Security Operations Analyst

Koitecc Solutions

Santa Clara, Northern (CA, KY)

Hybrid

USD 92,000 - 115,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Koitecc Solutions is seeking a Security Operations Analyst to bolster security capabilities across the university through scripting, automation, and data integration. You will help test, implement, and maintain automated operations and workflows under guidance from senior staff.

The role focuses on monitoring security events, supporting incident response, and assisting with security assessments in a collaborative higher-education environment.

Qualifications

  • Knowledge of information technology and information security concepts.
  • Ability to work in a collaborative environment and meet deadlines.
  • Excellent customer service and communication skills.

Responsibilities

  • Security Automation & Operational Tooling: Develop, test, and maintain API integrations and webhooks for security data feeds.
  • Playbook maintenance: Script and maintain security playbooks to streamline alert response.
  • Workflow integrations: Build automated workflows and provide documentation for investigations.
  • Operational tooling support: Evaluate automation tools and AI-assisted productivity tools.
  • Validate results: Ensure accuracy of automated or AI-derived data outputs.

Skills

Python scripting
Shell scripting
Security operations
Incident response

Job description

Position Title:

Security Operations Analyst


Position Type:

Regular


Hiring Range:

$91,800 - $114,785 annually; Compensation will be based on education, experience, skills relevant to the role, and internal equity.


Pay Frequency:

Annual


POSITION PURPOSE

The Security Operations Analyst is focused on supporting and enhancing security capabilities across the university through software scripting, automation maintenance, data integration, and the utilization of security tools. Working under the general guidance of senior team members, this position helps test, implement, and maintain automated security operations and workflows.


Secondary duties include initial monitoring and triage of security events, supporting incident response, and assisting with security assessments. This role is designed for a technically curious individual looking to build foundational security engineering and operational experience within a collaborative higher education environment.


The Security Operations Analyst reports to the Chief Information Security Officer and is a member of the Information Security Office. This office works with the university community to secure system and network resources, protect the confidentiality of student, faculty, and staff information, and raise cybersecurity awareness. In conjunction with technical teams, risk management, legal, and other university and external vendors and partners, the Information Security Office works to ensure regulatory compliance, best practices, and secure information handling.


The activities of this position must support the Mission and Goals of the University and Information Services. Demonstrated experience with and a commitment to delivering excellent customer service is required.


ESSENTIAL DUTIES AND RESPONSIBILITIES

Security Automation & Operational Tooling



  • Data Ingestion Pipelines: Assist in the development, testing, and routine maintenance of API integrations and webhooks that connect internal asset inventories and security data feeds.

  • Playbook Maintenance: Support the testing, scripting, and continuous maintenance of established security playbooks and workflows within security orchestration and automation platforms to streamline alert response times.

  • Workflow Integrations: Help build and maintain automated workflows and integrations that provide security personnel with relevant documentation, procedures, and operational context during investigations.

  • Operational Tooling Support: Test and evaluate emerging automation and AI-assisted productivity tools under guidance to help improve alert triage and operational efficiency.

  • Validate Results: Review and validate automated or AI-assisted analysis results to ensure accuracy and reliable data outputs for the security team.


Threat Detection & Operational Response



  • Automated Event Triage: Maintain and optimize basic Python and shell scripts used to automate the initial gathering of context and enrichment data for incoming security events.

  • Threat Data Monitoring: Participate in cybersecurity intelligence-sharing communities to monitor external threat data and help cross-reference newly identified Indicators of Compromise (IOCs) against internal systems.

  • Incident Support: Monitor security event queues, investigate anomalies, and serve as an operational contributor during security incidents under the direction of senior security personnel.


Compliance, Documentation, & Security Reviews



  • Participate in Security Reviews: Assist senior analysts in reviewing system configurations, data flows, and software deployments to verify alignment with university security standards and compliance guidelines.

  • Document Processes: Help translate manual workflows into structured, reproducible scripts and maintain clear, up-to-date technical documentation.

  • Promote Best Practices: Actively encourage information security best practices and contribute to campus cybersecurity awareness efforts.

  • Other Duties: Perform other security-related duties and technical support tasks as assigned.


PROVIDES WORK DIRECTION

This position does not have any direct reports.


GENERAL GUIDELINES


  • Works under general supervision to develop, test, and maintain programmatic security scripts and event triage workflows.

  • Consults with senior analysts or supervisor on complex problems, policy interpretations, or high-risk architectural decisions.

  • Identifies system alignment with security standards using automated validation workflows and tracks remediation efforts.

  • Prepares and submits technical metrics and routine incident reports as requested.

  • Interacts with the University community to identify potential security issues, and to foster relationships between the Security Office and the broader University community.


QUALIFICATIONS

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The items below are representative of the knowledge, skills, abilities, education, and experience required or preferred. This position requires the ability to effectively establish and maintain cooperative working relationships within a diverse multicultural environment.


1. Knowledge, Skills, and Abilities


General



  • Knowledge of information technology, infrastructure trends, and information security concepts, with the ability to continually develop new technical knowledge and skills.

  • Ability to work in a collaborative environment, as either a member or leader of a project team, to meet deadlines and achieve goals.

  • Ability to interact with a diverse workforce to provide excellent customer service.

  • Self-motivated, showing initiative and a passion for continuous improvement.

  • Ability to successfully keep track of and manage multiple tasks and project assignments simultaneously.

  • Ability to exercise independent judgment and engage in critical thinking and complex problem solving.

  • Ability to manage multiple priorities and respond effectively to operational security issues in a dynamic technical environment.

  • Ability to explain technical, risk, and automated security concepts to non-experts and diverse audiences.

  • Ability to maintain confidentiality and securely manage confidential information.

  • Must possess impeccable integrity, executing responsibilities while maintaining the trust and confidence of senior management.

  • Appreciation for the University's mission, vision, values, priorities, procedures, and policies.


Position-Specific



  • Proficiency in Python or shell scripting (e.g., Bash) for basic data manipulation, log parsing, or automating repetitive tasks.

  • Basic understanding of RESTful APIs, webhooks, and standard data exchange formats like JSON or XML.

  • Familiarity with core security concepts (e.g., common network protocols, operating system security internals, and log analysis).

  • Familiarity with software engineering fundamentals (such as version
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Analyst
Security Operations Analyst

Sacbar • Santa Clara (CA), Northern (KY)

Hybrid
USD 92,000 - 115,000
Security Operations Specialist
Security Operations Specialist

The University of North Carolina • Charlotte (NC)

On-site
USD 90,000 - 120,000
IT Security Specialist
IT Security Specialist

ibex • Palestine (TX)

On-site
USD 90,000 - 130,000
Analyst, Security
Analyst, Security

Socket.dev • Owensboro (KY)

On-site
USD 55,000 - 75,000
Medical
Vision
Dental
+11
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Security Operations Analyst
Security Operations Analyst

Santa-Clara-University • Palo Alto (CA)

Hybrid
USD 92,000 - 115,000
Security Engineer I
Security Engineer I

tamus • College Station (TX)

On-site
USD 80,000 - 92,000
Systems Security Analyst
Systems Security Analyst

Brown University Health • Rhode Island

On-site
USD 102,000 - 169,000
Medical insurance
Vision insurance
401(k)
+3
Senior Information Security Analyst
Senior Information Security Analyst

UMass Amherst • Amherst (MA)

Hybrid
USD 120,000 - 150,000
Senior Cybersecurity Ops Analyst
Senior Cybersecurity Ops Analyst

Jobtailor • Santa Ana (CA)

On-site
USD 75,000 - 120,000