We are looking for a Senior Cyber Ops Analyst to defend complex environments by owning end-to-end investigations, leading threat hunts, and improving detections and response workflows. You will collaborate across security domains and apply automation to raise team effectiveness.
Responsibilities
- Own complex multi-signal investigations end-to-end from triage to closure
- Correlate telemetry across endpoint, identity, network, cloud, and email sources to determine scope and impact
- Decide on escalation and response actions under ambiguity and justify conclusions with evidence
- Execute threat hunts based on threat intelligence and adversary TTPs to uncover missed activity
- Write advanced queries to pivot, correlate events, and validate hypotheses across datasets
- Build automation with scripts and APIs to enrich, parse, and correlate investigative data
- Lead incident handling for significant events and coordinate containment and eradication actions
- Partner with detection engineering to translate investigative insights into higher-fidelity detections
- Author and tune detection content and track effectiveness and false-positive rates
- Create reusable analytical patterns, runbooks, and hunt guides to improve team execution
- Mentor analysts and raise the team’s investigation and hunting capability
- Use approved AI tools to accelerate investigation workflows while verifying outputs
- Provide structured input for evaluating security tools and coverage gaps
Requirements
- 3+ years of SOC or security operations experience owning high-severity investigations
- Incident response leadership experience coordinating containment and eradication across teams
- Proven project ownership skills driving investigations from triage through root-cause analysis and closure
- Advanced query skills with KQL and SQL for hunting and event correlation
- Strong scripting skills in Python or PowerShell for automation and integrations
- Deep SIEM and EDR experience across common enterprise platforms and telemetry sources
- Strong detection engineering skills authoring, tuning, and validating detection rules
- Solid log analysis skills across endpoint, identity, network, email, and cloud data
- Strong security frameworks knowledge including MITRE ATT&CK and cyber kill chain concepts
- Strong cloud fundamentals across AWS, Microsoft Azure, and Google Cloud Platform
- Strong communication skills to document findings and defend conclusions with evidence
- Upper-Intermediate English proficiency (B2) for clear collaboration and reporting
Nice to have
- CrowdStrike Falcon Platform experience
- Splunk experience
- Security Orchestration and Automated Response experience
- Digital forensics experience
- Wireshark packet analysis skills