Security Operations Analyst (mid Level)

Saronic Saronic · Defense · Austin, TX · Software

This role is for a Security Operations Analyst responsible for monitoring, triaging, and investigating security alerts using SIEM and XDR platforms. The analyst will perform root cause analysis, lead incident response for mid-tier incidents, tune detections, conduct threat hunts, and contribute to playbooks and post-incident reviews. The role is part of a new SecOps team with opportunities for growth.

What you'd actually do

  1. Monitor and triage security alerts across endpoint, cloud, identity, network, and SaaS telemetry using enterprise SIEM and XDR platforms
  2. Perform in-depth alert investigation and root cause analysis, documenting findings with clear, structured timelines and impact assessments
  3. Lead initial incident response for mid-tier events: contain, eradicate, and recover across endpoint, cloud, and identity domains
  4. Conduct targeted threat hunting operations to identify attacker activity not surfaced by automated detections
  5. Support the SecOps Lead in developing and refining response playbooks, runbooks, and analyst workflow documentation

Skills

Required

  • Security Operations
  • SIEM
  • XDR
  • Incident Response
  • Threat Hunting
  • Detection Engineering
  • Endpoint Security
  • Cloud Security
  • Identity and Access Management
  • Network Security
  • SaaS Security
  • Root Cause Analysis
  • MITRE ATT&CK
  • Python
  • PowerShell
  • Bash
  • TCP/IP
  • DNS
  • HTTP/S
  • Firewall Logs
  • Proxy Logs
  • Lateral Movement Patterns

Nice to have

  • XDR platforms
  • Cloud-native security operations (AWS/Azure)
  • SOAR platforms
  • Response automation workflows
  • Supply chain security monitoring
  • CI/CD pipeline security monitoring
  • Data lake-based detection architectures
  • Pipeline-driven detection architectures
  • Classified environments
  • GovCloud environments
  • FedRAMP environments
  • Defense
  • Aerospace
  • Robotics
  • High-assurance operational environments
  • NIST SP 800-171
  • NIST SP 800-53
  • CMMC
  • GIAC GCIH
  • GCIA
  • GCFE
  • BTL1/2
  • CySA+
  • OSCP

What the JD emphasized

  • 3+ years of hands-on experience in a Security Operations, detection engineering, or incident response role
  • Demonstrated experience triaging and investigating alerts across at least two of the following: endpoint, cloud, identity, network, or SaaS environments
  • Hands-on proficiency with enterprise SIEM platforms and their query languages; ability to write and iterate on detection logic from scratch
  • Experience with EDR tooling in an operational context; ability to hunt, triage, and respond using endpoint telemetry
  • Solid understanding of attacker TTPs mapped to MITRE ATT&CK, and the ability to apply that knowledge during active investigations
  • Experience writing or iterating on detection logic, response playbooks, or SOC operational documentation
  • Scripting proficiency in Python, PowerShell, or Bash for alert enrichment, automation, or triage support
  • Strong understanding of network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral movement patterns
  • Clear and structured written and verbal communication — you can brief a non-technical stakeholder and write a thorough incident report
  • Ownership mindset: you follow incidents through to closure and flag what needs to be fixed, not just what needs to be documented
  • Experience operating in or supporting classified, GovCloud, or FedRAMP environments
  • Familiarity with compliance frameworks such as NIST SP 800-171, NIST SP 800-53, or CMMC