Lead Security Operations Analyst

Ledgent Technology

Houston (TX)

Hybrid

USD 110,000 - 150,000

Full time

2 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Work-from-home flexibility
Occasional in-person meetings

Job summary

Ledgent Technology is seeking a Lead Security Operations Analyst to join our mature security team in Houston, TX. You will lead investigations, mentor analysts, and drive detection engineering and automation across endpoint, cloud, identity, email, and network environments.

The ideal candidate has 5+ years in security operations, strong Microsoft Sentinel/Defender skills, and experience guiding incidents from detection through containment and recovery in a fast-paced enterprise.

Qualifications

  • 5+ years of experience in Security Operations, Security Engineering, Incident Response, or related fields.
  • Hands-on experience with Microsoft Sentinel and Microsoft Defender.
  • Experience leading security investigations end-to-end.
  • Knowledge of SIEM/EDR, IDS/IPS, email security, and threat detection.
  • Experience investigating phishing, account compromise, and identity-based threats.
  • Strong knowledge of Microsoft 365, Entra ID, AD, and cloud security concepts.
  • Experience with ServiceNow or similar ticketing platforms.
  • Excellent written and verbal communication; ability to work independently.

Responsibilities

  • Lead investigations and response for complex incidents across endpoint, cloud, identity, email, and network.
  • Monitor and triage alerts from SIEM, EDR, and other tools.
  • Mentor junior analysts as a technical escalation point.
  • Conduct proactive threat hunting to uncover undetected activity.
  • Develop and tune detection rules and use cases.
  • Support phishing, impersonation, BEC, and social engineering investigations.
  • Improve security automation workflows and SOAR playbooks.
  • Collaborate with security, IT, and cloud teams to strengthen defenses.
  • Perform forensic analysis and evidence preservation when required.
  • Maintain security procedures and incident response docs.
  • Participate in on-call rotation for critical incidents.

Skills

Lead SOC
Microsoft Sentinel
Microsoft Defender
Incident Response
Threat Hunting
Automation / SOAR
Mentoring Analysts

Tools

ServiceNow
SIEM
EDR
SOAR
Threat Intel Platforms

Job description

Lead Security Operations Analyst (JN -082026-429512) Houston, Texas

Salary: USD110000 - USD150000 per year

Title: Lead Security Operations Analyst

Location: Houston, TX or Austin, TX (Must reside locally for occasional in-person office meetings; otherwise offers work-from-home flexibility)

Employment Type: Full-Time

Industry: Professional Services / Enterprise Environment

No C2C at this time

Overview

Our client is seeking a Senior Information Security Analyst to join a mature and growing Security Operations team responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across a global enterprise environment.

This is an opportunity for a hands-on security professional who enjoys leading investigations, mentoring analysts, improving detection capabilities, and helping shape the future of security operations. The ideal candidate will bring deep experience working within Microsoft security technologies and can operate independently in a fast-paced environment with minimal oversight.

The team is heavily invested in security automation, threat detection, Microsoft Sentinel, Microsoft Defender, and AI-enabled security operations, creating an opportunity to contribute to both day-to-day security operations and long-term strategic security initiatives.

