Senior Security Operations Analyst

McKinsey & Company, Inc.

San Jose (CA)

On-site

USD 140,000 - 200,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Continuous learning
A voice that matters
Global community
Exceptional benefits

Job summary

McKinsey & Company, Inc. is looking for a cybersecurity incidents expert to monitor and respond to events across enterprise and multi-cloud environments.

You will conduct triage, containment, eradication, recovery, and post-incident documentation, while developing detection use cases and improving SOC automation. You will also perform threat hunting and collaborate with leadership to communicate findings and remediation actions.

Qualifications

  • 4+ years hands-on experience in Security Operations, Cyber Defense, Incident Response, or Threat Detection.
  • Experience in SOC operations and incident response across enterprise and multi-cloud environments.
  • Hands-on experience investigating events across AWS, Azure, and GCP with cloud-native services.
  • Strong knowledge of MITRE ATT&CK, Cyber Kill Chain, and modern threat actor TTPs.

Responsibilities

  • Monitor, investigate, and respond to cybersecurity incidents across enterprise and multi-cloud environments.
  • Perform incident triage, containment, eradication, recovery, and post-incident documentation.
  • Develop, tune, and optimize detection use cases and correlation rules.
  • Contribute to SOC automation workflows and incident response playbooks; threat hunting to identify threats.

Skills

Security Operations
Incident Response
Threat Detection
Cloud security
EDR/XDR monitoring
SIEM
Scripting (Python/PowerShell/Bash)
MITRE ATT&CK / Kill Chain

Education

Security certifications (GCIH GCFA GCFE CEH)

Tools

Microsoft Defender EDR
Cortex XSIAM
SIEM tools
IDS/IPS
Cloud logging services

Job description

Do you want to do work that matters, alongside supportive leaders who will help you grow faster than you ever thought possible? Are you a creative problem-solver who is energized by challenges? You’ve come to the right place.

YOUR IMPACT

Your work focuses on monitoring, investigating, and responding to cybersecurity incidents across enterprise and multi-cloud environments. You will investigate and respond to security incidents generated from multiple detection sources, serving as an incident handler for high-impact security events sources, serving as an incident handler for high-impact security events. You will perform endpoint, network, identity, and cloud log analysis to identify malicious activity, determine root cause, communicate to leadership and recommend appropriate containment and remediation actions. You will conduct incident triage, containment, eradication, recovery, and post-incident documentation in accordance with established response procedures. You will also perform threat hunting activities using endpoint, network, and cloud telemetry to proactively identify suspicious behavior and emerging threats. You will develop, tune, and optimize security detection use cases, correlation rules, to improve monitoring effectiveness and reduce false positives. You will contribute to the development and enhancement of SOC automation workflows and playbooks to improve operational efficiency. Also, you will contribute to the continuous improvement of SOC processes, detection capabilities, and incident response procedures.

YOUR GROWTH

You are someone who thrives in a high-performance environment, bringing a growth mindset and entrepreneurial spirit to tackle meaningful challenges that have a real impact. In return for your drive, determination, and curiosity, we’ll provide the resources, mentorship, and opportunities to help you quickly broaden your expertise, grow into a well-rounded professional, and contribute to work that truly makes a difference.

When you join us, you will have:

