Remote job
Security Analyst - Tier 3 (West Coast)
Job details
About this role
Role overview Join a senior analyst team responsible for validating investigations produced by AI-driven security agents in customer environments. This Tier 3 role acts as the technical lead and escalation point, mentoring junior analysts while hunting for emerging threats and shaping the processes that allow the team to scale without losing quality. The position is based on the West Coast and blends hands-on incident work with cross-functional collaboration across sales, engineering, and product.
Responsibilities - Review and validate AI-generated investigations for accuracy, completeness, and risk posture - Serve as the top-tier escalation point and mentor for junior analysts - Correlate telemetry across cloud, endpoint, identity, and network sources to reconstruct attack chains - Investigate malicious activity the automated system has responded to and articulate the risk prevented to customers - Run proactive threat hunts against customer environments and feed new detections back into the platform - Support ongoing monitoring, triage, and prioritization, especially during active incidents - Communicate findings clearly to stakeholders ranging from SOC analysts to executive leadership - Help design scalable workflows that preserve quality as the team grows
Requirements - 5+ years of experience in security operations - Hands-on background investigating alerts across endpoint, network, identity, email, and cloud sources - Working knowledge of monitoring tools such as XDR, SIEM, IDS/IPS, and IDP - Familiarity with log and telemetry concepts and frameworks like MITRE ATT&CK - Querying experience with SIEM languages such as SPL, KQL, FQL, or SQL - Strong grasp of malware analysis methods and incident triage practices - Ability to independently verify automated analysis and make sound security decisions - Service-oriented mindset with strong interpersonal and mentoring skills
Nice to have - Experience in a managed services environment - Incident handling background - Relevant certifications such as Security+, GSEC, or GCIH