Sr. Analyst - Security Operations

Solomon Page

Village of Great Neck (NY)

On-site

USD 120,000 - 140,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Solomon Page is seeking an experienced Senior Analyst – Security Operations to join their security team in a hands-on role focused on monitoring, incident response, vulnerability management, threat detection, and purple team activities. You will work with IT and engineering teams to investigate complex incidents and improve security controls across cloud, on‑prem, and SaaS environments.

The ideal candidate has 5+ years in SOC/IR, deep SIEM/EDR experience, and strong scripting and report-writing

Qualifications

  • 5+ years hands-on experience in a SOC, security operations, or incident response role.
  • Proficiency with SIEM platforms such as Splunk, Microsoft Sentinel, or Sumo Logic.
  • Hands-on experience with EDR solutions such as CrowdStrike Falcon or Microsoft Defender.
  • Hands-on experience configuring conditional access policies in Entra or another identity platform.
  • Hands-on experience configuring DLP policies in Microsoft Purview or another platform.
  • Demonstrated experience triaging and responding to a significant volume of security alerts and incidents.
  • Working knowledge of vulnerability management tools and processes, including scanning, prioritization, and remediation tracking.
  • Familiar with MITRE ATT&CK framework and applying it to investigations and detection engineering.
  • Scripting for investigation and automation tasks using Python, PowerShell, or Bash.
  • Strong analytical and problem-solving skills with excellent attention to detail.
  • Excellent written and verbal communication skills, with the ability to convey technical findings clearly to varied audiences.

Responsibilities

  • Security Monitoring & Incident Response: monitor, triage, and investigate alerts across SIEM/EDR/NDR and cloud platforms.
  • Respond to incidents end-to-end, including containment, eradication, recovery, and post-incident docs.
  • Maintain incident response playbooks and runbooks; identify gaps and improvements.
  • Root cause analysis after incidents; contribute findings to post-incident reviews.
  • Produce incident reports for technical and non-technical audiences.
  • Participate in on-call rotation for high-severity incidents.

Skills

SOC operations
Incident response
Threat detection
Purple teaming
Scripting: Python
Scripting: PowerShell
Scripting: Bash
Communication
Threat intelligence

Education

CISSP – Certified Information Systems Security Professional
GIAC GCIH – GIAC Certified Incident Handler
GIAC GCIA – Intrusion Analyst
CEH – Certified Ethical Hacker
CompTIA CySA+ or Security+
OSCP, GPEN, or similar
Cloud security certifications (SC-200, AWS Security Specialty)

Tools

Splunk
Microsoft Sentinel
Sumo Logic
CrowdStrike Falcon
Microsoft Defender
Entra
Purview
Tenable
Qualys
Rapid7

Job description

Our client is seeking an experienced Senior Analyst – Security Operations to join their security team. This role will focus on security monitoring, incident response, vulnerability management, threat detection, and purple team activities. The ideal candidate will have strong hands-on experience across modern security tools and be comfortable investigating complex incidents while collaborating with IT and engineering teams.

