Security Operations Analyst

Saronic Technologies

San Diego (CA)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical Insurance
401(k) plan
Stock options
Paid time off
Parental leave
Free lunch
Unlimited drinks & snacks

Job summary

Saronic Technologies is seeking a hands-on Security Engineer to join the Security Operations team on the front line of detection and response. You will triage alerts across endpoint, cloud, identity, network, and SaaS telemetry using SIEM and XDR platforms, perform root-cause analysis, and own initial response for well-scoped incidents.

This early-stage role offers growth across detection, investigation, and hunting with senior engineers to learn from, plus on-call duties and opportunities to

Qualifications

  • 2–5 years in security operations, SOC or IR roles with strong baseline experience.
  • Experience triaging alerts across multiple domains (endpoint, cloud, identity, network, SaaS).
  • Proficient with enterprise SIEM and can write investigative queries.
  • Hands-on with EDR tooling for triage, hunt, and response.
  • Knowledge of MITRE ATT&CK techniques applied to investigations.
  • Proficient in Python, PowerShell, or Bash for enrichment and automation.
  • Strong network fundamentals and clear written/verbal communication.
  • Ability to obtain and maintain U.S. security clearance.

Responsibilities

  • Monitor and triage alerts across endpoint, cloud, identity, network, and SaaS telemetry.
  • Investigate alerts; perform root-cause analysis with timelines and impact assessments.
  • Tune detections to reduce noise and surface gaps for engineering.
  • Own initial response for mid-tier incidents across multiple domains.
  • Participate in on-call rotation and communicate findings to leadership.
  • Contribute to post-incident reviews and remediation efforts.
  • Run targeted threat hunts and help build runbooks and playbooks.
  • Grow expertise across detection, investigation, and hunting.

Skills

Security Operations
Incident Response
Threat hunting
Python
PowerShell
Bash
MITRE ATT&CK
Communication

Tools

SIEM
XDR platforms
EDR tooling
Automation (scripting)

Job description

Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.

Job Overview

Saronic Technologies is a leader in revolutionizing autonomy at sea, developing cutting-edge unmanned surface vessels (USVs) to enhance maritime operations for defense and national security. We’re looking for a hands-on Security Engineer to join our Security Operations team on the front line of detection and response.

You’ll triage and investigate security alerts across endpoint, cloud, identity, network, and SaaS telemetry using our SIEM and XDR platforms, run root-cause analysis on real events, and own initial response for well-scoped incidents to contain, eradicate, recover. You’ll tune detections to cut noise, join the on-call rotation, run targeted threat hunts, and contribute to the playbooks and post-incident reviews that make the team better. This is an early, formative role on a SecOps team being built from the ground up, with senior engineers to learn from and real room to grow across security domains rather than being boxed into one lane.

Responsibilities
Detection & Alert Operations
  • Monitor and triage alerts across endpoint, cloud, identity, network, and SaaS telemetry using enterprise SIEM and XDR platforms
  • Investigate alerts and perform root-cause analysis, documenting clear timelines and impact assessments
  • Tune existing detections to reduce false positives, and surface gaps and tuning needs to Detection Engineering
Incident Response & Investigation
  • Own initial response for well-scoped, mid-tier incidents across endpoint, cloud, and identity to contain, eradicate, recover
  • Participate in the on-call rotation and communicate status and findings to security leadership and stakeholders
  • Contribute to post-incident reviews, surfacing gaps in detection, response, and containment
  • Coordinate with Security Engineering and IT during active incidents to accelerate response
SecOps Foundation & Enablement
  • Support security leadership and senior engineers in building response playbooks, runbooks, and analyst workflow documentation
  • Run targeted threat hunts to find activity that automated detections miss
  • Contribute to SecOps metrics, reporting, and operational-readiness reviews
  • Grow your depth across detection, investigation, and hunting as the team scales
Qualifications
  • 2-5 years of hands-on Security Operations, alert triage/SOC, or incident response experience, or an equivalent combination of experience and demonstrated ability; we are open to strong early-career talent
  • Experience triaging and investigating alerts across at least two of: endpoint, cloud, identity, network, or SaaS
  • Working proficiency with an enterprise SIEM platform and its query language; able to write investigative queries and tune existing detections
  • Hands-on experience with EDR tooling to triage, hunt, and respond using endpoint telemetry
  • Solid understanding of attacker TTPs mapped to MITRE ATT&CK, applied during investigations
  • Scripting proficiency in Python, PowerShell, or Bash for enrichment, automation, or triage
  • Strong network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral-movement patterns
  • Clear, structured written and verbal communication skills and can brief a non-technical stakeholder and write a thorough incident report
  • Ownership mindset: follows incidents through to closure and flags what needs fixing, not just what needs documenting
  • Hands-on learning signals such as a home lab, CTF participation, personal detection/hunting projects, or public writeups/blogs
  • Internship, rotational, or help-desk-to-SOC experience with a clear security operations trajectory
  • Ability to obtain and maintain a U.S. security clearance

