Senior Security Operations Analyst, Detection & Response
Core
Lead threat detection, investigation, and incident response across endpoint, cloud, and identity environments, while building automated detection workflows and supervising AI triage agents.
Role type
Senior Security Operations Analyst (Detection & Response)
Builds
Automated detection and response playbooks, SOC detection content, and AI-related threat coverage
Domain
Cybersecurity, Financial Services
Deliverable
production ML models | product features | dashboards & analysis
Required skills
Complex incident investigation, cloud/host forensics, detection rules as code, threat hunting, scripting (Python), REST API integration, AI triage supervision
Preferred skills
Financial services experience, GCIH/GCFA/GCDA/GNFA/CISSP certifications, Kubernetes, OWASP Top 10 for LLMs, MITRE ATT&CK/ATLAS
Technologies
EDR, SIEM, SOAR, AWS, Python, Kubernetes
Responsibilities
Lead complex investigations and containment for high-severity incidents; write, test, and tune detection rules and response playbooks; conduct hypothesis-driven threat hunts; document attacker activity for executive briefings; maintain investigation runbooks and SOC metrics; partner with cybersecurity to align priorities; supervise AI triage agents and tune configurations
Seniority
Senior, hands-on IC