Senior Security Analyst (MDR)

New
J
JobgetherCybersecurity
Based in United StatesFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
4+ years of hands-on security operations experience
Required Skills
AWSGCPAzure

Requirements

  • Have 4+ years of hands-on security operations experience in a SOC, MSSP, or MDR environment.
  • Bring experience independently owning investigation outcomes and security decisions, ideally at a senior or Tier 3 level.
  • Investigate threats across identity platforms such as Okta and Entra ID.
  • Have experience with AWS, Azure, and GCP cloud environments, endpoint detection and response systems, and SaaS platforms such as Microsoft 365 and Google Workspace.
  • Understand attacker tactics, techniques, and procedures, and apply the MITRE ATT&CK framework to security telemetry and investigations.
  • Use an evidence-driven approach to distinguish suspicious activity from confirmed threats.
  • Have hands-on experience with AI-assisted security investigation or automation and understand the need for human oversight.
  • Communicate effectively with customers and guide stakeholders through active security incidents.
  • Write clear, accurate, customer-ready investigation summaries and recommendations.
  • Be able to work within defined shifts as analyst coverage expands to a 24/7 operating model.
  • Experience in a multi-tenant MDR or MSSP environment is an advantage.
  • Experience writing or tuning detection rules using Sigma, YARA-L, SPL, KQL, or similar is highly valued.

Responsibilities

  • Own security investigations from initial case pickup through resolution, assessing impact and blast radius, assigning verdicts and severity, and documenting decisions.
  • Investigate identity, cloud, endpoint, and SaaS telemetry to reconstruct attacker activity.
  • Combine AI-assisted investigation with hands-on log and evidence analysis.
  • Recommend and execute containment actions within customer-authorized boundaries, evaluating impact and reversibility.
  • Prioritize investigations according to risk and meet response targets for incidents of different severity levels.
  • Explain incidents, implications, recommended actions, and final analysis to customers.
  • Conduct hypothesis-driven and AI-assisted threat hunts across customer environments.
  • Contribute to investigative standards, response workflows, customer reporting, analyst processes, and team tools.
  • Feed investigation outcomes and identified attack patterns into detection engineering and product development.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now