Senior Security Operations Analyst (Detection & Response)

New
P
PointFintech
Work from anywhere in the U.S.Full-TimeSenior
SalaryTier 1 | San Francisco Bay Area, New York, and Seattle | $151,050 - $166,950; Tier 2 | Austin, Boston, Chicago, Denver, Los Angeles, Miami, Philadelphia, Portland, Sacramento, San Diego, Santa Barbara & Washington DC | $127,300 - $140,700; Tier 3 | All other US metro areas | $117,800 - $130,200
Apply NowOpens the employer's application page

Job Details

Experience
5+ years
Required Skills
AWSPythonGoogle Workspace

Requirements

  • 5+ years of experience in security operations, incident response, SOC, or detection engineering.
  • Hands-on experience running or actively participating in an on-call / incident-response rotation, independently.
  • Strong SIEM skills, including authoring and tuning detections, correlation rules, and dashboards (e.g., Coralogix, Splunk, Elastic, Microsoft Sentinel).
  • Practical cloud security experience in AWS and Google Workspace, including identity and log sources.
  • Demonstrated ability to investigate and contain incidents end to end, such as phishing/AiTM, account takeover, BEC, and cloud/identity threats.
  • Working knowledge of vulnerability management and coordinating remediation with engineering teams.
  • Scripting and automation ability (e.g., Python) for detection-as-code and SOAR-style workflows.
  • Clear written and verbal communication skills for producing runbooks, metrics, and audit-ready documentation.
  • Comfortable operating with autonomy on a small team and owning problems end to end.
  • Able to participate in an off-hours on-call rotation.

Responsibilities

  • Rotate on-call and lead response: share the 24/7 on-call and incident-response rotation with the security lead — triaging, investigating, and driving containment of security alerts and incidents.
  • Own response documentation: build and maintain incident-response runbooks, escalation paths, and post-incident reviews so response is consistent and repeatable.
  • Engineer detections: build, tune, and maintain SIEM detections, correlation rules, dashboards, and reporting in Coralogix across cloud and identity log sources.
  • Close coverage gaps: reduce false positives and onboard new log sources to eliminate detection blind spots.
  • Own vulnerability management: run day-to-day vulnerability management — prioritize findings, coordinate remediation with system owners, and report on risk reduction across cloud and endpoints.
  • Automate response: develop detection-as-code and lightweight automation/SOAR so common alerts self-triage and response is faster and repeatable.
  • Add operational redundancy: serve as a redundant administrative and response path so containment is never bottlenecked on a single person.
  • Report and evidence: produce recurring security metrics and reporting for leadership, and supply control evidence for audits.
  • Apply AI to the workflow: use AI/LLM tooling to accelerate investigation, correlation, and detection engineering.
  • Improve the program: contribute to continuous improvement of the security-operations program, tooling, and threat monitoring.
View Full Description & ApplyYou'll be redirected to the employer's site
Tier 1 | San Francisco Bay Area, New York, and Seattle | $151,050 - $166,950; Tier 2 | Austin, Boston, Chicago, Denver, Los Angeles, Miami, Philadelphia, Portland, Sacramento, San Diego, Santa Barbara & Washington DC | $127,300 - $140,700; Tier 3 | All other US metro areas | $117,800 - $130,200
Apply Now