We are looking for a highly analytical, decisive SecOps Analyst to join our SecOps Team. Our SOC runs on an agentic AI platform that autonomously investigates and correlates security alerts across our infrastructure, cloud, and product environments. Your role is to be the critical human judgment layer: validating AI-driven investigations and owning confirmed incidents end-to-end.
If you take full ownership of a problem until it's truly closed, think critically rather than trusting a tool blindly, and want to operate at the frontier of AI-driven security operations, this role is for you.
Responsibilities- AI Investigation Validation: Review and validate findings from our agentic AI SOC platform. Catch false positives/negatives and surface edge cases internally to improve agent accuracy.
- End-to-End Incident Ownership: Own confirmed incidents from escalation through containment, remediation, and reporting, driving cases to closure, not just triage.
- Application & Product Log Monitoring: Investigate anomalies across our application and product logs to detect abuse, tenant/account misuse, and threats unique to our platform.
- Human-in-the-Loop Decision Authority: Authorize containment actions (isolating a host, suspending an identity, revoking a session) on critical alerts with confidence and speed.
- Proactive Threat Hunting: Hunt for threats outside the current scope, including business-logic abuse, insider threats, and anomalies unique to our product.
- Phishing & User Defense: Own confirmed phishing cases end-to-end, from detection through user communication and takedown.
- Documentation: Maintain clear investigation runbooks and case documentation so knowledge is shared, not siloed.
- On-Call Rotation: Serve as the decision-maker for high-severity, AI-escalated incidents during off-hours — reserved for high-confidence critical escalations, not noise.
- 2+ years of hands-on experience in a SOC, Incident Response, or Threat Intelligence role.
- Strong experience querying and analyzing logs in Splunk (must).
- Deep understanding of common attack vectors, MITRE ATT&CK, and enterprise security tools (EDR, IdP, SASE/Firewalls).
- Demonstrated critical thinking: comfortable questioning AI/automated conclusions rather than accepting them at face value.
- Strong incident command instincts: fast, confident decisions under pressure with incomplete information.
- Excellent written and verbal English communication for documentation and cross-functional incident communication.
Advantage
- Experience querying application/observability logs in Logz.io or ELK stack.
- Experience with AI-driven or agentic security tools.
- Experience in a SOAR-driven environment.
- Familiarity with investigating cloud-native threats.
- Relevant certifications (e.g., GCIA, GCIH, CySA+).
Skills Required
- 2+ years of hands-on experience in a SOC, Incident Response, or Threat Intelligence role
- Strong experience querying and analyzing logs in Splunk
- Understanding of common attack vectors and MITRE ATT&CK
- Experience with enterprise security tools, including EDR, IdP, and SASE/firewalls
- Critical thinking and ability to question AI or automated conclusions
- Strong incident command instincts and ability to make decisions under pressure
- Excellent written and verbal English communication skills
- Experience querying application or observability logs in Logz.io or ELK Stack
- Experience with AI-driven or agentic security tools
- Experience in a SOAR-driven environment
- Familiarity with investigating cloud-native threats
- Relevant certifications such as GCIA, GCIH, or CySA+
What We Do
Bright Data is the world’s #1 web data platform, supporting the public data needs of over 20,000 organizations in nearly every industry. Our solutions are leveraged to fuel AI as well as research, monitor, and analyze web data for smarter decisions. Bright Data offers a complete web data platform, from award-winning proxy networks and AI-powered web scraping tools, to dynamically refreshed datasets, an unparalleled retail and e-commerce data intelligence suite, and fully managed data services. Making public web data accessible is essential to keeping markets openly competitive and providing different data types to power LLMs. As an industry leader, we are committed to defending public web data. Bright Data has proven that ethical and transparent scraping practices for legitimate business use and social good initiatives are legally sound. We are very proud to lead innovation in web data, with +5,500 granted patent claims.







