Sr IT Security Operations Analyst

Blackstone Technology Group

Oakland (CA)

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Blackstone Talent Group seeks an experienced IT Security Operations Analyst to support complex, systemwide services from a client site in Oakland, CA. You will lead threat analyses, handle escalations, and improve detection content while coordinating with stakeholders.

The role requires 8+ years in security operations, hands-on SIEM expertise (CrowdStrike NG-SIEM preferred), and strong AWS security experience. Remote-to-site setup supported; strong communication and mentoring abilities essential.

Qualifications

  • 8+ years in IT security operations or incident response roles.
  • Experience with deep forensic analysis and complex investigations.
  • Hands-on with modern SIEM platforms and content development.
  • Strong AWS security experience including WAF, RDS, and logs pipelines.
  • Proven ability to communicate risk to technical and non-technical stakeholders.

Responsibilities

  • Lead threat analysis across multiple sources and translate findings into detections.
  • Act as tier-2/3 escalation for incidents including containment and recovery.
  • Tune and mature detection content in SIEM; reduce false positives.
  • Perform large-scale log analysis across AWS, network, and enterprise systems.
  • Mentor junior analysts and contribute to playbooks and runbooks.

Skills

Threat analysis
Incident response
CrowdStrike NG-SIEM
AWS security
Scripting (Python/PowerShell)
Communication skills
Forensic analysis
Analytical thinking

Education

Bachelor's degree in CS/IT/CIS

Tools

CrowdStrike NG-SIEM
S3/Athena
Pathlock/SSO/SoD
Entrust

Job description

Blackstone Talent Group, an award-winning technology consulting and talent agency is seeking a IT Security Operations Analyst - remote to join our team at our client’s site in Oakland, CA.

Position SummarySenior-level security operations resource supporting multiple complex, systemwide business services.

Duties
  • Lead deep-dive threat analysis across IP, telephony, email, web, and software-package threat intelligence sources (Google Threat Intelligence, Twilio, VirusTotal, and others), turning intelligence into actionable detections and response.
  • Serve as tier-2/tier-3 escalation for security incident detection, response, containment, resolution, and recovery — including forensic analysis, security event analysis, data collection, packet analysis, and ticket management.
  • Validate, tune, and mature detection content in CrowdStrike NG-SIEM (currently being implemented); confirm coverage, reduce false positives, and close visibility gaps.
  • Perform large-scale log analysis and correlation using S3, Athena, and related tooling across AWS (WAF, RDS, security groups), F5, network logs, PeopleSoft HCM, Pathlock (SSO, A360, SoD), Entrust, and other enterprise systems.
  • Administer and maintain one or more security services (SIEM, vulnerability management, threat detection, phishing, DLP), including patching, configuration changes, troubleshooting, and customer requests.
  • Prioritize and drive resolution of security issues with material financial or regulatory impact, including SOX-relevant systems and controls.
  • Analyze, report, and remediate findings from vulnerability scans and penetration tests; track risk acceptance and remediation to closure.
  • Create and maintain thorough technical security documentation for IT systems, architecture, and environments.
  • Mentor junior analysts, contribute to runbook and playbook development, and advise IT and business stakeholders on risk.
Required Skills / Experience
  • 8+ years on an IT security operations / incident response team in a senior analyst, engineer, or systems administrator capacity, including demonstrated ownership of complex investigations without supervision.
  • Deep forensic and incident response analysis of complex business systems.
  • Hands-on experience with modern SIEM platforms — implementation, tuning, detection engineering, and content development. CrowdStrike NG-SIEM or equivalent next-gen platform strongly preferred.
  • Substantial AWS security experience: WAF, security groups, RDS, CloudTrail/log pipelines, S3 and Athena for large-scale log analysis.
  • Applied threat intelligence experience across multiple source types (IP, email, telephony, domain/file reputation) and the ability to operationalize it.
  • Knowledge of security best practices across Linux, Windows, macOS, VMware, and Cisco IOS — including OS security tooling, configuration, logging, and patching.
  • Working knowledge of public-key cryptography and best practices for protecting data at rest and in transit.
  • Strong scripting ability (Python, PowerShell, Bash, or equivalent) for automation and data analysis.
  • Strong verbal and written communication, including the ability to convey security risk to both technical administrators and non-technical executive stakeholders.
  • Excellent analytical, design, and organizational skills; demonstrated ability to manage multiple concurrent assignments in a fast-paced environment.
Preferred Skills / Experience
  • Background or formal education in data science; demonstrated use of statistical or data-driven methods in threat hunting and anomaly detection.
  • Experience using AI/LLM tooling as an engineering aid for log analysis, correlation, and investigation acceleration.
  • Experience supporting ERP/HCM environments (PeopleSoft HCM) and access governance tooling (Pathlock, SoD, SSO).
  • Working knowledge of security audit processes, SOX controls, and related expectations.
  • Bachelor's degree in CS, IT, CIS, or a related field.
  • Professional certifications (CISSP, GCIA, GCIH, GCFA, Security+, CCNA) will weigh in the candidate's favor.

Blackstone Talent Group is a division of Blackstone Technology Group, a global IT services and solutions firm that implements technological solutions across commercial industry verticals and the US Federal Government. Blackstone’s global talent augmentation practice was founded in 1998. Blackstone Talent Group has offices in San Francisco, Denver, Houston, Colorado Springs, and Washington, DC. We specialize in providing clients the best talent across a variety of industries and sectors.

EOE of Minorities/Females/Veterans/Disabilities

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior IT Security Ops Analyst Threat & SIEM Expert
Senior IT Security Ops Analyst Threat & SIEM Expert

Blackstone Technology Group • Oakland (CA)

On-site
USD 120,000 - 180,000
IT Security Operations Analyst
IT Security Operations Analyst

Blackstone Talent Group • San Francisco (CA)

On-site
USD 120,000 - 150,000
Senior Threat & Incident Response Security Ops
Senior Threat & Incident Response Security Ops

Blackstone Talent Group • San Francisco (CA)

On-site
USD 120,000 - 150,000
Cyber Security Analyst
Cyber Security Analyst

Clinisoltech • Huntsville (AL)

Hybrid
USD 80,000 - 90,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Alert, Detection, and Response Engineer, Associate
Alert, Detection, and Response Engineer, Associate

Cybersecurity Jobs • Miami (FL)

On-site
USD 110,000 - 170,000
Comprehensive health benefits
Paid time off
Life insurance
+3
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Senior Information Security Analyst (SecOps)
Senior Information Security Analyst (SecOps)

DLA Piper LLP (US) • Baltimore (MD)

On-site
USD 90,000 - 120,000
Cyber Security Analyst
Cyber Security Analyst

blueStone • San Francisco (CA)

On-site
USD 80,000 - 120,000
Analyst, Cyber Security II
Analyst, Cyber Security II

TALENT Software Services • Columbia (SC)

On-site
USD 90,000 - 140,000