  • Continuous learning:Our learning and apprenticeship culture, backed by structured programs, is all about helping you grow while creating an environment where feedback is clear, actionable, and focused on your development. The real magic happens when you take the input from others to heart and embrace the fast-paced learning experience, owning your journey.
  • A voice that matters:From day one, we value your ideas and contributions. You’ll make a tangible impact by offering innovative ideas and practical solutions, all while upholding our unwavering commitment to ethics and integrity. We not only encourage diverse perspectives, but they are critical in driving us toward the best possible outcomes.
  • Global community:With colleagues across 65+ countries and over 100 different nationalities, our firm’s diversity fuels creativity and helps us come up with the best solutions. Plus, you’ll have the opportunity to learn from exceptional colleagues with diverse backgrounds and experiences.
  • Exceptional benefits:On top of a competitive salary (based on your location, experience, and skills), we provide a comprehensive benefits package to enable holistic well-being for you and your family.
YOUR QUALIFICATIONS AND SKILLS
  • Industry certifications such as GCIH, GCFA, GCFE, CEH, or equivalent are preferred
  • 4+ years of hands-on experience in Security Operations, Cyber Defense, Incident Response, or Threat Detection
  • Experience working within a Security Operations Center (SOC) or Cyber Defense team, handling security monitoring and incident response activities
  • Strong understanding of security monitoring, incident detection, investigation, and response across enterprise and multi-cloud environments
  • Hands-on experience investigating security events across AWS, Microsoft Azure, and Google Cloud Platform (GCP), with familiarity with cloud-native security services and logging
  • Solid understanding of the Cyber Kill Chain®, MITRE ATT&CK Framework, modern threat actor tactics, techniques, and procedures (TTPs), and incident response methodologies
  • Experience analyzing endpoint, network, authentication, application, and cloud logs using SIEM and XDR platforms
  • Strong working knowledge of Microsoft Defender EDR, and Palo Alto Cortex XSIAM
  • Experience using EDR/XDR, SIEM, IDS/IPS, email security, identity security, and cloud security tools during investigations
  • Working knowledge of Python, PowerShell, or Bash for investigation, automation, or operational efficiency
  • Strong analytical and problem-solving skills with the ability to investigate and resolve complex security incidents

FOR U.S. APPLICANTS: McKinsey & Company is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by applicable law.

FOR NON-U.S. APPLICANTS: McKinsey & Company is an Equal Opportunity employer. For additional details regarding our global EEO policy and diversity initiatives, please visit our McKinsey Careers and Diversity & Inclusion sites.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Specialist - Defense and Security
Specialist - Defense and Security

McKinsey & Company • Charlotte (NC)

Hybrid
USD 192,000
Exceptional training and mentorship
Comprehensive benefits package
Opportunities for travel and collaboration
Specialist - Defense and Security
Specialist - Defense and Security

McKinsey & Company • Houston (TX)

Hybrid
USD 192,000
Comprehensive benefits package
Exceptional training and coaching
Security Operations Analyst
Security Operations Analyst

Jobgether • United States

Remote
USD 70,000 - 100,000
Remote-first
Unlimited PTO
Medical, dental, vision
+4
Specialist - Defense and Security
Specialist - Defense and Security

McKinsey & Company • Boston (MA)

On-site
USD 192,000
Comprehensive benefits package
Exceptional training and mentoring
Cyber Risk Specialist - Risk & Resilience
Cyber Risk Specialist - Risk & Resilience

McKinsey & Company • Palo Alto (CA)

On-site
USD 173,000 - 211,000
Competitive salary
Comprehensive benefits package
Specialist - Defense and Security
Specialist - Defense and Security

McKinsey & Company • Denver (CO)

Hybrid
USD 192,000
Comprehensive benefits package
Continuous learning and mentorship
Global community
Cyber Risk Specialist - Risk & Resilience
Cyber Risk Specialist - Risk & Resilience

McKinsey & Company • Washington

On-site
USD 173,000 - 211,000
Cyber Risk Specialist - Risk & Resilience
Cyber Risk Specialist - Risk & Resilience

McKinsey & Company • New York (NY)

On-site
USD 173,000 - 211,000
Software Delivery Specialist - Department of Defense
Software Delivery Specialist - Department of Defense

McKinsey & Company • Washington

On-site
USD 140,000 - 145,000
Specialist - Defense and Security
Specialist - Defense and Security

McKinsey & Company • Dallas (TX)

On-site
USD 192,000
Comprehensive benefits package
Medical, dental, and vision coverage
Generous retirement contributions
+1