Remote job
Senior Security Operations Analyst (Detection & Response)
Job details
About this role
Role overview This senior individual-contributor position leads detection and response for a regulated consumer-finance environment that safeguards the financial data of a large homeowner customer base. As the team's second dedicated monitoring and response hire, the analyst will partner with the security lead to engineer detections, automate response, and harden visibility across an AWS, Google Workspace, and SaaS estate. The role combines hands-on incident response with the chance to build out a modern detection and response practice from an early stage.
Responsibilities - Share a 24/7 on-call and incident-response rotation, triaging, investigating, and driving containment of security alerts and incidents. - Build and maintain incident-response runbooks, escalation paths, and post-incident reviews so response is consistent and repeatable. - Engineer, tune, and maintain SIEM detections, correlation rules, dashboards, and reporting within the Coralogix platform across cloud and identity log sources. - Reduce false positives, onboard new log sources, and close detection coverage gaps across cloud and endpoint telemetry. - Run day-to-day vulnerability management, prioritizing findings, coordinating remediation with system owners, and reporting on risk reduction. - Develop detection-as-code and lightweight SOAR automation so common alerts self-triage, and apply AI/LLM tooling to accelerate investigation and detection engineering. - Produce recurring security metrics and audit-ready control evidence for leadership.
Requirements - 5+ years in security operations, incident response, SOC, or detection engineering at a mid-to-senior IC level. - Hands-on experience running or actively participating in an on-call / incident-response rotation independently. - Strong SIEM skills including authoring and tuning detections, correlation rules, and dashboards. - Solid grasp of cloud (AWS), identity (Google Workspace), and SaaS attack surfaces and telemetry.
Nice to have - Experience with detection-as-code, SOAR platforms, and AI/LLM-assisted investigation workflows. - Background in regulated consumer-finance or financial-services security programs.
Benefits and work setup - Remote-first within the U.S., with optional in-person collaboration near a Palo Alto-area headquarters roughly once per week for nearby candidates. - Candidates must reside in approved U.S. states of operation. - Comprehensive medical, dental, and vision plans with FSA/HSA options. - Unlimited paid time off plus 10 company holidays. - Generous, fully paid parental leave with transition-time flexibility and equity participation. - 401(k), life insurance, short- and long-term disability coverage. - Monthly stipends for internet and mobile, wellness perks, home-office reimbursement, and company-provided laptop and monitor.