Quick Overview
Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
3 days ago
SplunkTCP/IPDNSHIPAA
Job Description
Systems Engineer 3 – Senior Security Operations Analyst
Introduction: The Senior Security Operations Analyst will be responsible for monitoring, investigating, and responding to security events across network, endpoint, identity, and cloud environments.
Responsibilities:
- Monitor security alerts, logs, network events, endpoint telemetry, and threat intelligence feeds
- Triage and investigate suspicious activity and determine scope and business impact
- Coordinate incident escalation, containment, and remediation activities
- Build and tune detection rules, dashboards, alerts, playbooks, and automation workflows
- Perform threat hunting using KQL, SPL, endpoint telemetry, and packet/session analysis
- Perform EDR and NDR investigations
- Support vulnerability, risk, and security-control assessments
- Prepare incident reports and track corrective actions
- Work with network, infrastructure, cloud, and application teams to validate security events
- Provide security evidence and metrics for compliance and audit requests
- Support high-priority incidents or planned maintenance outside normal business hours when required
Requirements:
Required Qualifications:
- 7+ years of cybersecurity, network security, SOC, or incident-response experience
- Strong hands-on experience with Microsoft Sentinel
- Strong hands-on KQL experience
- Experience with Sentinel incident management, analytics rules, workbooks, automation, and data connectors
- Strong SIEM experience including log analysis, alert investigation, and correlation
- Hands-on EDR and NDR experience
- Threat hunting and incident-response experience
- Network traffic and packet/session analysis
- Strong knowledge of firewalls, IDS/IPS, DNS, VPN, proxy logs, TCP/IP, and network segmentation
- Knowledge of NIST, CIS Controls, HIPAA, and security compliance requirements
- Excellent analytical, written, and verbal communication skills
Preferred Qualifications:
- Google SecOps / Google Chronicle experience
- Wiz experience
- Splunk and SPL experience
- Microsoft Defender, CrowdStrike, or SentinelOne experience
- SC-200, AZ-500, or SC-100 certification
- Security+, CySA+, GIAC, CISSP, CISM, or CISA
- Splunk certifications
- Healthcare or public-sector experience
- Experience mentoring junior security analysts
Important: Candidates must be comfortable working onsite in Austin, TX and must be eligible to work as a direct W2 employee.
Similar jobs
- LT
Looking for Security Engineer Engineering Security Seattle WA Preferred Sunnyvale CA Day 1 Onsite
NewLorven Technologies, Inc.
Seattle, WA🇺🇸On-siteYesterdayMicroservicesBashLLM+2Technology - IU
AI Security Engineer Engineering Security
NewIBOTIX US Inc.
Sunnyvale, CA🇺🇸On-siteYesterdayMicroservicesBashLLM+2Technology - BA
Junior Cybersecurity Test Engineer
NewBooz Allen Hamilton
Rome, NY🇺🇸$55.2k - $126k/yrOn-site2 days agoRubyBashPenetration Testing+1Technology - GT
Information Systems Security Officer (ISSO) II with Security Clearance
NewgTANGIBLE Corporation
Suitland, MD🇺🇸HybridYesterdayTechnology - TE
Senior Vulnerability Management Engineer
NewTechWish
United States🇺🇸RemoteYesterdayPythonPowerShellBash+6Technology - AS
Professional - Security Analyst I
NewApex Systems
Houston, TX🇺🇸HybridYesterdayAzureSplunkTechnology