Get more replies from employers
Send a job-specific resume in minutes.
Saronic is seeking a SecOps Analyst to join our team in San Diego, California. In this role, you will be at the forefront of our detection and response operations, handling security alerts across various platforms such as endpoint, cloud, identity, and network.
We're looking for candidates with strong network fundamentals and 3+ years of hands-on experience in security operations. Relevant certifications and scripting proficiency in Python or similar languages are ideal for this position.
Strong understanding of network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral movement patterns.
Experience with EDR tooling in an operational context; ability to hunt, triage, and respond using endpoint telemetry.
Ownership mindset: you follow incidents through to closure and flag what needs to be fixed, not just what needs to be documented.
3+ years of hands‑on experience in a Security Operations, detection engineering, or incident response role.
Solid understanding of attacker TTPs mapped to MITRE ATT&CK, and the ability to apply that knowledge during active investigations.
Experience writing or iterating on detection logic, response playbooks, or SOC operational documentation.
Hands‑on proficiency with enterprise SIEM platforms and their query languages; ability to write and iterate on detection logic from scratch.
Clear and structured written and verbal communication — you can brief a non‑technical stakeholder and write a thorough incident report.
Security Clearance eligible.
Demonstrated experience triaging and investigating alerts across at least two of the following: endpoint, cloud, identity, network, or SaaS environments.
Scripting proficiency in Python, PowerShell, or Bash for alert enrichment, automation, or triage support.
Experience with XDR platforms and cross‑domain correlated detection across endpoint, identity, and cloud.
Familiarity with cloud‑native security operations and log sources in AWS or Azure environments.
Experience with SOAR platforms or building response automation workflows.
Exposure to supply chain and CI/CD pipeline security monitoring.
Familiarity with data lake‑based or pipeline‑driven detection architectures.
Experience operating in or supporting classified, GovCloud, or FedRAMP environments.
Background in defense, aerospace, robotics, or other high‑assurance operational environments.
Relevant certifications: GIAC GCIH, GCIA, GCFE, BTL1/2, CySA+, OSCP, or equivalent.
Familiarity with compliance frameworks such as NIST SP 800‑171, NIST SP 800‑53, or CMMC.
Active security clearance or prior clearance history is a strong differentiator.