  • Salary: $120K–$140K
Responsibilities:
  • Security Monitoring & Incident Response
  • Monitor, triage, and investigate security alerts across SIEM, EDR, NDR, and cloud platforms, escalating to the SOC Lead as appropriate.
  • Respond to security incidents end-to-end, including initial triage, containment, eradication, recovery, and post-incident documentation.
  • Execute and help maintain incident response playbooks and runbooks, identifying gaps and recommending improvements.
  • Conduct root cause analysis following incidents and contribute findings to post-incident reviews.
  • Produce clear, accurate incident reports for both technical and non-technical audiences.
  • Participate in an on-call rotation and respond to high-severity incidents outside of business hours when required.
Vulnerability Management
  • Perform vulnerability scans and assessments using tools such as Tenable, Qualys, or Rapid7 on both scheduled and ad-hoc bases.
  • Analyze and prioritize vulnerabilities using CVSS scores, threat intelligence, and asset criticality to guide remediation efforts.
  • Track and follow up on remediation progress with IT and engineering teams, escalating stalled items as needed.
  • Contribute to vulnerability reporting, including trends, patch compliance rates, and risk reduction metrics.
  • Stay current on newly disclosed CVEs and exploit trends and advise on risk-based prioritization.
Purple Teaming & Threat Detection
  • Participate in purple team exercises alongside red team operators to validate detection and response capabilities.
  • Map adversary techniques to the MITRE ATT&CK framework and use exercise findings to identify detection gaps.
  • Write and tune SIEM detection rules, correlation queries, and alerts based on adversary TTPs and purple team outcomes.
  • Conduct threat hunting exercises using hypothesis-driven and ATT&CK-aligned methodologies to identify undetected threats.
  • Track emerging threat actor activity and incorporate relevant TTPs into detection logic and hunting campaigns.
Security Operations & Collaboration
  • Analyze logs from endpoints, firewalls, proxies, cloud platforms, and identity systems.
  • Enrich investigations with threat intelligence, including IOCs, and correlate activity across multiple data sources.
  • Collaborate with IT and engineering teams to tune security controls, reduce false positives, and improve signal quality.
  • Maintain accurate SOC documentation, including runbooks, knowledge base articles, and escalation procedures.
  • Support compliance activities such as SOC 2, ISO 27001, and NIST CSF by providing evidence and participating in audits as required.
  • Mentor junior analysts by sharing knowledge and providing guidance on investigations and tool usage, without formal management responsibility.
Required Qualifications:
  • 5+ years of hands-on experience in a SOC, security operations, or incident response role.
  • Strong proficiency with SIEM platforms such as Splunk, Microsoft Sentinel, or Sumo Logic.
  • Hands-on experience with EDR solutions such as CrowdStrike Falcon or Microsoft Defender.
  • Hands-on experience configuring conditional access policies in Entra or another identity platform.
  • Hands-on experience configuring DLP policies in Microsoft Purview or another platform.
  • Demonstrated experience triaging and responding to a significant volume of security alerts and incidents.
  • Working knowledge of vulnerability management tools and processes, including scanning, prioritization, and remediation tracking.
  • Solid understanding of network protocols and fundamentals, including TCP/IP, DNS, HTTP/S, firewalls, and proxies.
  • Experience analyzing logs across endpoints, networks, cloud environments, and SaaS platforms.
  • Familiarity with the MITRE ATT&CK framework and applying it to investigations and detection engineering.
  • Scripting experience for investigation and automation tasks using Python, PowerShell, or Bash.
  • Strong analytical and problem-solving skills with excellent attention to detail.
  • Excellent written and verbal communication skills, with the ability to convey technical findings clearly to varied audiences.
Preferred Qualifications:
  • Experience participating in purple team, red team, or adversary emulation exercises.
  • Background in threat hunting using hypothesis-driven or behavior-based methodologies.
  • Exposure to SOAR platforms and security automation or workflow development.
  • Experience with cloud security telemetry and threat models across AWS, Azure, or GCP.
  • Familiarity with threat intelligence platforms or workflows such as MISP, Recorded Future, or OpenCTI.
  • Knowledge of digital forensics tools and techniques, including KAPE, Volatility, or Velociraptor.
Certifications
  • Required: CISSP – Certified Information Systems Security Professional
  • Preferred: GIAC GCIH – GIAC Certified Incident Handler
  • Preferred: GIAC GCIA – Intrusion Analyst
  • Preferred: CEH – Certified Ethical Hacker
  • Preferred: CompTIA CySA+ or Security+
  • Preferred: OSCP, GPEN, or similar offensive/detection-focused certification
  • Preferred: Cloud security certifications such as Microsoft SC-200, AWS Security Specialty, or equivalent

Opportunity Awaits.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Network Security Analyst
Network Security Analyst

Allied Consultants, Inc. • Austin (TX)

On-site
USD 90,000 - 130,000
Medical insurance
Life insurance
401(K) plan with company match
+2
Sr SOC Analyst
Sr SOC Analyst

Jobgether • United States

On-site
USD 120,000 - 150,000
Professional growth
AI-driven tools
Collaborative team
+1
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Security Operations Analyst
Security Operations Analyst

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Health benefits
401(k) and profit-sharing
Paid holidays
+1
Sr Information Security Analyst
Sr Information Security Analyst

Scorpion Therapeutics • Michigan

Hybrid
USD 120,000 - 180,000
Hybrid work two days from home
Career development opportunities
Security Operations Analyst
Security Operations Analyst

Mondo • Needham (MA)

Hybrid
USD 83,000 - 96,000
Health insurance
Dental insurance
Vision insurance
+1