Security Operations Analyst

Saronic Technologies

Austin (TX)

On-site

USD 120,000 - 180,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Insurance
Time Off
Parental Leave
401(k) plan with company match
Stock Options
Life and Disability Insurance
Pet Insurance
Free lunch in office
Unlimited drinks and snacks

Job summary

Saronic Technologies is seeking a Senior SecOps Analyst to join its growing security team in Austin. You will triage alerts across endpoints, cloud, identity, and network, lead initial response for mid-tier incidents, and tune detections to reduce noise, while collaborating on playbooks and runbooks.

You will perform targeted threat hunting, contribute to incident reviews, and mentor junior analysts as the SecOps team scales, leveraging strong SIEM/XDR capabilities.

Qualifications

  • 3+ years in Security Operations, detection engineering, or IR roles.
  • Experience triaging alerts across multiple environments (endpoint, cloud, identity, network, SaaS).
  • Proficiency with SIEM queries; ability to write detection logic from scratch.
  • Experience with EDR tooling and endpoint telemetry for hunting, triage, and response.
  • Knowledge of attacker TTPs mapped to MITRE ATT&CK and applying it in investigations.
  • Experience writing detection logic, response playbooks, or SOC docs.
  • Python/PowerShell/Bash for alert enrichment and automation.
  • Solid network fundamentals (TCP/IP, DNS, HTTP/S, logs).
  • Clear written and verbal communication; ability to brief non-technical stakeholders.
  • Ownership mindset; follow incidents through to closure; security clearance eligible.

Responsibilities

  • Monitor and triage security alerts across endpoint, cloud, identity, network, and SaaS telemetry.
  • Lead initial incident response for mid-tier events: contain, eradicate, recover.
  • Tune detections to reduce false positives and improve signal fidelity.
  • Participate in on-call rotation and communicate status to SecOps Lead.
  • Contribute to playbooks, runbooks, and analyst workflow docs.
  • Conduct targeted threat hunts to identify attacker activity not surfaced by automation.
  • Assist in SecOps metrics tracking and readiness reviews.
  • Mentor junior analysts as the team grows.

Skills

Python
PowerShell
Bash
MITRE ATT&CK
Threat hunting
Detection logic
SOC concepts

Education

GIAC GCIH
GCIA
GCFE

Tools

SIEM platforms
XDR platforms
EDR tooling
SOAR platforms

Job description

Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.

Job Overview

As a Senior SecOps Analyst at Saronic, you'll be on the front line of our detection and response operations, triaging and investigating security alerts across endpoint, cloud, identity, network, and SaaS telemetry using our SIEM and XDR platforms. You'll run root cause analysis on real events, lead initial response for mid-tier incidents (contain, eradicate, recover), and tune detections to cut down on noise and sharpen what actually matters. Beyond the day-to-day, you'll join the on-call rotation, run targeted threat hunts to catch what automation misses, help build out our playbooks and runbooks, and contribute to post-incident reviews that turn gaps into real improvements. This is an early, formative role on a SecOps team being built from the ground up, so you'll have a direct hand in shaping how we operate, with room to grow across security domains rather than being boxed into one lane.

