Senior Security Operations Analyst

Saronic Technologies

$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years of experience in Security Operations, detection engineering, or incident response roles
  • Experience triaging alerts across two or more security domains: endpoint, cloud, identity, or network
  • Proficient with enterprise SIEM platforms and their query languages for detection logic
  • Operational experience with EDR tools for alert response and telemetry analysis
  • Strong knowledge of MITRE ATT&CK to effectively apply during investigations
  • Ability to develop detection logic and write SOP documentation
  • Scripting skills in Python, PowerShell, or Bash for automation and alert enrichment
  • Fundamental understanding of TCP/IP, DNS, HTTP/S, and network logs
  • Strong communications skills for reporting to technical and non-technical stakeholders
  • Ownership mindset with a focus on incident resolution and process improvement

Responsibilities

  • Monitor and triage security alerts across multiple telemetry platforms using SIEM and XDR
  • Conduct detailed investigation and root cause analysis on security events, documenting findings
  • Tune detection systems to minimize false positives and enhance signal clarity
  • Lead initial response to mid-tier incidents, coordinating containment and recovery actions
  • Participate in on-call rotation, providing timely updates to stakeholders
  • Perform post-incident reviews to identify gaps and implement improvements
  • Support creation of playbooks and workflows, aiding team efficiency
  • Engage in proactive threat hunting to uncover hidden attacker activity

Benefits

  • Comprehensive medical insurance with 100% coverage for employees
  • 100% paid dental and vision insurance for employees
  • Generous paid time off (PTO) and holidays
  • Paid parental leave for new mothers and fathers
  • 401(k) retirement plan with company matching contributions
  • Stock options offering equity in company performance
  • Life and disability insurance coverage
  • Discounted pet insurance options and Telehealth services
  • Free lunch and unlimited beverages and snacks in the office
Full Job Description
Job Overview

As a Senior SecOps Analyst at Saronic, you'll be on the front line of our detection and response operations, triaging and investigating security alerts across endpoint, cloud, identity, network, and SaaS telemetry using our SIEM and XDR platforms. You'll run root cause analysis on real events, lead initial response for mid-tier incidents (contain, eradicate, recover), and tune detections to cut down on noise and sharpen what actually matters. Beyond the day-to-day, you'll join the on-call rotation, run targeted threat hunts to catch what automation misses, help build out our playbooks and runbooks, and contribute to post-incident reviews that turn gaps into real improvements. This is an early, formative role on a SecOps team being built from the ground up, so you'll have a direct hand in shaping how we operate, with room to grow across security domains rather than being boxed into one lane.

Responsibilities

Detection & Alert Operations
  • Monitor and triage security alerts across endpoint, cloud, identity, network, and SaaS telemetry using enterprise SIEM and XDR platforms
  • Perform in-depth alert investigation and root cause analysis, documenting findings with clear, structured timelines and impact assessments
  • Tune detections to reduce false positive noise and improve signal fidelity; contribute to detection-as-code pipelines using structured query languages
  • Operate across multiple detection and visibility platforms as part of a maturing, layered security monitoring ecosystem


Incident Response & Investigation
  • Lead initial incident response for mid-tier events: contain, eradicate, and recover across endpoint, cloud, and identity domains
  • Participate in the on-call incident rotation and effectively communicate status and findings to the SecOps Lead and relevant stakeholders
  • Conduct post-incident reviews, identifying gaps in detection, response, and containment and translating them into actionable improvements
  • Coordinate with Security Engineering and IT during active incidents to accelerate response and reduce dwell time


SecOps Foundation & Enablement
  • Support the SecOps Lead in developing and refining response playbooks, runbooks, and analyst workflow documentation
  • Conduct targeted threat hunting operations to identify attacker activity not surfaced by automated detections
  • Contribute to SecOps metrics tracking, reporting, and operational readiness reviews
  • Help onboard and mentor junior analysts as the team grows, serving as a technical resource and process guide


Qualifications
  • 3+ years of hands-on experience in a Security Operations, detection engineering, or incident response role
  • Demonstrated experience triaging and investigating alerts across at least two of the following: endpoint, cloud, identity, network, or SaaS environments
  • Hands-on proficiency with enterprise SIEM platforms and their query languages; ability to write and iterate on detection logic from scratch
  • Experience with EDR tooling in an operational context; ability to hunt, triage, and respond using endpoint telemetry
  • Solid understanding of attacker TTPs mapped to MITRE ATT&CK, and the ability to apply that knowledge during active investigations
  • Experience writing or iterating on detection logic, response playbooks, or SOC operational documentation
  • Scripting proficiency in Python, PowerShell, or Bash for alert enrichment, automation, or triage support
  • Strong understanding of network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral movement patterns
  • Clear and structured written and verbal communication - you can brief a non-technical stakeholder and write a thorough incident report
  • Ownership mindset: you follow incidents through to closure and flag what needs to be fixed, not just what needs to be documented
  • Security Clearance eligible


Preferred Qualifications
  • Experience with XDR platforms and cross-domain correlated detection across endpoint, identity, and cloud
  • Familiarity with cloud-native security operations and log sources in AWS or Azure environments
  • Experience with SOAR platforms or building response automation workflows
  • Exposure to supply chain and CI/CD pipeline security monitoring
  • Familiarity with data lake-based or pipeline-driven detection architectures
  • Experience operating in or supporting classified, GovCloud, or FedRAMP environments
  • Background in defense, aerospace, robotics, or other high-assurance operational environments
  • Familiarity with compliance frameworks such as NIST SP 800-171, NIST SP 800-53, or CMMC
  • Relevant certifications: GIAC GCIH, GCIA, GCFE, BTL1/2, CySA+, OSCP, or equivalent
  • Active security clearance or prior clearance history is a strong differentiator


Physical Demands
  • Prolonged periods of sitting at a desk and working on a computer
  • Occasional standing and walking within the office
  • Manual dexterity to operate a computer keyboard, mouse, and other office equipment
  • Visual acuity to read screens, documents, and reports
  • Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies
  • Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages)


Benefits

Medical Insurance: Comprehensive health insurance plans covering a range of services

Saronic pays 100% of the premium for employees and 80% for dependents

Dental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision care

Saronic pays 100% of the premium under the basic plan for employees and 80% for dependents

Time Off: Generous PTO and Holidays

Parental Leave: Paid maternity and paternity leave to support new parents

Competitive Salary: Industry-standard salaries with opportunities for performance-based bonuses

Retirement Plan: 401(k) plan with company match

Stock Options: Equity options to give employees a stake in the company's success

Life and Disability Insurance: Basic life insurance and short- and long-term disability coverage

Pet Insurance: Discounted pet insurance options including 24/7 Telehealth helpline

Additional Perks: Free lunch benefit and unlimited free drinks and snacks in the office

Similar Jobs

More Jobs at Saronic Technologies

More Information Technology Jobs

Find similar Senior Security Operations Analyst jobs: