Sr. IS Analyst - Security Operations
Core
Lead SOC investigations, incident response, containment, and remediation while improving detection coverage, response effectiveness, threat hunting outcomes, and SOC operational maturity.
Role type
Senior IC Security Operations Analyst
Builds
SOC detection rules, playbooks, and response documentation
Domain
Cybersecurity / Financial Services
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM and EDR/XDR platform investigation, alert triage, incident response lifecycle management, threat hunting, root cause analysis, log and telemetry analysis, detection rule tuning, MITRE ATT&CK framework application, stakeholder communication
Preferred skills
Python/PowerShell scripting, cloud security, identity security, NIST/CIS frameworks
Technologies
SIEM, EDR, XDR, MITRE ATT&CK, Python, PowerShell, JSON, REST, ticketing systems
Responsibilities
Monitor, analyze, triage, and investigate security alerts and medium to high severity incidents; Perform detailed investigation of suspicious activity across endpoints, network, identity, email, cloud, and applications; Lead incident response activities including detection, analysis, containment coordination, remediation tracking, and closure documentation; Conduct threat hunting using threat intelligence and behavioral patterns; Review, tune, and improve detection rules, correlation logic, and monitoring use cases; Prepare clear incident reports and investigation summaries for technical and non-technical audiences; Collaborate with security engineering, infrastructure, and business teams to support investigation and remediation; Maintain and improve SOC playbooks, runbooks, and response documentation.
Seniority
Senior, hands-on IC