.

Overview
Company
Impact
Profile match
Headquartered in New York City, New York, Bloomberg is a global leader in financial technology, data, and business media. The company is best known for its proprietary Bloomberg Terminal, which provides financial professionals with real-time market analytics, trading tools, and execution capabilities. Through its multi-platform news division, it delivers economic reporting, research, and analysis across television, digital, print, and audio outlets worldwide.

Cyber Security Operations Center - Threat Hunting, Intelligence & Incident Response

The Role

Bloomberg’s Cyber Security Operations Center (CSOC) protects the organization by identifying, investigating, and responding to cyber threats. Working closely with Engineering, Legal, Compliance, and other teams across Bloomberg, CSOC provides security monitoring, incident response, threat hunting, and forensic expertise across a complex global technology environment.

As a Senior Incident Response & Digital Forensics Analyst within the Threat Hunting, Intelligence & Incident Response (THIR) team, you will lead the technical investigation of our most complex security incidents and escalations.

You will take ambiguous events where the answer is not immediately apparent and drive them to a defensible conclusion. This includes analyzing host, memory, network, and log evidence; acquiring and examining forensic images; investigating suspicious binaries; and reconstructing attacker activity to determine what happened, how it happened, and the extent of impact.

During significant incidents, you will help establish ground truth quickly, maintain technical ownership of the investigation, and work with stakeholders across Bloomberg to support an effective response.

This role also carries an important leadership expectation: raising the analytical capability of the wider team. Through hands-on mentoring, incident pairing, playbooks, procedures, and structured knowledge sharing, you will help build deeper expertise in areas such as malware analysis, memory forensics, and log-based threat hunting.

You will also help shape Bloomberg’s forensic capabilities by contributing to tooling, workflows, investigative standards, and the conversion of lessons learned from incidents into repeatable processes and durable detection coverage.

What You’ll Bring

  • Substantial hands-on experience leading security incident investigations end to end, from initial signal through root-cause analysis and written conclusion.

  • Strong practical experience with disk and memory forensics across Windows and Linux, including evidence acquisition and analysis.

  • Demonstrated malware analysis experience, including static and dynamic analysis, safe detonation, and extraction of useful observables for detection and threat hunting.

  • Strong knowledge of operating-system internals across Windows, Linux, and macOS.

  • Strong understanding of networking fundamentals, including TCP/IP, DNS, routing, and network evidence analysis.

  • Deep hands-on experience investigating large datasets using Splunk or a comparable enterprise search and log-analysis platform.

  • Experience using endpoint and network telemetry to determine attacker behavior and identify additional evidence when existing visibility is insufficient.

  • Programming or scripting capability in any language; Python is commonly used within the team.

  • The ability to investigate difficult and unfamiliar problems independently while knowing when to involve others or seek additional expertise.

  • Strong written and verbal communication skills, including the ability to explain investigative findings and reasoning clearly.

Additional Experience We Value

Experience in one or more of the following areas would be beneficial:

  • Memory-forensics frameworks such as Volatility and structured forensic acquisition tooling.

  • Reverse engineering beyond behavioral malware analysis.

  • Cloud forensics across AWS, Azure, or GCP, including snapshot-based acquisition and investigation.

  • Threat hunting and knowledge of attacker tools, techniques, and procedures used against enterprise environments.

  • CrowdStrike Falcon, particularly Real Time Response (RTR), for remote artifact and evidence collection.

  • Humio / LogScale or other large-scale log-analysis platforms.

  • Endpoint telemetry and EDR technologies such as osquery, Sysmon, Carbon Black, or Tanium.

  • Network security monitoring technologies such as Zeek, Suricata, Snort, NetWitness, packet capture, or network IDS.

  • Working with detection engineering teams to translate investigative findings into sustainable detection coverage.

  • Git, Jira, Jupyter notebooks, or similar development and collaboration tools.

  • Relevant certifications such as GCFA, GCFE, GREM, or GNFA.

  • Experience applying mainstream commercial AI platforms to security or analytical workflows.

