Description
We are looking for a highly analytical, decisive SecOps Analyst to join our SecOps Team. Our SOC runs on an agentic AI platform that autonomously investigates and correlates security alerts across our infrastructure, cloud, and product environments. Your role is to be the critical human judgment layer: validating AI-driven investigations and owning confirmed incidents end-to-end.
If you take full ownership of a problem until it's truly closed, think critically rather than trusting a tool blindly, and want to operate at the frontier of AI-driven security operations, this role is for you.
Responsibilities
- AI Investigation Validation: Review and validate findings from our agentic AI SOC platform. Catch false positives/negatives and surface edge cases internally to improve agent accuracy.
- End-to-End Incident Ownership: Own confirmed incidents from escalation through containment, remediation, and reporting, driving cases to closure, not just triage.
- Application & Product Log Monitoring: Investigate anomalies across our application and product logs to detect abuse, tenant/account misuse, and threats unique to our platform.
- Human-in-the-Loop Decision Authority: Authorize containment actions (isolating a host, suspending an identity, revoking a session) on critical alerts with confidence and speed.
- Proactive Threat Hunting: Hunt for threats outside the current scope, including business-logic abuse, insider threats, and anomalies unique to our product.
- Phishing & User Defense: Own confirmed phishing cases end-to-end, from detection through user communication and takedown.
- Documentation: Maintain clear investigation runbooks and case documentation so knowledge is shared, not siloed.
- On-Call Rotation: Serve as the decision-maker for high-severity, AI-escalated incidents during off-hours — reserved for high-confidence critical escalations, not noise.
Requirements
- 2+ years of hands-on experience in a SOC, Incident Response, or Threat Intelligence role.
- Strong experience querying and analyzing logs in Splunk (must).
- Deep understanding of common attack vectors, MITRE ATT&CK, and enterprise security tools (EDR, IdP, SASE/Firewalls).
- Demonstrated critical thinking: comfortable questioning AI/automated conclusions rather than accepting them at face value.
- Strong incident command instincts: fast, confident decisions under pressure with incomplete information.
- Excellent written and verbal English communication for documentation and cross-functional incident communication.
Advantage
- Experience querying application/observability logs in Logz.io or ELK stack.
- Experience with AI-driven or agentic security tools.
- Experience in a SOAR-driven environment.
- Familiarity with investigating cloud-native threats.
- Relevant certifications (e.g., GCIA, GCIH, CySA+).