Senior Security Analyst, Cyber Defense

SPS Commerce Inc

Minneapolis (MN)

Hybrid

USD 108,200 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SPS Commerce Inc is seeking a Senior SOC Engineer to lead detection and response, manage the SOC day to day, and drive improvements across incident response, threat hunting, and DFIR within a cloud-based environment.

You will triage alerts, coordinate incident containment, perform proactive threat hunts, and integrate AI tools to accelerate investigations. This role offers hybrid work based in Minneapolis, MN with remote flexibility.

Qualifications

  • 5+ years in security operations, incident response, or threat detection with senior-level depth in DFIR and SOC work.
  • Hands-on investigation experience with SIEM and EDR platforms, capable of searching, pivoting across identity, cloud, and network logs, and scoping incidents end to end.
  • Strong evidence-handling practice and forensic fundamentals for preserving and reasoning over disk, memory, and log artifacts.
  • Understanding of adversarial behavior (e.g., MITRE ATT&CK).
  • Familiarity with exposure management workflows—triage, prioritization, and remediation tracking.
  • Clear written and verbal communication with the judgment to brief engineers and executives appropriately.
  • Collaborative style, genuine curiosity about security and technology, and sound judgment across a large organization.
  • Internal candidates must have SOC, security operations, or security engineering experience handling escalated investigations or incident response, along with at least 1 year of SPS experience.

Responsibilities

  • Lead alert triage and investigation, serving as the escalation point for SOC alerts and gathering evidence from SIEM, EDR, identity, cloud audit trails, network and email telemetry, and other sources.
  • Run incident response for confirmed high-severity incidents: scope, contain, coordinate with stakeholders, and provide timely updates to leadership.
  • Document incidents thoroughly and ensure genuine closure beyond ticket completion.
  • Conduct proactive threat hunting informed by threat intelligence, surfacing gaps before they become incidents.
  • Integrate AI and automation tools to accelerate investigation, summarization, and documentation, and collaborate with engineering to implement improvements.
  • Collaborate with exposure management, security engineering, and cloud security teams on triage, prioritization, and remediation tracking.
  • Sharpen detections and tooling by executing runbooks, identifying stale or missing guidance, and providing improvement requests to engineering.
  • Develop the SOC by reviewing determination quality, coaching analysts, and participating in on‑call rotation.
  • Perform additional duties as assigned.

Skills

Security operations
Incident response
Threat detection
DFIR
SOC work
Communication

Tools

SIEM
EDR
CrowdStrike
SOAR

Job description

Position Summary

SPS Commerce is a leading provider of cloud‑based supply chain management solutions. As a senior member of the Cyber Defense team, you will lead detection and response activities, manage the SOC day‑to‑day, and drive continuous improvement across threat investigation, incident response, and threat hunting.

Key Responsibilities
  • Lead alert triage and investigation, serving as the escalation point for SOC alerts and gathering evidence from SIEM, EDR, identity, cloud audit trails, network and email telemetry, and other sources.
  • Run incident response for confirmed high‑severity incidents: scope, contain, coordinate with stakeholders, and provide timely updates to leadership.
  • Document incidents thoroughly and ensure genuine closure beyond ticket completion.
  • Conduct proactive threat hunting informed by threat intelligence, surfacing gaps before they become incidents.
  • Integrate AI and automation tools to accelerate investigation, summarization, and documentation, and collaborate with engineering to implement improvements.
  • Collaborate with exposure management, security engineering, and cloud security teams on triage, prioritization, and remediation tracking.
  • Sharpen detections and tooling by executing runbooks, identifying stale or missing guidance, and providing improvement requests to engineering.
  • Develop the SOC by reviewing determination quality, coaching analysts, and participating in on‑call rotation.
  • Perform additional duties as assigned.
Required Qualifications
  • 5+ years in security operations, incident response, or threat detection with senior‑level depth in DFIR and SOC work.
  • Hands‑on investigation experience with SIEM and EDR platforms, capable of searching, pivoting across identity, cloud, and network logs, and scoping incidents end to end.
  • Sound evidence‑handling practice and forensic fundamentals for preserving and reasoning over disk, memory, and log artifacts.
  • Understanding of adversarial behavior (e.g., MITRE ATT&CK).
  • Familiarity with exposure management workflows—triage, prioritization, and remediation tracking.
  • Clear written and verbal communication with the judgment to brief engineers and executives appropriately.
  • Collaborative style, genuine curiosity about security and technology, and sound judgment across a large organization.
  • Internal candidates must have SOC, security operations, or security engineering experience handling escalated investigations or incident response, along with at least 1 year of SPS experience.
Preferred Qualifications
  • Experience with CrowdStrike as an EDR platform.
  • Experience with SOAR platforms and CrowdStrike NG‑SIEM.
  • Cloud security monitoring experience, primarily AWS, with exposure to Azure, GCP, and container environments such as EKS.
  • Knowledge of Windows Defender XDR.
  • Python programming for scripting, automation, or tooling.
  • Familiarity with IaC (Terraform, CloudFormation) and CI/CD pipelines, and how to investigate and secure them.
  • Exposure to Oracle, Snowflake, Databricks, and the Atlassian suite.
  • Proactive threat hunting and threat‑intelligence experience.
Location and Work Model

This role follows a hybrid work model for candidates based in Minneapolis, MN and is also open to 100% remote candidates.

Compensation and Benefits

The annual salary range is $108,200.00 – $140,000.00 USD. The actual salary offered will be determined based on factors such as education, skills, experience, certifications, location, and more. SPS Commerce offers a comprehensive benefits package designed to support employees’ health, well‑being, and financial security. Benefits are country‑specific and aligned with local laws and market practices.

EEO Statement

We are committed to affirmative action and equal opportunity in all aspects of employment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst, Cyber Defense
Senior Security Analyst, Cyber Defense

SPS Commerce • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000
Senior Security Analyst, Cyber Defense
Senior Security Analyst, Cyber Defense

SPS Commerce, Inc. • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000
Senior Security Analyst - Lead SOC & Threat Hunting Remote
Senior Security Analyst - Lead SOC & Threat Hunting Remote

SPS Commerce Inc • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000
Senior Cyber Defense Lead - Threat Hunting & IR Hybrid
Senior Cyber Defense Lead - Threat Hunting & IR Hybrid

SPS Commerce, Inc. • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000
Senior SOC Lead: Threat Hunting & IR (Remote)
Senior SOC Lead: Threat Hunting & IR (Remote)

SPS Commerce • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Senior Cyber Threat Defense - Security Operations Engineer
Senior Cyber Threat Defense - Security Operations Engineer

Segment (Twilio) • Draper (UT)

On-site
USD 110,000 - 160,000
Competitive compensation
Comprehensive benefits
Flexible work environment
+1
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Security Operations Analyst
Security Operations Analyst

Jobgether • United States

Remote
USD 70,000 - 100,000
Remote-first
Unlimited PTO
Medical, dental, vision
+4
Sr SOC Analyst
Sr SOC Analyst

ASM Global LLC. • United States

Hybrid
USD 100,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+2