How You Work

Technical expertise is important, but the way you approach investigations matters equally.

We look for people who demonstrate:

Curiosity and problem solving - You explore the unknown, ask good questions, seek evidence, and methodically work through difficult problems.

Persistence - You stay engaged when investigations become complex, incomplete, or difficult to resolve.

Candor and humility - You are confident in your expertise while being open about what you do not know, receptive to feedback, and willing to involve others.

Learning agility - You can quickly develop knowledge of unfamiliar technologies, environments, and investigative techniques.

Collaboration and empathy - You work effectively with people from different technical disciplines, cultures, and backgrounds and respect different perspectives.

Knowledge sharing - You actively help others improve through mentoring, documentation, pairing, and practical knowledge transfer.

How We Work

THIR is a globally distributed team across New York, EMEA, and APAC. Our follow-the-sun model allows investigations and operational work to transition between regions rather than routinely requiring teams to work outside normal hours.

The role is shift-oriented, and significant incidents may occasionally require support outside standard working hours. When that happens, the team works together globally to manage the response.

Life at Bloomberg

Bloomberg operates in a fast-moving, collaborative environment where people are encouraged to contribute ideas regardless of title. We value high standards, trust, curiosity, teamwork, and giving back to the communities in which we operate.

If this sounds like an environment where you would thrive, we would like to hear from you.

Bloomberg is an equal opportunities employer. We value diversity and do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or other protected characteristics.

If indicated, please note that years of experience are a guide; we will consider applications from all candidates who can demonstrate the skills necessary for the role.

Discover what makes Bloomberg unique - watch our podcast series for an inside look at our culture, values, and the people behind our success.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
711,236 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$69k – $172k per year (Estimated) • Remote/Hybrid • Stockholm
Python
C#
C++
AI/ML
Fine-tuning
Prompt Engineering
Function Calling
LLM
RAG
Tool Use
DevOps
GCP
Azure
CI/CD
Jenkins
AWS
Game Dev
Unreal Engine
Apply
AI Architect 3 hours ago
$46k – $104k per year (Estimated) • In office • 14+ years exp • Bachelor's Degree • Bengaluru
Python
JavaScript
TypeScript
SQL
C#
Node JS
Databases
PostgreSQL
DynamoDB
ElasticSearch
Apache Kafka
Amazon Aurora
AI/ML
Copilot
Claude
ChatGPT
AI Agents
Machine Learning
Frontend
Yarn
Angular
React.js
npm
DevOps
Terraform
Azure
CI/CD
Jenkins
Git
AWS
Docker
Platform Engineering
Gerrit
AWS Lambda
GitHub
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
AWS Step Functions
Management
Agile
QA
Selenium
Appium
Apply
$115k – $244k per year (Estimated) • Equity • In office • Full-Time • 10+ years exp • Bachelor's Degree • Irvine • Santa Clara
Python
AI/ML
Copilot
ChatGPT
Apply
$215k – $290k per year • In office
Python
SQL
Cybersecurity
DLP
Apply
$110k – $190k per year • In office • 3+ years exp • Bachelor's Degree
Python
SQL
AI/ML
AI Agents
NLP
DevOps
Platform Engineering
Analytics
Tableau
Power BI
QlikSense
ETL/ELT
Apply
$215k – $290k per year • In office
Python
SQL
Cybersecurity
DLP
Apply
$190k – $240k per year • In office • 10+ years exp • Bachelor's Degree
Apply
In office • 8+ years exp
Management
Agile
Apply
$110k – $190k per year • In office • 3+ years exp • Bachelor's Degree
Python
SQL
AI/ML
AI Agents
NLP
DevOps
Platform Engineering
Analytics
Tableau
Power BI
QlikSense
ETL/ELT
Apply
In office • 7+ years exp
Python
JavaScript
TypeScript
SQL
Databases
Redis
RabbitMQ
Frontend
Vue.js
Redux
React.js
DevOps
CI/CD
Linux
Analytics
ETL/ELT
Apply
See all jobs
This is one of many
711,236 more open roles from verified company boards, updated every day.