Responsibilities
  • Lead investigation and response efforts for complex security incidents across endpoint, cloud, identity, email, and network environments.
  • Monitor, triage, and investigate security alerts generated by SIEM, EDR, and other security monitoring tools.
  • Serve as a technical escalation point and mentor for junior security analysts.
  • Conduct proactive threat hunting activities to identify malicious activity not detected through existing controls.
  • Build, tune, and maintain detection rules, monitoring logic, and security use cases.
  • Support phishing, impersonation, business email compromise, and social engineering investigations.
  • Develop and improve security automation workflows, response playbooks, and SOAR capabilities.
  • Collaborate with security, infrastructure, cloud, and IT teams to strengthen defensive capabilities and improve security posture.
  • Perform forensic analysis and support evidence preservation activities when required.
  • Maintain and improve operational procedures, security documentation, and incident response processes.
  • Participate in an on-call rotation supporting critical security incidents.
Required Qualifications
  • 5+ years of experience within Security Operations, Security Engineering, Incident Response, Cybersecurity, or a related discipline.
  • Strong hands‑on experience with Microsoft Sentinel and Microsoft Defender.
  • Experience leading security investigations from detection through containment, remediation, and recovery.
  • Working knowledge of SIEM, EDR, IDS/IPS, email security, and threat detection technologies.
  • Experience investigating phishing attacks, account compromise incidents, and identity‑based threats.
  • Strong understanding of Microsoft 365, Microsoft Entra ID (Azure AD), Active Directory, and cloud security concepts.
  • Experience utilizing ServiceNow or similar ticketing/service management platforms.
  • Strong written and verbal communication skills.
  • Ability to work independently and take ownership of issues through resolution.
Preferred Qualifications

Candidates should possess strong expertise in one or more of the following disciplines:

  • Identity & Access Security
  • Cloud Security (Azure, AWS, or GCP)
  • Windows and Linux Security Operations
  • Detection Engineering
  • Security Automation and SOAR
  • Threat Hunting

Additional experience with the following is highly desirable:

  • PowerShell and/or Python
  • Security automation playbooks
  • MITRE ATT&CK Framework
  • Microsoft Security ecosystem technologies
  • AI-assisted security operations and automation
Preferred Certifications
  • Microsoft SC-200
  • Microsoft SC-300
  • Microsoft AZ-500
  • CompTIA Security+
  • CISSP
  • CCSP
  • GCIH
  • GSOC
  • GCFA
  • GCFE
  • Other cybersecurity and cloud security certifications
Ideal Candidate

The ideal candidate:

  • Thrives in a Security Operations Center (SOC) environment.
  • Can independently manage investigations with minimal oversight.
  • Possesses strong analytical and troubleshooting skills.
  • Enjoys mentoring and developing junior team members.
  • Communicates effectively with both technical and non-technical stakeholders.
  • Takes ownership and follows issues through to resolution.
  • Is passionate about continuous improvement, automation, and security innovation.
  • Works collaboratively within global teams and cross‑functional environments.
What You'll Gain
  • Exposure to a large-scale enterprise cybersecurity environment.
  • Opportunities to influence detection, response, and security automation strategies.
  • Access to advanced Microsoft security technologies.
  • Collaborative and highly skilled cybersecurity team environment.
  • Long-term career growth within an established organization.
  • Hands‑on involvement in automation, AI‑enabled security operations, detection engineering, and threat hunting initiatives.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Information Security Analyst
Information Security Analyst

NPAworldwide • City of Syracuse (NY)

On-site
USD 85,000 - 90,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Security Operations Analyst
Security Operations Analyst

Jobgether • United States

Remote
USD 70,000 - 100,000
Remote-first
Unlimited PTO
Medical, dental, vision
+4
Senior Security Analyst
Senior Security Analyst

Yardi • Santa Barbara (CA)

On-site
USD 97,000 - 110,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Senior Cybersecurity Analyst #3344
Senior Cybersecurity Analyst #3344

Genius Road, LLC • Austin (TX)

Hybrid
USD 150,000 - 190,000
Certified Women’s Business Enterprise
Equal Opportunity Employer
Cybersecurity Operations & Incident Response Manager
Cybersecurity Operations & Incident Response Manager

Jobgether • Town of Texas (WI)

Hybrid
USD 162,000 - 200,000
Competitive salary range: $162,681 – $200,000
Health, dental, and vision coverage
401(k) retirement savings plan
+3
Security Team Lead
Security Team Lead

IT Resource Hunter • Columbia (SC)

On-site
USD 85,000 - 110,000
Senior Security Operations Analyst
Senior Security Operations Analyst

Prosegur Security USA, Inc • Lowell (MA)

On-site
USD 90,000 - 120,000