Senior Security Analyst, Cyber Defense

SPS Commerce

Minneapolis (MN)

Hybrid

USD 108,200 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SPS Commerce is seeking a senior member of the Cyber Defense team to lead detection and response, guide the SOC, and manage escalations across SIEM, EDR, identity, and cloud telemetry. You will shepherd investigations, drive incident response, and proactively hunt threats to keep the SOC well‑prioritized and effective.

The ideal candidate has 5+ years in security operations with DFIR and SOC experience, strong communication skills, and a track record of improving detections and runbooks.

Qualifications

  • 5+ years in security operations, incident response, or threat detection with senior‑level DFIR/SOC depth.
  • Hands‑on investigation with a SIEM and an EDR platform; ability to pivot across identity, cloud, and network logs.
  • Solid evidence handling and forensic fundamentals for disk, memory, and log artifacts.
  • Familiarity with adversarial behavior and MITRE ATT&CK.
  • Know‑how of exposure management workflows: triage, prioritization, remediation tracking.
  • Clear written and verbal communication; able to brief engineers and executives effectively.
  • Internal SPS candidates: SOC/IR/engineering experience with at least 1 year at SPS.
  • Key Skills: DFIR, SIEM/EDR, threat hunting, MITRE ATT&CK, cloud monitoring, cross‑team comms, executive briefing.

Responsibilities

  • Lead alert triage and investigation across SIEM/EDR and cloud, correlating data from multiple sources to determine escalation needs.
  • Run incident response for high‑severity incidents: scoping, containment, stakeholder coordination, thorough documentation.
  • Hunt for threats using current intelligence and surface coverage gaps before incidents occur.
  • Incorporate AI and automation to accelerate investigations, summaries, and documentation; partner with engineering to operationalize.
  • Collaborate with exposure management, security engineering, and cloud security on investigations and detections.
  • Improve detections, runbooks, and tooling; provide coaching to analysts and feed enhancements to engineering.
  • Develop the SOC: review determinations and escalation quality; participate in on‑call rotation.
  • Perform other duties as assigned.

Skills

Digital forensics and incident
SIEM/EDR investigation
Threat hunting
MITRE ATT&CK
Cloud security monitoring
Cross-team communication
Executive briefing

Tools

CrowdStrike
SOAR platforms
NG-SIEM
AWS
Azure
GCP
EKS

Job description

Description

SPS Commerce is a leading provider of cloud-based supply chain management solutions, serving a global network of retail trading partners. We foster a collaborative and inclusive work environment where innovation and continuous improvement are highly valued. Join SPS Commerce and be part of a dynamic team that’s transforming the global retail supply chain!

Position Summary

A senior member of the Cyber Defense team who leads detection and response work and provides day-to-day leadership of the SOC. This individual serves as a technical leader — setting the cultural tone, modeling high standards, and managing the SOC queue to keep work prioritized and moving. They collaborate closely across exposure management, security engineering, and cloud security.

This role owns escalated investigations, takes point on escalated incidents, and proactively hunts threats across the enterprise. Success is measured by timely, high-quality investigations, effective incident response, a well‑prioritized SOC, and clear documentation that enables consistent operations and continuous improvement.

