Role Overview
We are seeking a highly technical and proactive Sr. Security Operations Analyst to join our Information Security team. In this role you will engineer and mature our security operations infrastructure — designing automated playbooks, tuning advanced telemetry across SIEM, EDR, and cloud environments, and leading high-severity incident containment. As a senior member of the team, you will define triage standards and elevate the technical capability of the wider SOC.
n
Responsibilities
Detection engineering: Architect and optimize real-time detection engineering playbooks across SIEM, EDR, and cloud security platforms to minimize false positives, accelerate triage, and scale threat-hunting capability.
Investigation: Investigate suspicious activity, correlate findings across data sources, and document explicit, timely case notes for each alert or incident.
Incident command: Lead the response lifecycle for high-severity incidents as primary investigator or incident commander, ensuring seamless coordination and technical handoff across cross-functional teams.
Containment:
Execute containment actions under established playbooks, including endpoint isolation, disabling compromised accounts, and blocking malicious indicators.
Threat hunting: Research indicators of compromise and apply threat intelligence to identify anomalous behavior.
Rule tuning: Tune detection rules and use cases to reduce false positives and close visibility gaps, in coordination with engineering.
Email threats: Investigate and remediate email-based threats such as phishing and business email compromise, from both user submissions and automated detection.
Continuous improvement: Contribute to post-incident reviews and metrics reporting — MTTD, MTTR, alert volume, and false-positive rate — to support ongoing SOC maturity.
Currency: Stay current on emerging threats, attacker TTPs, and industry frameworks such as MITRE ATT&CK.;
Requirements
SIEM platforms
Splunk
Microsoft Sentinel
QRadar
EDR p