Remote job
Staff Security Analyst
Job details
About this role
Role overview
This senior individual-contributor role serves as the technical authority for detecting, triaging, investigating, and responding to security threats. The position owns the most complex and high-severity cases while strengthening the detections, playbooks, and processes the wider team depends on. It also bridges day-to-day security operations and the engineering work that makes them better.
Responsibilities
- Lead triage and investigation of complex, high-severity security alerts and incidents spanning cloud, endpoint, identity, and application telemetry. - Tune, write, and validate detections to lift signal and reduce noise, partnering closely with detection engineering. - Act as senior incident responder: drive investigations, coordinate response activities, and produce clear post-incident analyses. - Run proactive threat-hunting exercises and convert findings into new detections and preventative controls. - Build and maintain investigation and response playbooks, and raise the team's overall analytical rigor. - Develop automation and tooling that reduces manual toil across triage and investigation workflows, and mentor other analysts.
Requirements
- Typically 8+ years of experience in security operations, incident response, threat detection, or a comparable analytical security role. - Deep hands-on experience investigating threats across cloud, endpoint, identity, and network telemetry. - Strong command of SIEM and detection platforms, log analysis techniques, and query languages. - Proven experience writing and tuning detections and leading end-to-end incident investigations. - Scripting or automation ability, ideally in Python or a similar language. - Sharp analytical judgment paired with clear written communication for incident documentation.
Nice to have
- Detection engineering background and familiarity with detection-as-code practices. - Experience in threat hunting and operationalizing threat intelligence. - Working knowledge of cloud-provider security tooling and digital forensics. - Industry certifications such as GCIA or GCIH.
Benefits and work setup
- Listed compensation of $220,000 for this Staff-level role. - Senior individual-contributor track emphasizing team-wide impact on detections, playbooks, and analyst development.