Jobgether

Senior Cyber Operations Analyst

Jobgether

SIEMSOARmachine learningPythonBashJavaScriptPowerShellKQLNLP

About the Role

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Cyber Operations Analyst based in United States. The Senior Cyber Operations Analyst will play a key role in monitoring, detecting, investigating, and responding to cybersecurity threats in a fast-paced security operations environment. The position combines advanced security analysis with automation, AI, and machine learning to improve threat detection and response capabilities. You will work across SIEM, SOAR, endpoints, applications, networks, cloud infrastructure, identity systems, and threat intelligence platforms. As a senior team member, you will handle complex incidents, serve as an escalation point, and help strengthen the capabilities of other analysts. The role also involves developing detections, tuning alerts, improving security workflows, and identifying opportunities to automate repetitive activities. You will collaborate with engineering, data science, incident response, and IT teams to enhance security operations and AI-enabled capabilities. This is a fully remote or hybrid opportunity with a strong focus on continuous improvement, emerging threats, and resilient security operations. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Cyber Operations Analyst based in United States. The Senior Cyber Operations Analyst will play a key role in monitoring, detecting, investigating, and responding to cybersecurity threats in a fast-paced security operations environment. The position combines advanced security analysis with automation, AI, and machine learning to improve threat detection and response capabilities. You will work across SIEM, SOAR, endpoints, applications, networks, cloud infrastructure, identity systems, and threat intelligence platforms. As a senior team member, you will handle complex incidents, serve as an escalation point, and help strengthen the capabilities of other analysts. The role also involves developing detections, tuning alerts, improving security workflows, and identifying opportunities to automate repetitive activities. You will collaborate with engineering, data science, incident response, and IT teams to enhance security operations and AI-enabled capabilities. This is a fully remote or hybrid opportunity with a strong focus on continuous improvement, emerging threats, and resilient security operations. Accountabilities: Serve as a subject matter expert for analysts supporting 24/7/365 security monitoring and incident response operations. Investigate, triage, and respond to cybersecurity incidents, including participation in off-hours and on-call rotations. Act as an escalation point for complex SOC investigations and day-to-day security operations while identifying opportunities for automation. Evaluate security operations capabilities, identify strengths and gaps, and recommend AI-enabled solutions that improve team performance and knowledge. Monitor emerging cybersecurity threats, vulnerabilities, AI developments, and adversary techniques that may affect the organization and its services. Automate repetitive security operations tasks within SOAR environments using cloud technologies, machine learning, and AI. Develop and enhance detection capabilities aligned with the MITRE ATT&CK framework, incorporating automation and AI where appropriate. Validate security alerts by interpreting confidence scores, risk ratings, recommended actions, and relevant threat intelligence. Use NLP and AI-powered tools to analyze security events, logs, incident data, and intelligence. Improve AI model performance and alert quality by labeling events and validating true and false positives. Use multi-agent collaboration and MCP-based solutions within security investigation and response workflows. Collaborate with data science and engineering teams to improve AI models and technologies used in SOC operations. Refine security playbooks, policies, procedures, and guidelines in line with industry best practices and evolving AI capabilities. Partner with security engineering, incident response, and IT teams to improve monitoring, detection, workflows, and response processes. Support the development and tracking of security metrics, KPIs, and service-level objectives. Participate in tabletop exercises and review findings from exercises, vulnerability assessments, and penetration tests to identify and address security gaps. Evaluate logging coverage and examine data across endpoints, databases, applications, identity systems, networks, mobile platforms, and cloud environments. Recommend security-tool adjustments to improve detection quality and reduce false positives. Provide guidance on monitoring, logging, identity, data protection, detection strategies, and preventive controls. Report on SOC performance, security posture, trends, and improvement opportunities to cybersecurity leaders and stakeholders. Mentor junior analysts and contribute to strengthening the overall capabilities and resilience of the security operations