Responsibilities
Detection & Alert Operations
  • Monitor and triage security alerts across endpoint, cloud, identity, network, and SaaS telemetry using enterprise SIEM and XDR platforms
  • Perform in-depth alert investigation and root cause analysis, documenting findings with clear, structured timelines and impact assessments
  • Tune detections to reduce false positive noise and improve signal fidelity; contribute to detection-as-code pipelines using structured query languages
  • Operate across multiple detection and visibility platforms as part of a maturing, layered security monitoring ecosystem
Incident Response & Investigation
  • Lead initial incident response for mid-tier events: contain, eradicate, and recover across endpoint, cloud, and identity domains
  • Participate in the on-call incident rotation and effectively communicate status and findings to the SecOps Lead and relevant stakeholders
  • Conduct post-incident reviews, identifying gaps in detection, response, and containment and translating them into actionable improvements
  • Coordinate with Security Engineering and IT during active incidents to accelerate response and reduce dwell time
SecOps Foundation & Enablement
  • Support the SecOps Lead in developing and refining response playbooks, runbooks, and analyst workflow documentation
  • Conduct targeted threat hunting operations to identify attacker activity not surfaced by automated detections
  • Contribute to SecOps metrics tracking, reporting, and operational readiness reviews
  • Help onboard and mentor junior analysts as the team grows, serving as a technical resource and process guide
Qualifications
  • 3+ years of hands‑on experience in a Security Operations, detection engineering, or incident response role
  • Demonstrated experience triaging and investigating alerts across at least two of the following: endpoint, cloud, identity, network, or SaaS environments
  • Hands-on proficiency with enterprise SIEM platforms and their query languages; ability to write and iterate on detection logic from scratch
  • Experience with EDR tooling in an operational context; ability to hunt, triage, and respond using endpoint telemetry
  • Solid understanding of attacker TTPs mapped to MITRE ATT&CK, and the ability to apply that knowledge during active investigations
  • Experience writing or iterating on detection logic, response playbooks, or SOC operational documentation
  • Scripting proficiency in Python, PowerShell, or Bash for alert enrichment, automation, or triage support
  • Strong understanding of network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral movement patterns
  • Clear and structured written and verbal communication — you can brief a non-technical stakeholder and write a thorough incident report
  • Ownership mindset: you follow incidents through to closure and flag what needs to be fixed, not just what needs to be documented
  • Security Clearance eligible
Preferred Qualifications
  • Experience with XDR platforms and cross-domain correlated detection across endpoint, identity, and cloud
  • Familiarity with cloud-native security operations and log sources in AWS or Azure environments
  • Experience with SOAR platforms or building response automation workflows
  • Exposure to supply chain and CI/CD pipeline security monitoring
  • Familiarity with data lake-based or pipeline-driven detection architectures
  • Experience operating in or supporting classified, GovCloud, or FedRAMP environments
  • Background in defense, aerospace, robotics, or other high-assurance operational environments
  • Familiarity with compliance frameworks such as NIST SP 800-171, NIST SP 800-53, or CMMC
  • Relevant certifications: GIAC GCIH, GCIA, GCFE, BTL1/2, CySA+, OSCP, or equivalent
  • Active security clearance or prior clearance history is a strong differentiator
Physical Demands
  • Prolonged periods of sitting at a desk and working on a computer
  • Occasional standing and walking within the office
  • Manual dexterity to operate a computer keyboard, mouse, and other office equipment
  • Visual acuity to read screens, documents, and reports
    Benefits
    • Medical Insurance: Comprehensive health insurance plans covering a range of services
    • Saronic pays 100% of the premium for employees and 80% for dependents
    • Dental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision care
    • Saronic pays 100% of the premium under the basic plan for employees and 80% for dependents
    • Time Off: Generous PTO and Holidays
    • Parental Leave: Paid maternity and paternity leave to support new parents
    • Competitive Salary: Industry-standard salaries with opportunities for performance-based bonuses
    • Retirement Plan: 401(k) plan with company match
    • Stock Options: Equity options to give employees a stake in the company’s success
    • Life and Disability Insurance: Basic life insurance and short- and long-term disability coverage
    • Pet Insurance: Discounted pet insurance options including 24/7 Telehealth helpline
    • Additional Perks: Free lunch benefit and unlimited free drinks and snacks in the office

    Saronic CCPA Notice for Candidates and California Employees

    If this role is based in the United States, it requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).

    Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits.

    We are also committed to providing reasonable accommodations for qualified individuals with disabilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Analyst
Security Operations Analyst

Saronic Technologies • San Diego (CA)

On-site
USD 130,000 - 180,000
Medical Insurance
Dental and Vision Insurance
Time Off (PTO/Holidays)
+7
Senior Security Operations Analyst
Senior Security Operations Analyst

Saronic • Austin (TX)

On-site
USD 120,000 - 170,000
Medical Insurance
Dental & Vision
Time Off & Holidays
+6
Security Operations Analyst
Security Operations Analyst

Saronic Technologies • San Diego (CA)

On-site
USD 120,000 - 180,000
Medical Insurance
401(k) plan
Stock options
+4
Senior Security Operations Analyst
Senior Security Operations Analyst

Saronic Technologies • Austin (TX)

On-site
USD 90,000 - 120,000
Medical Insurance
Dental and Vision Insurance
401(k) Plan with company match
+4
Security Operations Analyst (mid Level) Strategy & Ops
Security Operations Analyst (mid Level) Strategy & Ops

Front Door Defense • Town of Texas (WI)

On-site
USD 80,000 - 120,000
Medical Insurance
Dental and Vision Insurance
Generous PTO
+3
Senior Security Operations Analyst Strategy & Ops
Senior Security Operations Analyst Strategy & Ops

Front Door Defense • Town of Texas (WI)

On-site
USD 110,000 - 150,000
Medical Insurance
Dental and Vision Insurance
Time Off
Security Operations Analyst
Security Operations Analyst

NightDragon Acquisition Corp. • Austin (TX)

On-site
USD 110,000 - 170,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
Security Engineer, Cyber Threat Intelligence
Security Engineer, Cyber Threat Intelligence

Saronic Technologies • San Diego (CA)

On-site
USD 140,000 - 200,000
Medical Insurance
401(k) with company match
Dental and Vision Insurance
+5
Security Engineer, Detection Engineering
Security Engineer, Detection Engineering

NightDragon Acquisition Corp. • Austin (TX)

On-site
USD 120,000 - 170,000
Medical Insurance
Dental and Vision Insurance
Generous PTO and Holidays
+7
Security Engineer (Detection Engineering)
Security Engineer (Detection Engineering)

Saronic • Austin (TX)

On-site
USD 95,000 - 120,000
Medical Insurance
Dental and Vision Insurance
Generous PTO
+7