×
Register Here to Apply for Jobs or Post Jobs. X

Security Analyst (Security Operations

Job in Houston, Harris County, Texas, 77246, USA
Listing for: Socket.dev
Full Time position
Listed on 2026-08-08
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 100000 - 130000 USD Yearly USD 100000.00 130000.00 YEAR
Job Description & How to Apply Below
Position: Security Analyst (Security Operations)

About Nscale

Nscale is building the infrastructure platform for the AI era. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers, reducing the complexity of AI development and helping customers manage cost, innovate rapidly, and operate responsibly.

We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.

About

the Role

We are hiring Security Response Engineers to own what happens after an alert becomes real, across enterprise, cloud, production, data centre, and operational technology environments.

Agents and a managed security service provider (MSP) hold the level 1 queue. You take escalations, decide fast, act, and then make sure the same class of problem does not come back. Half the job is response. The other half is turning what you learned into engineering work that permanently retires the issue.

If you have spent years closing the same ticket every Tuesday—and knowing exactly how to fix it for good, but never having the mandate—this is the job where that is the mandate.

How this function works

Read this section carefully. It is not a standard SOC, and the difference is the whole point.

  • You do not watch a queue. An in-house security agent and a contracted managed provider hold level 0 and level 1 around the clock. Work reaches you as an escalation with context already attached.
  • Every escalation forks three ways: act, solve, or both. Act is the immediate containment. Solve is the engineering artifact you hand to the build teams so that alert class does not fire again. Most escalations are both.
  • Your primary metric is the share of escalations permanently solved. Not tickets closed, and not mean time to close. If the same alert fires twice, we got it wrong the first time.
  • Two classes, not five. We sort everything into risk indicator or actionable, using the SSVC model. If you have drowned in a five-tier severity scheme nobody trusted, you will like this.
  • Follow-the-sun across hubs. Nobody works permanent nights.
What you'll be doing

Escalation response

  • Take escalations from the agent and managed provider, scope them against real asset and business context, decide, and act.
  • Execute approved containment, including isolating devices, revoking sessions, restricting access, blocking activity, and preserving evidence.
  • Know what you can do immediately, what requires authority, and what could disrupt production if handled incorrectly.

The solve

  • Ensure every escalation exits with an engineering artifact where one is warranted: a detection requirement, telemetry gap with a business case, control change, automation, or regression test.
  • Specify the artifact clearly enough that the team building it can act without a second conversation. You do not build it; you make the required outcome unambiguous.

Investigation and evidence

  • Build timelines from primary evidence across identity, endpoint, email, SaaS, cloud, network, production, and increasingly operational technology and building management systems, which are currently dark to us.
  • Close every case with a security disposition, an owner, the evidence, actions taken, and any required follow-up.

Detection judgement

  • Review candidate detections auto-authored by our research loop as shadow rules and assess their inside-out coverage.
  • Make the human judgement on whether shadow detections should be promoted to live. You do not write the detection logic, but nothing goes live without your call.

Provider quality

  • Reconcile the managed provider’s case work, which lives in their platform rather than ours, against our standards.
  • Hold the provider accountable for evidence, analysis, routing, and closure quality.

Readiness

  • Contribute to threat hunts, incident reviews, tabletop exercises, recovery tests, the on-call rotation, and keeping runbooks honest.

First 90 days

  • Independently own escalations across common classes,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary