The Role
Leads security operations through detection engineering, SIEM and EDR monitoring, threat hunting, incident investigation, containment, and high-severity incident command. Tunes detection rules, investigates phishing and business email compromise, develops automated playbooks, documents cases, and tracks SOC metrics. The role supports continuous improvement, cross-functional coordination, and 24/7 SOC operations while applying threat intelligence and MITRE ATT&CK techniques.
Summary Generated by Built In
Role Overview
We are seeking a highly technical and proactive Sr. Security Operations Analyst to join our Information Security team. In this role you will engineer and mature our security operations infrastructure — designing automated playbooks, tuning advanced telemetry across SIEM, EDR, and cloud environments, and leading high-severity incident containment. As a senior member of the team, you will define triage standards and elevate the technical capability of the wider SOC.
Responsibilities
- Detection engineering: Architect and optimize real-time detection engineering playbooks across SIEM, EDR, and cloud security platforms to minimize false positives, accelerate triage, and scale threat-hunting capability.
- Investigation: Investigate suspicious activity, correlate findings across data sources, and document clear, timely case notes for each alert or incident.
- Incident command: Lead the response lifecycle for high-severity incidents as primary investigator or incident commander, ensuring seamless coordination and technical handoff across cross-functional teams.
- Containment: Execute containment actions under established playbooks, including endpoint isolation, disabling compromised accounts, and blocking malicious indicators.
- Threat hunting: Research indicators of compromise and apply threat intelligence to identify anomalous behavior.
- Rule tuning: Tune detection rules and use cases to reduce false positives and close visibility gaps, in coordination with engineering.
- Email threats: Investigate and remediate email-based threats such as phishing and business email compromise, from both user submissions and automated detection.
- Continuous improvement: Contribute to post-incident reviews and metrics reporting — MTTD, MTTR, alert volume, and false-positive rate — to support ongoing SOC maturity.
- Currency: Stay current on emerging threats, attacker TTPs, and industry frameworks such as MITRE ATT&CK.
Requirements
- SIEM platforms
- Splunk
- Microsoft Sentinel
- QRadar
- EDR platforms
- CrowdStrike
- Microsoft Defender for Endpoint
- SentinelOne
- Windows operating systems
- Linux operating systems
- TCP/IP
- DNS
- Firewalls
- Network proxies
- Incident response
- Threat hunting
- Detection engineering
- Log analysis
- MITRE ATT&CK framework
- Phishing investigation
- Business email compromise
- Written communication
- Case documentation
Preferred Skills
- AWS
- Azure
- GCP
- Cloud security
- SOAR platforms
- Python
- PowerShell
- KQL
- SPL
- Security automation
- Playbook development
Qualifications
- 4–6 years of IT or security experience, including hands-on exposure to a SOC, security help desk, or systems administration environment
- 3+ years monitoring or investigating alerts using a SIEM (e.g., Splunk, Sentinel, QRadar) and an EDR platform (e.g., CrowdStrike, Defender for Endpoint, SentinelOne)
- Working knowledge of Windows and Linux operating systems, including common attack surfaces and log sources such as event logs, auth logs, and process telemetry
- Foundational understanding of networking concepts (TCP/IP, DNS, proxies, firewalls) and the protocols relevant to intrusion detection
- Strong attention to detail, sound judgment under time pressure, and clear written communication for case documentation and shift handoffs
- Ability to work effectively in a 24/7 SOC rotation, including scheduled shifts and periodic on-call coverage
- Bachelor's degree in Cybersecurity, Information Technology, or a related field — or equivalent hands-on experience
- Foundational certifications such as CompTIA Security+ or CySA+ are expected; progress toward GIAC (GCIH, GFACT) or similar is a plus
Skills Required
- 4-6 years of IT or security experience, including hands-on SOC, security help desk, or systems administration experience
- 3+ years monitoring or investigating alerts using SIEM and EDR platforms
- Experience with SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar
- Experience with EDR platforms such as CrowdStrike, Microsoft Defender for Endpoint, or SentinelOne
- Working knowledge of Windows and Linux operating systems, including attack surfaces and log sources
- Foundational knowledge of TCP/IP, DNS, network proxies, firewalls, and intrusion-detection protocols
- Incident response, threat hunting, detection engineering, log analysis, phishing investigation, and business email compromise experience
- Strong attention to detail, sound judgment under time pressure, and clear written communication
- Ability to work in a 24/7 SOC rotation with scheduled shifts and periodic on-call coverage
- Bachelor's degree in Cybersecurity, Information Technology, or a related field, or equivalent hands-on experience
- CompTIA Security+ or CySA+ certification
- AWS, Azure, GCP, cloud security, SOAR, Python, PowerShell, KQL, SPL, security automation, or playbook development
- Progress toward GIAC GCIH, GFACT, or similar certification
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Simfluent builds and operates global capability centers for modern enterprises. It creates fully integrated hubs that function as permanent extensions of clients’ businesses, with capabilities spanning engineering and platforms, cloud, architecture, product, data, and AI. Through greenfield, build-operate-transfer, and hybrid models, Simfluent helps organizations scale technology delivery while preserving quality, culture, strategic alignment, and local control, with predictable execution at enterprise scale.







