About this role
Role Overview
We are seeking a highly technical and proactive Sr. Security Operations Analyst to join our Information Security team. In this role you will engineer and mature our security operations infrastructure — designing automated playbooks, tuning advanced telemetry across SIEM, EDR, and cloud environments, and leading high-severity incident containment. As a senior member of the team, you will define triage standards and elevate the technical capability of the wider SOC.
\nResponsibilities- Detection engineering: Architect and optimize real-time detection engineering playbooks across SIEM, EDR, and cloud security platforms to minimize false positives, accelerate triage, and scale threat-hunting capability.
- Investigation: Investigate suspicious activity, correlate findings across data sources, and document clear, timely case notes for each alert or incident.
- Incident command: Lead the response lifecycle for high-severity incidents as primary investigator or incident commander, ensuring seamless coordination and technical handoff across cross-functional teams.
- Containment: Execute containment actions under established playbooks, including endpoint isolation, disabling compromised accounts, and blocking malicious indicators.
- Threat hunting: Research indicators of compromise and apply threat intelligence to identify anomalous behavior.
- Rule tuning: Tune detection rules and use cases to reduce false positives and close visibility gaps, in coordination with engineering.
- Email threats: Investigate and remediate email-based threats such as phishing and business email compromise, from both user submissions and automated detection.
- Continuous improvement: Contribute to post-incident reviews and metrics reporting — MTTD, MTTR, alert volume, and false-positive rate — to support ongoing SOC maturity.
- Currency: Stay current on emerging threats, attacker TTPs, and industry frameworks such as MITRE ATT&CK.
- SIEM platforms
- Splunk
- Microsoft Sentinel
- QRadar
- EDR platforms
- CrowdStrike
- Microsoft Defender for Endpoint
- SentinelOne
- Windows operating systems
- Linux operating systems
- TCP/IP
- DNS
- Firewalls
- Network proxies
- Incident response
- Threat hunting
- Detection engineering
- Log analysis
- MITRE ATT&CK framework
- Phishing investigation
- Business email compromise
- Written communication
- Case documentation
- AWS
- Azure
- GCP
- Cloud security
- SOAR platforms
- Python
- PowerShell
- KQL
- SPL
- Security automation
- Playbook development
- 4–6 years of IT or security experience, including hands-on exposure to a SOC, security help desk, or systems administration environment
- 3+ years monitoring or investigating alerts using a SIEM (e.g., Splunk, Sentinel, QRadar) and an EDR platform (e.g., CrowdStrike, Defender for Endpoint, SentinelOne)
- Working knowledge of Windows and Linux operating systems, including common attack surfaces and log sources such as event logs, auth logs, and process telemetry
- Foundational understanding of networking concepts (TCP/IP, DNS, proxies, firewalls) and the protocols relevant to intrusion detection
- Strong attention to detail, sound judgment under time pressure, and clear written communication for case documentation and shift handoffs
- Ability to work effectively in a 24/7 SOC rotation, including scheduled shifts and periodic on-call coverage
- Bachelor's degree in Cybersecurity, Information Technology, or a related field — or equivalent hands-on experience
- Foundational certifications such as CompTIA Security+ or CySA+ are expected; progress toward GIAC (GCIH, GFACT) or similar is a plus
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?