← Back to job listings
SA
Security Operations Analyst (Mid level)
Saronic · San Diego, United States
About The Role
Join Saronic as a Security Operations Analyst, where you'll be at the forefront of our detection and response operations. In this mid-level role, you'll triage and investigate security alerts across various domains, lead initial incident response, and contribute to post-incident reviews. You'll have the opportunity to shape our SecOps team and grow across security domains.
- Monitor and triage security alerts across various telemetry sources, performing in-depth investigations and root cause analysis.
- Lead initial incident response for mid-tier events, coordinating with Security Engineering and IT during active incidents.
- Conduct targeted threat hunting operations to identify attacker activity not surfaced by automated detections, and contribute to SecOps metrics tracking.
- Strong understanding of network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral movement patterns
- Experience with EDR tooling in an operational context; ability to hunt, triage, and respond using endpoint telemetry
- Ownership mindset: you follow incidents through to closure and flag what needs to be fixed, not just what needs to be documented
- 3+ years of hands-on experience in a Security Operations, detection engineering, or incident response role
- Solid understanding of attacker TTPs mapped to MITRE ATT&CK, and the ability to apply that knowledge during active investigations
- Experience writing or iterating on detection logic, response playbooks, or SOC operational documentation
- Hands-on proficiency with enterprise SIEM platforms and their query languages; ability to write and iterate on detection logic from scratch
- Clear and structured written and verbal communication — you can brief a non-technical stakeholder and write a thorough incident report
- Security Clearance eligible
- Demonstrated experience triaging and investigating alerts across at least two of the following: endpoint, cloud, identity, network, or SaaS environments
- Scripting proficiency in Python, PowerShell, or Bash for alert enrichment, automation, or triage support
- Experience with XDR platforms and cross-domain correlated detection across endpoint, identity, and cloud
- Familiarity with cloud-native security operations and log sources in AWS or Azure environments
- Experience with SOAR platforms or building response automation workflows
- Exposure to supply chain and CI/CD pipeline security monitoring
- Familiarity with data lake-based or pipeline-driven detection architectures
- Experience operating in or supporting classified, GovCloud, or FedRAMP environments
- Background in defense, aerospace, robotics, or other high-assurance operational environments
- Relevant certifications: GIAC GCIH, GCIA, GCFE, BTL1/2, CySA+, OSCP, or equivalent
- Familiarity with compliance frameworks such as NIST SP 800-171, NIST SP 800-53, or CMMC
- Active security clearance or prior clearance history is a strong differentiator
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring