Security Operations Analyst
Core
Monitor and respond to adversarial activity, conduct threat hunting, and lead incident response for critical defense technologies.
Role type
Senior Security Operations Analyst (Incident Commander)
Builds
Detection signatures, response playbooks, and automation using detection-as-code principles
Domain
Defense technology, cybersecurity, cloud infrastructure, and endpoint security
Required skills
Security monitoring, log analysis, detection engineering, Python development, SIEM query languages (SPL, KQL, SQL), data lake analysis, attacker TTPs knowledge
Preferred skills
Cloud incident response (AWS, Azure, GCP), Digital Forensics, reverse engineering
Technologies
Python, SIEM, AWS, Azure, GCP, Windows, Linux, MacOS
Responsibilities
Triage and respond to security alerts across endpoints, cloud, and SaaS; build and optimize detection signatures and automation; conduct threat hunting and data baseline analysis; lead incident response investigations; mentor junior analysts
Seniority
Senior, hands-on IC with incident command responsibilities