Security Operations Analyst
Listed on 2026-08-17
-
IT/Tech
Cybersecurity, Security Management & Operations, Network Security
Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.
Job OverviewSaronic Technologies is a leader in revolutionizing autonomy at sea, developing cutting-edge unmanned surface vessels (USVs) to enhance maritime operations for defense and national security. We're looking for a hands-on Security Engineer to join our Security Operations team on the front line of detection and response.
You'll triage and investigate security alerts across endpoint, cloud, identity, network, and SaaS telemetry using our SIEM and XDR platforms, run root-cause analysis on real events, and own initial response for well-scoped incidents to contain, eradicate, recover. You'll tune detections to cut noise, join the on-call rotation, run targeted threat hunts, and contribute to the playbooks and post-incident reviews that make the team better.
This is an early, formative role on a Sec Ops team being built from the ground up, with senior engineers to learn from and real room to grow across security domains rather than being boxed into one lane.
Monitor and triage alerts across endpoint, cloud, identity, network, and SaaS telemetry using enterprise SIEM and XDR platforms
Investigate alerts and perform root-cause analysis, documenting clear timelines and impact assessments
Tune existing detections to reduce false positives, and surface gaps and tuning needs to Detection Engineering
Own initial response for well-scoped, mid-tier incidents across endpoint, cloud, and identity to contain, eradicate, recover
Participate in the on-call rotation and communicate status and findings to security leadership and stakeholders
Contribute to post-incident reviews, surfacing gaps in detection, response, and containment
Coordinate with Security Engineering and IT during active incidents to accelerate response
Support security leadership and senior engineers in building response playbooks, runbooks, and analyst workflow documentation
Run targeted threat hunts to find activity that automated detections miss
Contribute to Sec Ops metrics, reporting, and operational-readiness reviews
Grow your depth across detection, investigation, and hunting as the team scales
2–5 years of hands-on Security Operations, alert triage/SOC, or incident response experience, or an equivalent combination of experience and demonstrated ability; we are open to strong early-career talent
Experience triaging and investigating alerts across at least two of: endpoint, cloud, identity, network, or SaaS
Working proficiency with an enterprise SIEM platform and its query language; able to write investigative queries and tune existing detections
Hands-on experience with EDR tooling to triage, hunt, and respond using endpoint telemetry
Solid understanding of attacker TTPs mapped to MITRE ATT&CK, applied during investigations
Scripting proficiency in Python, Power Shell, or Bash for enrichment, automation, or triage
Strong network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral-movement patterns
Clear, structured written and verbal communication skills and can brief a non-technical stakeholder and write a thorough incident report
Ownership mindset: follows incidents through to closure and flags what needs fixing, not just what needs documenting
Hands-on learning signals such as a home lab, CTF participation, personal detection/hunting projects, or public writeups/blogs
Internship, rotational, or help-desk-to-SOC experience with a clear security operations trajectory
Ability to obtain and maintain a U.S. security clearance
Experience with XDR platforms and cross-domain correlated detection across endpoint, identity, and cloud
Familiarity with cloud-native security operations and log sources in AWS or Azure
Experience with SOAR platforms or building response-automation workflows
Exposure to supply-chain and CI/CD pipeline security monitoring
Familiarity with data lake-based or pipeline-driven…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).