Security Analyst (Automation & Analytics)

PRI Technology

New York (NY)

Hybrid

USD 110,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Bonus

Job summary

PRI Technology is seeking a Security Analytics Analyst for a top-tier investment bank in Midtown Manhattan. You will join a team of 11 handling SIEM/EDR, security governance and engineering, triaging alerts, investigating incidents, and improving detection through data analysis and automation.

The role emphasizes critical thinking, scripting (Python/PowerShell), and hands-on work to enhance SOC efficiency and detection quality. This is a hybrid role with three days onsite and two remote.

Qualifications

  • Hands-on scripting experience (Python/PowerShell) required.
  • Familiarity with SIEM/EDR and log analysis helpful.
  • Experience building detection rules or analytics is a plus.

Responsibilities

  • Triage and investigate alerts from SIEM, EDR, identity, and cloud platforms.
  • Act as escalation point for MSSP-generated alerts.
  • Improve alert quality and responders' consistency with feedback to MSSP.
  • Conduct structured investigations across endpoint, identity, and network telemetry.
  • Document incidents with timelines, impact, and recommendations.
  • Develop and maintain detection use cases aligned to threat frameworks.

Skills

Python scripting
PowerShell scripting
SIEM/EDR
Structured data analysis
Automation

Tools

Splunk
Elastic
Azure Sentinel

Job description

I have a unique opportunity for a Security Analytics Analyst to join the team for one of our top tier investment banks located in Midtown Manhattan. You would be joining a team of 11 that handles SIEM/EDR activities as well as Security Governance and Engineering. Please see the job description below and let me know if you should have any questions. As the Security Analyst, you will triage alerts, investigate incidents, and improve detection capabilities through data analysis and automation. The role emphasizes critical thinking, analytical reasoning, and hands-on scripting to enhance SOC efficiency and detection quality.

This is 3 days onsite, 2 days remote.

*** This does come with a very generous base salary and bonus ***

Responsibilities

  • Triage and investigate alerts from SIEM, EDR, identity, and cloud platforms
  • Act as the internal escalation point for MSSP-generated alerts
  • Provide direction and feedback to MSSP to improve alert quality and response consistency
  • Validate MSSP findings and ensure appropriate prioritization and remediation
  • Conduct structured investigations across endpoint, identity, and network telemetry
  • Correlate data across multiple sources to determine root cause and scope
  • Document incidents with clear timelines, impact assessments, and recommendations
  • Analyze logs and datasets to identify detection gaps and improve signal quality
  • Tune detection logic and reduce false positives
  • Develop and maintain detection use cases aligned to threat frameworks (e.g., MITRE ATT&CK)
  • Design, test, and deploy new detection rules and analytics based on emerging threats and internal findings
  • Build scripts (Python, PowerShell, or similar) to automate triage, enrichment, and case workflows
  • Integrate tools and APIs to streamline SOC processes
  • Improve case management workflows and response playbooks through automation
  • Propose and implement improvements to monitoring coverage and response processes
  • Contribute to playbooks, runbooks, and detection standards
  • Participate in threat hunting and simulation exercises
  • Ability to analyze incomplete or ambiguous data and form defensible conclusions
  • Strong hypothesis-driven investigation approach
  • Demonstrated problem-solving in technical or analytical contexts

Qualifications

  • Hands-on experience with scripting (Python, PowerShell, or similar)
  • Any familiarity with SIEM, EDR, and log analysis would be helpful
  • Understanding of common attack techniques and investigation methods
  • Experience working with structured or semi-structured data
  • Ability to challenge and validate security logs
  • Any experience building detection rules or analytics (Splunk, Sentinel, Elastic, etc.)
  • Exposure to AI/ML-assisted security workflows or automation tools

Senior Technical Recruiter, PRI Technology

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid Security Analytics Engineer - Automation & Detection
Hybrid Security Analytics Engineer - Automation & Detection

PRI Technology • New York (NY)

Hybrid
USD 110,000 - 170,000
Bonus
Security Operations Center Analyst
Security Operations Center Analyst

PRI Technology • New York (NY)

On-site
USD 85,000 - 140,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Security Operations Center Analyst
Security Operations Center Analyst

Madison-Davis, LLC • United States

On-site
USD 90,000 - 120,000
Sr. SOC Analyst
Sr. SOC Analyst

Insight Global • Santa Ana (CA)

On-site
USD 120,000 - 150,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Senior Security Analyst
Senior Security Analyst

23andMe • Palo Alto (CA)

On-site
USD 140,000 - 190,000
Health plans
Family planning support
Mental healthcare
+3
Senior Security Analyst
Senior Security Analyst

Yardi • Santa Barbara (CA)

On-site
USD 97,000 - 110,000
Expert Cyber Security Incident and Threat Engineer
Expert Cyber Security Incident and Threat Engineer

Request Technology, LLC • Oakland (CA)

On-site
USD 150,000 - 190,000
Bonus eligible