×
Register Here to Apply for Jobs or Post Jobs. X

Sr. Analyst Security Operations

Job in Great Neck, Nassau County, New York, 11024, USA
Listing for: Solomon Page
Full Time position
Listed on 2026-08-28
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 120000 - 140000 USD Yearly USD 120000.00 140000.00 YEAR
Job Description & How to Apply Below
Position: Sr. Analyst   Security Operations

Sr. Analyst - Security Operations

Our client is seeking an experienced Senior Analyst – Security Operations to join their security team. This role will focus on security monitoring, incident response, vulnerability management, threat detection, and purple team activities. The ideal candidate will have strong hands-on experience across modern security tools and be comfortable investigating complex incidents while collaborating with IT and engineering teams.

Salary: $120K–$140K

Responsibilities:

Security Monitoring & Incident Response
  • Monitor, triage, and investigate security alerts across SIEM, EDR, NDR, and cloud platforms, escalating to the SOC Lead as appropriate.
  • Respond to security incidents end-to-end, including initial triage, containment, eradication, recovery, and post-incident documentation.
  • Execute and help maintain incident response playbooks and runbooks, identifying gaps and recommending improvements.
  • Conduct root cause analysis following incidents and contribute findings to post-incident reviews.
  • Produce clear, accurate incident reports for both technical and non-technical audiences.
  • Participate in an on-call rotation and respond to high-severity incidents outside of business hours when required.
Vulnerability Management
  • Perform vulnerability scans and assessments using tools such as Tenable, Qualys, or Rapid7 on both scheduled and ad-hoc bases.
  • Analyze and prioritize vulnerabilities using CVSS scores, threat intelligence, and asset criticality to guide remediation efforts.
  • Track and follow up on remediation progress with IT and engineering teams, escalating stalled items as needed.
  • Contribute to vulnerability reporting, including trends, patch compliance rates, and risk reduction metrics.
  • Stay current on newly disclosed CVEs and exploit trends and advise on risk-based prioritization.
Purple Teaming & Threat Detection
  • Participate in purple team exercises alongside red team operators to validate detection and response capabilities.
  • Map adversary techniques to the MITRE ATT&CK framework and use exercise findings to identify detection gaps.
  • Write and tune SIEM detection rules, correlation queries, and alerts based on adversary TTPs and purple team outcomes.
  • Conduct threat hunting exercises using hypothesis-driven and ATT&CK-aligned methodologies to identify undetected threats.
  • Track emerging threat actor activity and incorporate relevant TTPs into detection logic and hunting campaigns.
Security Operations & Collaboration
  • Analyze logs from endpoints, firewalls, proxies, cloud platforms, and identity systems.
  • Enrich investigations with threat intelligence, including IOCs, and correlate activity across multiple data sources.
  • Collaborate with IT and engineering teams to tune security controls, reduce false positives, and improve signal quality.
  • Maintain accurate SOC documentation, including runbooks, knowledge base articles, and escalation procedures.
  • Support compliance activities such as SOC 2, ISO 27001, and NIST CSF by providing evidence and participating in audits as required.
  • Mentor junior analysts by sharing knowledge and providing guidance on investigations and tool usage, without formal management responsibility.
Required Qualifications:
  • 5+ years of hands-on experience in a SOC, security operations, or incident response role.
  • Strong proficiency with SIEM platforms such as Splunk, Microsoft Sentinel, or Sumo Logic.
  • Hands-on experience with EDR solutions such as Crowd Strike Falcon or Microsoft Defender.
  • Hands-on experience configuring conditional access policies in Entra or another identity platform.
  • Hands-on experience configuring DLP policies in Microsoft Purview or another platform.
  • Demonstrated experience triaging and responding to a significant volume of security alerts and incidents.
  • Working knowledge of vulnerability management tools and processes, including scanning, prioritization, and remediation tracking.
  • Solid understanding of network protocols and fundamentals, including TCP/IP, DNS, HTTP/S, firewalls, and proxies.
  • Experience analyzing logs across endpoints, networks, cloud environments, and SaaS platforms.
  • Familiarity with the MITRE ATT&CK framework and applying it to investigations and detection…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary