Senior Security Analyst (MDR)
New
J
JobgetherCybersecurity
Based in United StatesFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 4+ years of hands-on security operations experience
- Required Skills
- AWSGCPAzure
Requirements
- Have 4+ years of hands-on security operations experience in a SOC, MSSP, or MDR environment.
- Bring experience independently owning investigation outcomes and security decisions, ideally at a senior or Tier 3 level.
- Investigate threats across identity platforms such as Okta and Entra ID.
- Have experience with AWS, Azure, and GCP cloud environments, endpoint detection and response systems, and SaaS platforms such as Microsoft 365 and Google Workspace.
- Understand attacker tactics, techniques, and procedures, and apply the MITRE ATT&CK framework to security telemetry and investigations.
- Use an evidence-driven approach to distinguish suspicious activity from confirmed threats.
- Have hands-on experience with AI-assisted security investigation or automation and understand the need for human oversight.
- Communicate effectively with customers and guide stakeholders through active security incidents.
- Write clear, accurate, customer-ready investigation summaries and recommendations.
- Be able to work within defined shifts as analyst coverage expands to a 24/7 operating model.
- Experience in a multi-tenant MDR or MSSP environment is an advantage.
- Experience writing or tuning detection rules using Sigma, YARA-L, SPL, KQL, or similar is highly valued.
Responsibilities
- Own security investigations from initial case pickup through resolution, assessing impact and blast radius, assigning verdicts and severity, and documenting decisions.
- Investigate identity, cloud, endpoint, and SaaS telemetry to reconstruct attacker activity.
- Combine AI-assisted investigation with hands-on log and evidence analysis.
- Recommend and execute containment actions within customer-authorized boundaries, evaluating impact and reversibility.
- Prioritize investigations according to risk and meet response targets for incidents of different severity levels.
- Explain incidents, implications, recommended actions, and final analysis to customers.
- Conduct hypothesis-driven and AI-assisted threat hunts across customer environments.
- Contribute to investigative standards, response workflows, customer reporting, analyst processes, and team tools.
- Feed investigation outcomes and identified attack patterns into detection engineering and product development.
View Full Description & ApplyYou'll be redirected to the employer's site