team. Requirements Bachelor’s degree and at least 6 years of related experience; equivalent additional directly related experience may be considered in lieu of a degree. Professional experience in SOC monitoring, cybersecurity operations, incident response, or a related field. Strong working knowledge of machine learning and AI and their practical application within security operations. Experience using NLP, query construction, and AI-powered tools to analyze logs, threat intelligence, and incident data. Experience with MCP servers, purpose-built agents, and AI assistants or platforms supporting security investigation and response. Demonstrated understanding of emerging cybersecurity threats, including adversaries’ use of AI-enabled attack techniques. Experience developing security detections aligned with the MITRE ATT&CK framework and relevant open-source AI frameworks. Proficiency with scripting languages such as Python, Bash, JavaScript, or PowerShell, along with experience using KQL. Hands-on experience with SOAR, SIEM, threat intelligence platforms, identity systems, sandboxes, vulnerability management, and EDR/XDR technologies. Strong understanding of cybersecurity threats, vulnerabilities, incident response principles, and security monitoring practices. Familiarity with security frameworks or regulations such as CMMC, NIST CSF, CIS, GDPR, or CCPA. Experience with Azure, AWS, and GCP; experience with government cloud environments is a plus. Experience managing or collaborating with Managed Security Service Providers (MSSPs). Strong analytical and problem-solving abilities, with the judgment to make timely decisions during complex and time-sensitive incidents. Excellent written and verbal communication skills, including the ability to explain cybersecurity incidents clearly and document post-incident reviews and root cause analyses. Strong organizational and time-management skills, with the ability to manage multiple priorities and deadlines in a fast-paced environment. Ability to combine strategic and tactical thinking to improve security operations and drive continuous improvement. Ability to remain calm and focused under pressure while handling urgent security priorities. Strong collaboration and stakeholder-management skills across technical and organizational levels. Preferred certifications include GIAC credentials such as GCED, GCIH, or GDAT, or Microsoft Security Operations Analyst Associate. Preferred experience includes managing SIEM, threat intelligence, security orchestration and automation, IDS/IPS, file integrity monitoring, data loss prevention, and network/system monitoring technologies. Experience conducting investigations using formal chain-of-custody procedures, forensic tools, and established forensic best practices is preferred. Domestic and/or international travel may be required based on workload and project demands; however, the source posting specifies no travel is required for this position. Visa sponsorship is not available for this position. Benefits Salary: USD $102,170–$178,776, with compensation determined by factors including geographic location, role responsibilities, relevant experience, skills, certifications, and education/training. Work arrangement: Fully remote or hybrid work options may be considered. Career growth: Opportunity to operate in a senior cybersecurity role with significant exposure to advanced security operations and emerging technologies. AI and automation exposure: Hands-on opportunities to apply AI, machine learning, NLP, MCP-based agents, and automation to real-world security operations. Technical scope: Work across SIEM, SOAR, EDR/XDR, cloud infrastructure, identity, networks, applications, endpoints, threat intelligence, and security analytics. Leadership opportunities: Serve as a senior escalation point, subject matter expert, and mentor to other security analysts. Cross-functional collaboration: Partner with engineering, data science, security, incident response, and IT teams. Continuous learning: Opportunity to stay current with emerging threats, AI-enabled attacks, evolving security technologies, and industry practices. Meaningful impact: Direct contribution to strengthening security posture, improving detection and response, and building more resilient security operations. Additional compensation: Discretionary bonuses may apply to the position. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1

You'll be redirected to Jobgether's application page

Job Details

Salary

$102K–$179K

Location

United States

Job type

Full-time

Category

Cybersecurity

Experience

6 years

Posted

Today

Job Highlights

  • $102K–$179K salary
  • 6 years level role
  • 100% Remote — open to candidates in United States

About Jobgether

This job is hosted by Jobgether. Clicking Apply opens their site.

More jobs from Jobgether on RC9

Remote Work Style

Mixed

Mix of flexible and scheduled meetings

Your Match

See how well your skills line up with this role, and what you're missing.

AI Cover Letter

Generate a cover letter tailored to this job from your profile.