Key Responsibilities
  • Lead alert triage and investigation: Serve as the escalation point for alerts raised by the managed SOC and monitoring systems. Pull together the full picture from whatever the investigation calls for: SIEM, EDR, identity and authentication activity, cloud audit trails, network and email telemetry, and other sources as the evidence leads. Reach accurate, defensible determinations under time pressure and decide what warrants escalation to a full incident.
  • Run incident response: Take point on confirmed higher‑severity incidents: scoping, containment, coordinating with affected stakeholders, and keeping leadership informed with clear, timely updates. Document incidents thoroughly and drive them to genuine closure, not just ticket closure.
  • Hunt for what monitoring misses: Perform proactive threat hunting informed by current threat intelligence, surfacing coverage gaps and emerging risk before they become incidents.
  • Work AI and automation into the daily craft: Use AI‑assisted tooling to accelerate investigation, summarization, and documentation, and identify where AI and automation can reduce repetitive manual work, speed response, or close gaps—partnering with engineering to make it real.
  • Partner across the team: Collaborate with exposure management on triage, prioritization, and remediation tracking, and work with security engineering and cloud security where investigations and detections cross over.
  • Sharpen detections and tooling: Execute established runbooks, identify stale or missing guidance, and feed concrete improvement requests back to engineering to strengthen detections, automations, and documentation.
  • Develop the SOC: Review SOC determination and escalation quality and provide coaching and feedback that helps analysts grow.
  • Participate in the team's on‑call rotation.
  • Perform other duties as assigned.
Required Qualifications
  • 5+ years in security operations, incident response, or threat detection, with senior‑level depth in digital forensics and incident response (DFIR) and SOC work.
  • Hands‑on investigation experience with a SIEM and an EDR platform—the specific products matter less than the ability to search, pivot across identity, cloud, and network log sources, and scope an incident end to end.
  • Sound evidence‑handling practice and forensic fundamentals, including preserving and reasoning over disk, memory, and log artifacts.
  • A working understanding of adversarial behavior (e.g., MITRE ATT&CK).
  • Working familiarity with exposure management workflows—triage, prioritization, and remediation tracking.
  • Clear written and verbal communication, with the judgment to brief both engineers and executives appropriately.
  • A collaborative working style and genuine curiosity about security and technology—a seasoned professional who exercises sound judgment and collaborates effectively across a larger organization.
  • Internal candidates: SOC, security operations, or security engineering experience handling escalated investigations or incident response and working across detection, vulnerability management, or cloud security functions, with at least 1 year of SPS experience.
  • Key Skills: Digital forensics and incident response (DFIR), SIEM/EDR investigation, threat hunting, adversarial behavior analysis (MITRE ATT&CK), cloud security monitoring, cross‑team communication and executive briefing.
Preferred Qualifications
  • Experience with Crowdstrike as an EDR platform.
  • Experience with SOAR platforms.
  • Experience with Crowdstrike NG‑SIEM.
  • Cloud security monitoring experience, primarily AWS, with some exposure to Azure and GCP, and container environments such as EKS.
  • Windows Defender XDR.
  • Python programming experience for scripting, automation, or tooling.
  • Familiarity with infrastructure‑as‑code (e.g., Terraform, CloudFormation) and CI/CD pipelines, and how to investigate and secure them.
  • Familiarity with one or more of Oracle, Snowflake, Databricks, and the Atlassian suite.
  • Proactive threat hunting and threat‑intelligence experience.
Location

This role follows a hybrid work model for candidates based in Minneapolis, MN and is also open to 100% remote candidates.

What We Offer

At SPS Commerce, we are committed to ensuring that each employee's compensation reflects their unique experiences, performance, and skills in their role. The salary range for this role is $108,200.00 – $140,000.00 USD.

SPS Commerce offers a comprehensive benefits package designed to support employees' health, well‑being, and financial security. Benefits are country‑specific and aligned with local laws and market practices.

Commitment To Our Employees

At SPS we power connections that drive the world of commerce forward, and our success depends on making strong decisions, fostering innovation, delivering unparalleled customer solutions, and driving outstanding business performance. We achieve this by creating an environment where every employee feels a true sense of belonging. We embrace diversity, equity, and inclusion, ensuring everyone feels accepted, valued, and empowered to make a meaningful impact.

We are committed to affirmative action and equal opportunity in all aspects of employment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst, Cyber Defense
Senior Security Analyst, Cyber Defense

SPS Commerce Inc • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000
Senior Security Analyst, Cyber Defense
Senior Security Analyst, Cyber Defense

SPS Commerce, Inc. • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000
Senior Manager, Risk & Controls
Senior Manager, Risk & Controls

Finch Turf, Inc. • Minneapolis (MN)

Hybrid
USD 133,000 - 208,000
Health, dental, vision insurance
401(k) plan
Paid time off
+1
Senior Security Analyst - Lead SOC & Threat Hunting Remote
Senior Security Analyst - Lead SOC & Threat Hunting Remote

SPS Commerce Inc • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000
Security Operations Analyst
Security Operations Analyst

Jobgether • United States

Remote
USD 70,000 - 100,000
Remote-first
Unlimited PTO
Medical, dental, vision
+4
Senior CIRT / Threat Intel Analyst
Senior CIRT / Threat Intel Analyst

Relha LLC • New York (NY)

On-site
USD 100,000 - 170,000
Corporate Attorney
Corporate Attorney

SPS Commerce Inc • Minneapolis (MN)

Hybrid
USD 135,000 - 210,000
Health insurance
Dental insurance
Vision insurance
+3
Sr. Financial Reporting Analyst - SEC Reporting
Sr. Financial Reporting Analyst - SEC Reporting

SPS Commerce Inc • Minneapolis (MN)

Hybrid
USD 90,200 - 129,300
Health insurance
Dental insurance
Vision insurance
+5
Sr. Financial Reporting Analyst - SEC Reporting
Sr. Financial Reporting Analyst - SEC Reporting

SPS Commerce • Minneapolis (MN)

Hybrid
USD 90,200 - 129,300
Health insurance
Dental insurance
Vision insurance
+3
Senior Sales Operations Analyst
Senior Sales Operations Analyst

SPS Commerce • United States

Hybrid
USD 69,000 - 90,000