Senior Security Operations Analyst (Detection & Response)
New
P
PointFintech
Work from anywhere in the U.S.Full-TimeSenior
SalaryTier 1 | San Francisco Bay Area, New York, and Seattle | $151,050 - $166,950; Tier 2 | Austin, Boston, Chicago, Denver, Los Angeles, Miami, Philadelphia, Portland, Sacramento, San Diego, Santa Barbara & Washington DC | $127,300 - $140,700; Tier 3 | All other US metro areas | $117,800 - $130,200
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years
- Required Skills
- AWSPythonGoogle Workspace
Requirements
- 5+ years of experience in security operations, incident response, SOC, or detection engineering.
- Hands-on experience running or actively participating in an on-call / incident-response rotation, independently.
- Strong SIEM skills, including authoring and tuning detections, correlation rules, and dashboards (e.g., Coralogix, Splunk, Elastic, Microsoft Sentinel).
- Practical cloud security experience in AWS and Google Workspace, including identity and log sources.
- Demonstrated ability to investigate and contain incidents end to end, such as phishing/AiTM, account takeover, BEC, and cloud/identity threats.
- Working knowledge of vulnerability management and coordinating remediation with engineering teams.
- Scripting and automation ability (e.g., Python) for detection-as-code and SOAR-style workflows.
- Clear written and verbal communication skills for producing runbooks, metrics, and audit-ready documentation.
- Comfortable operating with autonomy on a small team and owning problems end to end.
- Able to participate in an off-hours on-call rotation.
Responsibilities
- Rotate on-call and lead response: share the 24/7 on-call and incident-response rotation with the security lead — triaging, investigating, and driving containment of security alerts and incidents.
- Own response documentation: build and maintain incident-response runbooks, escalation paths, and post-incident reviews so response is consistent and repeatable.
- Engineer detections: build, tune, and maintain SIEM detections, correlation rules, dashboards, and reporting in Coralogix across cloud and identity log sources.
- Close coverage gaps: reduce false positives and onboard new log sources to eliminate detection blind spots.
- Own vulnerability management: run day-to-day vulnerability management — prioritize findings, coordinate remediation with system owners, and report on risk reduction across cloud and endpoints.
- Automate response: develop detection-as-code and lightweight automation/SOAR so common alerts self-triage and response is faster and repeatable.
- Add operational redundancy: serve as a redundant administrative and response path so containment is never bottlenecked on a single person.
- Report and evidence: produce recurring security metrics and reporting for leadership, and supply control evidence for audits.
- Apply AI to the workflow: use AI/LLM tooling to accelerate investigation, correlation, and detection engineering.
- Improve the program: contribute to continuous improvement of the security-operations program, tooling, and threat monitoring.
View Full Description & ApplyYou'll be redirected to the employer's site