Senior Security Operations Analyst

Saronic

San Diego, Austin (CA, TX)

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Saronic is seeking a SecOps Analyst to join our team in San Diego, California. In this role, you will be at the forefront of our detection and response operations, handling security alerts across various platforms such as endpoint, cloud, identity, and network.

We're looking for candidates with strong network fundamentals and 3+ years of hands-on experience in security operations. Relevant certifications and scripting proficiency in Python or similar languages are ideal for this position.

Qualifications

  • Understanding of TCP/IP, DNS, HTTP/S, and firewall/proxy logs.
  • Experience with EDR tooling in operational contexts.
  • 3+ years of experience in a Security Operations role.

Responsibilities

  • Triage and investigate security alerts across multiple domains.
  • Lead initial incident response for mid-tier events.
  • Conduct post-incident reviews and contribute to improvements.

Skills

Network fundamentals
EDR tooling
Incident response
Scripting proficiency
Communication skills

Education

3+ years in Security Operations
Relevant certifications (GIAC, OSCP, etc.)

Tools

SIEM platforms
XDR platforms
SOAR platforms

Job description

Responsibilities
  • As a SecOps Analyst at Saronic, you’ll be on the front line of our detection and response operations, triaging and investigating security alerts across endpoint, cloud, identity, network, and SaaS telemetry using our SIEM and XDR platforms
  • You’ll run root cause analysis on real events, lead initial response for mid-tier incidents (contain, eradicate, recover), and tune detections to cut down on noise and sharpen what actually matters
  • Beyond the day-to-day, you’ll join the on‑call rotation, run targeted threat hunts to catch what automation misses, help build out our playbooks and runbooks, and contribute to post‑incident reviews that turn gaps into real improvements
  • This is an early, formative role on a SecOps team being built from the ground up, so you’ll have a direct hand in shaping how we operate, with room to grow across security domains rather than being boxed into one lane
  • Monitor and triage security alerts across endpoint, cloud, identity, network, and SaaS telemetry using enterprise SIEM and XDR platforms
  • Perform in‑depth alert investigation and root cause analysis, documenting findings with clear, structured timelines and impact assessments
  • Tune detections to reduce false positive noise and improve signal fidelity; contribute to detection‑as‑code pipelines using structured query languages
  • Operate across multiple detection and visibility platforms as part of a maturing, layered security monitoring ecosystem
  • Lead initial incident response for mid‑tier events: contain, eradicate, and recover across endpoint, cloud, and identity domains
  • Participate in the on‑call incident rotation and effectively communicate status and findings to the SecOps Lead and relevant stakeholders
  • Conduct post‑incident reviews, identifying gaps in detection, response, and containment and translating them into actionable improvements
  • Coordinate with Security Engineering and IT during active incidents to accelerate response and reduce dwell time
  • Support the SecOps Lead in developing and refining response playbooks, runbooks, and analyst workflow documentation
  • Conduct targeted threat hunting operations to identify attacker activity not surfaced by automated detections
  • Contribute to SecOps metrics tracking, reporting, and operational readiness reviews
  • Help onboard and mentor junior analysts as the team grows, serving as a technical resource and process guide
Qualifications

Strong understanding of network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral movement patterns.

Experience with EDR tooling in an operational context; ability to hunt, triage, and respond using endpoint telemetry.

Ownership mindset: you follow incidents through to closure and flag what needs to be fixed, not just what needs to be documented.

3+ years of hands‑on experience in a Security Operations, detection engineering, or incident response role.

Solid understanding of attacker TTPs mapped to MITRE ATT&CK, and the ability to apply that knowledge during active investigations.

Experience writing or iterating on detection logic, response playbooks, or SOC operational documentation.

Hands‑on proficiency with enterprise SIEM platforms and their query languages; ability to write and iterate on detection logic from scratch.

Clear and structured written and verbal communication — you can brief a non‑technical stakeholder and write a thorough incident report.

Security Clearance eligible.

Demonstrated experience triaging and investigating alerts across at least two of the following: endpoint, cloud, identity, network, or SaaS environments.

Scripting proficiency in Python, PowerShell, or Bash for alert enrichment, automation, or triage support.

Experience with XDR platforms and cross‑domain correlated detection across endpoint, identity, and cloud.

Familiarity with cloud‑native security operations and log sources in AWS or Azure environments.

Experience with SOAR platforms or building response automation workflows.

Exposure to supply chain and CI/CD pipeline security monitoring.

Familiarity with data lake‑based or pipeline‑driven detection architectures.

Experience operating in or supporting classified, GovCloud, or FedRAMP environments.

Background in defense, aerospace, robotics, or other high‑assurance operational environments.

Relevant certifications: GIAC GCIH, GCIA, GCFE, BTL1/2, CySA+, OSCP, or equivalent.

Familiarity with compliance frameworks such as NIST SP 800‑171, NIST SP 800‑53, or CMMC.

Active security clearance or prior clearance history is a strong differentiator.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Analyst
Security Operations Analyst

Saronic Technologies • Austin (TX)

On-site
USD 120,000 - 180,000
Medical Insurance
Dental Insurance
Vision Insurance
+8
Security Operations Analyst
Security Operations Analyst

Saronic Technologies • San Diego (CA)

On-site
USD 130,000 - 180,000
Medical Insurance
Dental and Vision Insurance
Time Off (PTO/Holidays)
+7
Senior Security Operations Analyst
Senior Security Operations Analyst

Saronic Technologies • Austin (TX)

On-site
USD 90,000 - 120,000
Medical Insurance
Dental and Vision Insurance
401(k) Plan with company match
+4
Senior Security Operations Analyst
Senior Security Operations Analyst

Saronic • Austin (TX)

On-site
USD 120,000 - 170,000
Medical Insurance
Dental & Vision
Time Off & Holidays
+6
Security Operations Analyst
Security Operations Analyst

Saronic Technologies • San Diego (CA)

On-site
USD 120,000 - 180,000
Medical Insurance
401(k) plan
Stock options
+4
Senior Security Analyst – Security Operations Center
Senior Security Analyst – Security Operations Center

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Security Operations Analyst (mid Level) Strategy & Ops
Security Operations Analyst (mid Level) Strategy & Ops

Front Door Defense • Town of Texas (WI)

On-site
USD 80,000 - 120,000
Medical Insurance
Dental and Vision Insurance
Generous PTO
+3
Senior Security Operations Analyst Strategy & Ops
Senior Security Operations Analyst Strategy & Ops

Front Door Defense • Town of Texas (WI)

On-site
USD 110,000 - 150,000
Medical Insurance
Dental and Vision Insurance
Time Off
Senior SecOps Analyst — Incident Response & Detection
Senior SecOps Analyst — Incident Response & Detection

Front Door Defense • Town of Texas (WI)

On-site
USD 110,000 - 150,000
Medical Insurance
Dental and Vision Insurance
Time Off
Senior SecOps Analyst: Detect, Hunt & Respond
Senior SecOps Analyst: Detect, Hunt & Respond

Saronic Technologies • San Diego (CA)

On-site
USD 130,000 - 180,000
Medical Insurance
Dental and Vision Insurance
Time Off (PTO/Holidays)
+7