Saronic

Saronic

Security Operations Analyst (mid level)

Austin, TX · Mid

No sponsorship$171k-$800kDetected 35 days ago
PythonBashPowerShellAWSAzureCI/CDCybersecuritySIEMSOARSOC OperationsDetection EngineeringIncident ResponseComplianceSupply ChainRoboticsTCP/IPDNSFirewallCommunication

About the role

  • This is an early, formative role on a SecOps team being built from the ground up, so you'll have a direct hand in shaping how we operate, with room to grow across security domains rather than being boxed into one lane.

Responsibilities

  • Perform in-depth alert investigation and root cause analysis, documenting findings with clear, structured timelines and impact assessments
  • Lead initial incident response for mid-tier events: contain, eradicate, and recover across endpoint, cloud, and identity domains
  • Participate in the on-call incident rotation and effectively communicate status and findings to the SecOps Lead and relevant stakeholders
  • Support the SecOps Lead in developing and refining response playbooks, runbooks, and analyst workflow documentation

Requirements

  • 3+ years of hands-on experience in a Security Operations, detection engineering, or incident response role
  • Hands-on proficiency with enterprise SIEM platforms and their query languages
  • ability to write and iterate on detection logic from scratch
  • Experience with EDR tooling in an operational context
  • ability to hunt, triage, and respond using endpoint telemetry
  • Solid understanding of attacker TTPs mapped to MITRE ATT&CK, and the ability to apply that knowledge during active investigations
  • Experience writing or iterating on detection logic, response playbooks, or SOC operational documentation
  • Scripting proficiency in Python, PowerShell, or Bash for alert enrichment, automation, or triage support
  • Strong understanding of network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral movement patterns
  • Clear and structured written and verbal communication - you can brief a non-technical stakeholder and write a thorough incident report
  • Demonstrated experience triaging and investigating alerts across at least two of the following: endpoint, cloud, identity, network, or SaaS environments
  • Hands-on proficiency with enterprise SIEM platforms and their query languages; ability to write and iterate on detection logic from scratch
  • Experience with EDR tooling in an operational context; ability to hunt, triage, and respond using endpoint telemetry

Nice to have

  • Experience with XDR platforms and cross-domain correlated detection across endpoint, identity, and cloud
  • Familiarity with cloud-native security operations and log sources in AWS or Azure environments
  • Experience with SOAR platforms or building response automation workflows
  • Exposure to supply chain and CI/CD pipeline security monitoring
  • Familiarity with data lake-based or pipeline-driven detection architectures
  • Experience operating in or supporting classified, GovCloud, or FedRAMP environments
  • Background in defense, aerospace, robotics, or other high-assurance operational environments
  • Familiarity with compliance frameworks such as NIST SP 800-171, NIST SP 800-53, or CMMC

Skills

  • Job Overview

Compensation

  • Competitive Salary: Industry-standard salaries with opportunities for performance-based bonuses

Benefits

  • Free lunch benefit and unlimited free drinks and snacks in the office
  • Medical Insurance: Comprehensive health insurance plans covering a range of services
  • Dental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision care
  • Time Off: Generous PTO and Holidays
  • Parental Leave: Paid maternity and paternity leave to support new parents
  • Retirement Plan: 401(k) plan with company match
  • Stock Options: Equity options to give employees a stake in the company's success
  • Life and Disability Insurance: Basic life insurance and short- and long-term disability coverage

Company info

  • Operate across multiple detection and visibility platforms as part of a maturing, layered security monitoring ecosystem
  • We are also committed to providing reasonable accommodations for qualified individuals with disabilities.

Visa & Work Authorization

  • Security Clearance eligible

This listing is sourced directly from Saronic's careers page and normalized into a canonical job model.