Preferred Qualifications

  • Experience with XDR platforms and cross-domain correlated detection across endpoint, identity, and cloud
  • Familiarity with cloud-native security operations and log sources in AWS or Azure
  • Experience with SOAR platforms or building response-automation workflows
  • Exposure to supply-chain and CI/CD pipeline security monitoring
  • Familiarity with data lake-based or pipeline-driven detection architectures
  • Background in defense, aerospace, robotics, or other high-assurance operational environments
  • Familiarity with compliance frameworks such as NIST SP 800-171 or NIST SP 800-53
  • Relevant certifications are a plus but never a gate, including GIAC GCIH, GCIA, GCFA, GCFE, GCDA, GSOM, CySA+, BTL1/2, OSCP, or CISSP
  • Active security clearance or prior clearance history is a strong differentiator
Physical Demands
  • Prolonged periods of sitting at a desk and working on a computer
  • Occasional standing and walking within the office
  • Manual dexterity to operate a computer keyboard, mouse, and other office equipment
  • Visual acuity to read screens, documents, and reports
  • Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies
  • Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages)
Benefits
  • Medical Insurance: Comprehensive health insurance plans covering a range of services
  • Saronic pays 100% of the premium for employees and 80% for dependents
  • Dental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision care
  • Saronic pays 100% of the premium under the basic plan for employees and 80% for dependents
  • Time Off: Generous PTO and Holidays
  • Parental Leave: Paid maternity and paternity leave to support new parents
  • Competitive Salary: Industry-standard salaries with opportunities for performance-based bonuses
  • Retirement Plan: 401(k) plan with company match
  • Stock Options: Equity options to give employees a stake in the company’s success
  • Life and Disability Insurance: Basic life insurance and short- and long-term disability coverage
  • Pet Insurance: Discounted pet insurance options including 24/7 Telehealth helpline
  • Additional Perks: Free lunch benefit and unlimited free drinks and snacks in the office

Saronic CCPA Notice for Candidates and California Employees

If this role is based in the United States, it requires access to export-controlled information or items that require 'U.S. Person' status. As defined by U.S. law, individuals who are any one of the following are considered to be a 'U.S. Person': (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).

Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits. We are also committed to providing reasonable accommodations for qualified individuals with disabilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Operations Analyst
Senior Security Operations Analyst

Saronic • Austin (TX)

On-site
USD 120,000 - 170,000
Medical Insurance
Dental & Vision
Time Off & Holidays
+6
Security Operations Analyst
Security Operations Analyst

Saronic Technologies • San Diego (CA)

On-site
USD 130,000 - 180,000
Medical Insurance
Dental and Vision Insurance
Time Off (PTO/Holidays)
+7
Security Operations Analyst
Security Operations Analyst

Saronic Technologies • Austin (TX)

On-site
USD 120,000 - 180,000
Medical Insurance
Dental Insurance
Vision Insurance
+8
Security Operations Analyst (mid Level) Strategy & Ops
Security Operations Analyst (mid Level) Strategy & Ops

Front Door Defense • Town of Texas (WI)

On-site
USD 80,000 - 120,000
Medical Insurance
Dental and Vision Insurance
Generous PTO
+3
Senior Security Operations Analyst Strategy & Ops
Senior Security Operations Analyst Strategy & Ops

Front Door Defense • Town of Texas (WI)

On-site
USD 110,000 - 150,000
Medical Insurance
Dental and Vision Insurance
Time Off
Senior Security Operations Analyst
Senior Security Operations Analyst

Saronic Technologies • Austin (TX)

On-site
USD 90,000 - 120,000
Medical Insurance
Dental and Vision Insurance
401(k) Plan with company match
+4
Security Operations Analyst
Security Operations Analyst

NightDragon Acquisition Corp. • Austin (TX)

On-site
USD 110,000 - 170,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
Security Engineer, Cyber Threat Intelligence
Security Engineer, Cyber Threat Intelligence

Saronic Technologies • San Diego (CA)

On-site
USD 140,000 - 200,000
Medical Insurance
401(k) with company match
Dental and Vision Insurance
+5
Security Engineer, Detection Engineering
Security Engineer, Detection Engineering

NightDragon Acquisition Corp. • Austin (TX)

On-site
USD 120,000 - 170,000
Medical Insurance
Dental and Vision Insurance
Generous PTO and Holidays
+7
Security Engineer (Detection Engineering)
Security Engineer (Detection Engineering)

Saronic • Austin (TX)

On-site
USD 95,000 - 120,000
Medical Insurance
Dental and Vision Insurance
Generous PTO
+7