
Senior Security Operations Center Analyst
Posted Aug 26

Posted Aug 26
This is a fully remote position, open to applicants in United States.
• Triage and respond to security alerts and incidents across on-premises and multi-cloud enterprise and product environments.
• Conduct thorough investigations utilizing SIEM, EDR, cloud audit logs, identity telemetry, and network data.
• Assess incident scope, identify root causes, analyze attacker TTPs, and evaluate business impact.
• Manage incident communications, providing severity updates, coordinating with stakeholders, and preparing executive-ready summaries.
• Facilitate containment and remediation efforts in collaboration with IT, Cloud/Platform, and Engineering teams.
• Generate comprehensive incident documentation that encompasses timelines, evidence, hypotheses, IOCs, actions taken, and lessons learned.
• Perform hypothesis-driven threat hunts aligned with MITRE ATT&CK framework.
• Convert hunt findings into detections, tuning strategies, playbooks, and telemetry recommendations.
• Develop, adjust, and sustain detection content and SIEM analytics.
• Validate detection mechanisms through testing and retrospective analysis.
• Define and uphold monitoring and detection use cases in collaboration with stakeholders.
• Execute endpoint and/or cloud forensics and preserve relevant evidence.
• Assist in malware triage and artifact analysis.
• Investigate cloud threats and anomalies using security signals and audit telemetry from AWS, Azure, and GCP.
• Collaborate with Cloud/Platform teams to resolve logging, retention, and telemetry shortcomings.
• Participate in an on-call rotation to ensure 24x7 incident response coverage.
• Act as an escalation point for high-severity incidents.
• Bachelor’s degree in computer science or a related field (or equivalent experience/training).
• 4+ years of pertinent security operations / incident response experience.
• Strong comprehension of the security incident management lifecycle and operational response methodologies.
• Extensive experience with SIEM/log management platforms, such as Microsoft Sentinel, Splunk, ELK, Snowflake-based analytics, or similar tools.
• Proficiency in querying and analyzing security telemetry.
• Capability to analyze and interpret various logs including security event logs, system logs, application logs, cloud logs, and device logs.
• Practical investigation experience using AWS Security Hub, Microsoft Defender for Cloud, Google Security Command Center, and cloud logs.
• Familiarity with Python, PowerShell, or shell scripting.
• Strong written and verbal communication skills, encompassing ticket documentation, incident reporting, and stakeholder updates.
• Excellent analytical and problem-solving abilities.
• Preferred expertise in forensics, threat hunting, or detection engineering.
• Ability to comply with U.S. export control regulations.
• Bonus or commission eligibility.
• Medical benefits.
• Retirement benefits.
• Financial benefits.
• Wellness benefits.
• Paid time off.
• Employee discounts.
• Support for a growth mindset throughout all career stages.
EnableComp
Transaction Network Services (TNS)
Munson Healthcare
Get handpicked remote jobs straight to your inbox weekly.