Senior Information Security Analyst
Listed on 2026-09-04
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection, Network Security
Mentions 'Vibe coding' as an example scripting skill for automation and investigations; vibe coding could be used for scripting/automation in the SOC.
About the RoleThe Senior Information Security Analyst is a hands-on security operations role focused on detecting, investigating, and responding to cyber threats, tuning detections, and automating investigative and response workflows. The role works cross-functionally to reduce risk, produce clear incident reports, and improve overall security monitoring and response capabilities.
Job Description RoleThe Senior Information Security Analyst is a hands-on security operations role responsible for monitoring, triaging, investigating, and responding to security incidents. The role develops and tunes detections, automates operational workflows, supports security tool integrations, and collaborates with IT and engineering teams to reduce risk and improve operational resilience.
Key Responsibilities- Monitor and triage alerts across security platforms; validate incidents and eliminate false positives.
- Investigate confirmed threats using log analysis, endpoint telemetry, and threat context to determine scope, severity, and business impact.
- Prioritize and upscale security incidents according to incident response procedures.
- Develop and tune security detections to improve accuracy and reduce alert noise; apply MITRE ATT&CK techniques and threat intelligence to detection logic.
- Create scripts and automation to streamline alert triage, investigations, and response activities; automate repetitive operational tasks.
- Support integration and optimization of security tools and data transformations.
- Provide hands-on incident response support including containment, remediation guidance, and recovery activities.
- Produce incident reports detailing findings, root cause, and corrective actions; participate in post-incident reviews and lessons learned.
- Contribute to security operations projects, process improvements, audits, training, and documentation; provide backup coverage during incidents or peak workloads.
- 5+ years of hands-on experience in information security, security operations, incident response, or threat detection roles.
- Bachelor’s degree in a security-related discipline or equivalent practical experience with formal security training or industry-recognized certifications.
- Demonstrated experience performing alert triage, threat investigation, and incident response using enterprise security tools (e.g., SIEM, EDR, email security platforms).
- Working knowledge of security operations processes, including incident lifecycle management, escalation procedures, and stakeholder communication.
- Strong analytical and problem-solving skills and ability to document and communicate findings to technical and non-technical audiences.
- Foundational scripting or automation experience (e.g., Power Shell, Python, Bash) to support security operations.
- Experience in a Security Operations Center (SOC) or 24x7 enterprise monitoring environment.
- Industry-recognized certifications such as CompTIA CySA+, GCIH, GCED, OSDA, CEH, or equivalent.
- Experience with detection engineering, threat hunting, and tuning security controls to reduce false positives and improve detection fidelity.
- Hands-on scripting/automation experience (examples: Power Shell, Python, Bash, Vibe coding) to support investigations and efficiency improvements.
- Familiarity with the MITRE ATT&CK framework and applying adversary TTPs to investigations or detection logic.
- Experience with endpoint detection and response (EDR) tools and email security analysis (phishing investigation, header analysis).
- Experience contributing to security tool deployments, cross-functional initiatives, and presenting findings to senior leadership.
- Salary base range: $99,800.00 - $
- Medical, prescription, dental, and vision coverage beginning on day 1 for eligible employees
- Profit sharing and 401(k) matching (after eligibility criteria met)
- Paid vacation, sick time, and holidays
- Employee appreciation events and employee assistance programs
- Work arrangement:
Hybrid
Incident Response Threat Detection Alert Triage Investigation Detection Engineering Threat Hunting Scripting & Automation Log Analysis Security Monitoring Analytical Thinking Communication Reporting Collaboration Project Contribution Process Improvement Training & Documentation
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).