IT Security Operations Analyst

Blackstone Talent Group

San Francisco (CA)

On-site

USD 120,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Blackstone Talent Group is seeking a security operations professional to own investigations end to end, tune a new SIEM, and mentor junior analysts. You will perform deep-dive threat analyses across multiple domains and serve as escalation for complex incidents.

The role requires hands-on experience with CrowdStrike NG-SIEM, strong AWS security knowledge, and scripting abilities for automation. Strong communication and leadership in a fast-paced environment are essential.

Qualifications

  • 3+ years on an IT security operations/IR team with independent investigations.
  • Deep forensic and incident response analysis of complex business systems.
  • Hands-on with modern SIEM platforms; CrowdStrike NG-SIEM preferred.
  • Substantial AWS security experience: WAF, RDS, S3, CloudTrail/Athena.
  • Applied threat intelligence across IP, email, telephony, domain/file reputation.

Responsibilities

  • Lead deep-dive threat analysis across multiple sources to create actionable detections.
  • Escalate for security incident detection, response, containment, and recovery including forensic work.
  • Tune and mature detection content in CrowdStrike NG-SIEM; reduce false positives.
  • Analyze and correlate large-scale logs across AWS and enterprise systems.

Skills

Threat analysis
Incident response
SIEM engineering
AWS security
Threat intelligence
Cross-platform security
Scripting (Python/PowerShell/Bash)

Education

Bachelor's degree in CS/IT/CIS
Professional security certifications (CISSP/GCIA/GCFA/S+, CCNA)

Tools

CrowdStrike NG‑SIEM
S3/Athena
Pathlock
Entrust
PeopleSoft HCM

Job description

Security operations resource supporting multiple complex, systemwide business services. This role sits at the tier-2/tier-3 level: deep-dive threat analysis, detection engineering, and forensic incident response — not alert triage. The person in this seat is expected to independently own investigations end to end, validate and tune a newly implemented SIEM, and serve as an escalation point and technical mentor for less experienced analysts.

Duties
  • Lead deep-dive threat analysis across IP, telephony, email, web, and software-package threat intelligence sources (Google Threat Intelligence, Twilio, VirusTotal, and others), turning intelligence into actionable detections and response.
  • Serve as tier-2/tier-3 escalation for security incident detection, response, containment, resolution, and recovery — including forensic analysis, security event analysis, data collection, packet analysis, and ticket management.
  • Validate, tune, and mature detection content in CrowdStrike NG-SIEM (currently being implemented); confirm coverage, reduce false positives, and close visibility gaps.
  • Perform large-scale log analysis and correlation using S3, Athena, and related tooling across AWS (WAF, RDS, security groups), F5, network logs, PeopleSoft HCM, Pathlock (SSO, A360, SoD), Entrust, and other enterprise systems.
  • Administer and maintain one or more security services (SIEM, vulnerability management, threat detection, phishing, DLP), including patching, configuration changes, troubleshooting, and customer requests.
  • Prioritize and drive resolution of security issues with material financial or regulatory impact, including SOX-relevant systems and controls.
  • Analyze, report, and remediate findings from vulnerability scans and penetration tests; track risk acceptance and remediation to closure.
Required Skills / Experience
  • 3+ years on an IT security operations / incident response team in a senior analyst, engineer, or systems administrator capacity, including demonstrated ownership of complex investigations without supervision.
  • Deep forensic and incident response analysis of complex business systems.
  • Hands‐on experience with modern SIEM platforms — implementation, tuning, detection engineering, and content development. CrowdStrike NG‑SIEM or equivalent next‑gen platform strongly preferred.
  • Substantial AWS security experience: WAF, security groups, RDS, CloudTrail/log pipelines, S3 and Athena for large‑scale log analysis.
  • Applied threat intelligence experience across multiple source types (IP, email, telephony, domain/file reputation) and the ability to operationalize it.
  • Knowledge of security best practices across Linux, Windows, macOS, VMware, and Cisco IOS — including OS security tooling, configuration, logging, and patching.
  • Working knowledge of public-key cryptography and best practices for protecting data at rest and in transit.
  • Strong scripting ability (Python, PowerShell, Bash, or equivalent) for automation and data analysis.
Preferred Skills / Experience
  • Background or formal education in data science; demonstrated use of statistical or data-driven methods in threat hunting and anomaly detection.
  • Experience using AI/LLM tooling as an engineering aid for log analysis, correlation, and investigation acceleration.
  • Experience supporting ERP/HCM environments (PeopleSoft HCM) and access governance tooling (Pathlock, SoD, SSO).
  • Working knowledge of security audit processes, SOX controls, and related expectations.
  • Bachelor's degree in CS, IT, CIS, or a related field. Professional certifications (CISSP, GCIA, GCIH, GCFA, Security+, CCNA) will weigh in the candidate's favor.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Security Operations Lead
Security Operations Lead

Fireworks AI • United States

On-site
USD 140,000 - 190,000
Sr Information Security Analyst
Sr Information Security Analyst

Scorpion Therapeutics • Michigan

Hybrid
USD 120,000 - 180,000
Hybrid work two days from home
Career development opportunities
Security Analyst II
Security Analyst II

Gilder Search Group • Cleveland (OH)

On-site
USD 70,000 - 100,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Threat Management Specialist (Tier 2)
Threat Management Specialist (Tier 2)

PlanIT Group, LLC • Reston (VA)

On-site
USD 120,000 - 150,000
Senior Security Operations Analyst
Senior Security Operations Analyst

Prosegur Security USA, Inc • Lowell (MA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Senior Security Analyst
Senior Security Analyst

Yardi • Santa Barbara (CA)

On-site
USD 97,000 - 110,000