Senior Security Operations Analyst
Saronic Technologies - Austin, TX
Hiring: Senior Security Operations Analyst Company: Saronic Technologies Location: Austin, TX Job Posted Time: 2026-09-13 13:21:00 Target Skills & Keywords : AWS, Azure, Bash, CI/CD, DNS, Data Lake, PowerShell, Python, SIEM, SOC, SaaS, Security Clearance, TCP/IP About the job Experience: •6+ years of hands-on Security Operations, detection engineering, or incident response experience, or an equivalent combination of experience and demonstrated ability Required Skills: •Operate across endpoint, cloud, identity, network, and SaaS telemetry in our SIEM and XDR to tune and refine detections in-flight, and be the primary front-line voice driving detection improvements back to Detection Engineering •Lead root-cause analysis on complex, novel, or cross-domain events, and structure investigations others can follow •Own coverage from the operator's seat and map what you're seeing to MITRE ATT&CK, identify gaps, and set the priorities Detection Engineering builds against •Lead incident response end-to-end for complex and higher-severity incidents across endpoint, cloud, and identity to contain, eradicate, recover •Serve as a trusted escalation point on the on-call rotation, and brief status and impact to security leadership and stakeholders •Own post-incident reviews, translating detection, response, and containment gaps into prioritized, durable improvements •Coordinate cross-team with Security Engineering and IT during active incidents to reduce dwell time •Define and mature the response playbooks, runbooks, and analyst workflows the team runs on Qualifications: •Track record leading complex or ambiguous investigations and incidents end-to-end across at least two of: endpoint, cloud, identity, network, or SaaS •Deep hands-on proficiency with enterprise SIEM/XDR query languages for investigation and hunting; able to tune detections and translate front-line findings into detection requirements •Operational EDR expertise to lead hunts, triage, and response using endpoint telemetry •Strong command of attacker TTPs mapped to MITRE ATT&CK, applied during live investigations •Scripting proficiency in Python, PowerShell, or Bash for enrichment, automation, and triage •Strong network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral-movement patterns •Clear, structured communication skills and can brief non-technical stakeholders and be the calm, trusted voice during an incident •Ownership mindset: drives incidents to closure and makes durable, risk-based tradeoff decisions •Demonstrated capacity to obtain and maintain a U.S. security clearance •Operational familiarity with cloud-native security operations and log sources in AWS or Azure Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!