Saviynt logo
Saviynt

The #1 Converged Identity Platform with Intelligent Access Governance for Employees, Third Parties & Machines.

L3 SOC Analyst

Security OperationsSecurity OperationsFull TimeRemoteSeniorTeam 501-1,000Since 2010H1B SponsorCompany SiteLinkedIn

Location

United Kingdom

Posted

101 days ago

Salary

0

Seniority

Senior

Job Description

L3 SOC Analyst

Saviynt

• Act as the final escalation point for complex incidents originating from L1/L2 analysis. • Lead investigations into high-severity security events, including those impacting AWS, Azure, Kubernetes clusters and hybrid environments. • Perform advanced forensic analysis across endpoints, cloud workloads, and network telemetry to determine root cause, impact, and remediation actions. • Correlate telemetry from SIEM, EDR, CSPM, and cloud-native sources to identify sophisticated attack chains. • Design, develop, and maintain automated response playbooks within the SOAR platform to improve response efficiency. • Build and maintain automation scripts (Python, Go, etc.) for alert enrichment, evidence collection, and containment. • Integrate security platforms via APIs to enable streamlined, automated detection and response workflows. • Identify opportunities to reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) through automation and process optimisation. • Conduct proactive threat hunting across enterprise and cloud environments using intelligence-driven and hypothesis-based methodologies. • Serve as an SME for cloud security monitoring leveraging tools such as AWS GuardDuty, CloudTrail, CrowdStrike, and Proofpoint. • Develop and tune SIEM detections, correlation rules, and EDR queries aligned to MITRE ATT&CK tactics and emerging threat intelligence. • Provide technical mentoring and guidance to L1/L2 analysts to strengthen SOC capability. • Maintain and enhance SOC documentation including SOPs, runbooks, and response playbooks. • Analyse incident trends and operational metrics to recommend improvements in detection coverage, automation effectiveness, and security posture.

Job Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, or related discipline (or equivalent industry experience).
  • Extensive experience in Security Operations with demonstrable time in a senior analyst, threat hunter, or L3 role.
  • Strong hands-on experience in cloud security monitoring and incident response across AWS, Azure, or GCP.
  • Proven scripting and automation capability using Python, Go, PowerShell, Bash, etc.
  • Practical experience with SOAR platforms (e.g., CrowdStrike Fusion SOAR) and SIEM technologies (e.g., CrowdStrike Falcon, Splunk, QRadar, Microsoft Sentinel).
  • Deep understanding of EDR tooling, host/network forensics, and detection engineering practices.
  • Strong working knowledge of the MITRE ATT&CK framework and its application in threat detection and hunting.

Benefits

  • UK Citizenship is mandatory due to data residency, customer contractual obligations, and potential security clearance requirements.
  • Candidates must have the unrestricted right to work in the United Kingdom.
  • Availability during weekends and outside standard working hours is expected to support critical incidents and urgent escalations.

Related Categories

Related Job Pages

More Security Operations Jobs

Zscaler logo

Cyber Incident Response/Customer Security Operations - SkillBridge Intern

Zscaler

We make it easy to secure your cloud transformation. Get fast, secure, and direct access to apps without appliances.

OtherRemoteTeam 5,001-10,000Since 2008H1B Sponsor

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description We are looking for a Detection Engineering - SkillBridge Intern to join our Red Canary Customer Service Operations team. This is a remote role reporting to the Manager, Detection Engineering. The security landscape is always shifting and introducing new adversaries. Red Canary operates 24/7 to track down threats using the entirety of our customer’s data and deliver fast and practical detections to our customers. Together, we create a customer-centric culture that fosters success, adoption, and continuous growth. What you’ll do (Role Expectations) - Use Red Canary’s detection platform to analyze EDR telemetry, alerts, and log sources across several detection domains including Endpoint, Identity, SIEM, and Cloud/SaaS. - Publish threats for customers using concisely-written communication while effectively conveying key and important indicators. - Research coverage opportunities to create new detectors and tune existing ones through detector development. - Improve the Detection Engineering workflow through orchestration and automation. Qualifications - Cybersecurity operational experience with a focus in Detection and Response. - Must be located in the United States during the SkillBridge program. - Must be a current Active Duty United States military member or a member of the United States Guard/Reserve component on active duty orders for at least the last 180 days with 180 days or fewer remaining prior to your date of discharge. - Approval from your unit commander. - MOU must be approved and submitted before start. Requirements - Experience with EDR tools. - Experience conducting Incident Response activities. - Malware/Threat Analysis and Detection Engineering experience. Benefits - Various health plans - Time off plans for vacation and sick time - Parental leave options - Retirement options - Education reimbursement - In-office perks, and more!

Maryland
Job Closed
Twilio logo

Senior Manager, Security Risk

Twilio

Twilio is a Platform-as-a-Service (PaaS) company established in 2007. In support of a flexible workplace, Twilio has previously posted freelance, flexible sched

Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! . See yourself at Twilio Join the team as Twilio’s next Senior Manager, Security Risk Management About the job Twilio is looking for a dynamic, hands-on Senior Manager of Security Risk Management to lead and evolve our global risk function. This role is designed for a strategic thinker who isn't afraid to roll up their sleeves and contribute as an individual performer while managing a high-performing, distributed team. You will be responsible for navigating a complex microservices environment of hybrid cloud and on-premise telecommunications infrastructure, ensuring our security risk approach is pragmatic, scalable, and deeply integrated into the R&D and IT lifecycles. Responsibilities In this role, you’ll: - Program Leadership & People Management: Lead, mentor, and grow a team of international and domestic risk analysts. - Foster a culture of excellence, accountability, and continuous professional development. - Hands-on Risk Assessment: Conduct and oversee complex risk assessments across microservices architectures, cloud-native environments, and legacy on-premise telecommunications systems. - Integrating compliance control requirements into the risk management process. Strategic Framework Implementation: Operationalize and mature the One Twilio Risk Management framework leveraging risk management frameworks (NIST RMF, ISO 27005, etc.) with a specific focus on emerging areas like AI Risk, Data Governance, Privacy, Reliability, and Observability. - Advanced Reporting: Develop and deliver high-impact, executive-level risk reporting. You must be able to translate technical vulnerabilities into business risk, providing leadership with the "so-what" and actionable insights to drive investment. - Workflow Optimization: Identify and design efficient process workflows within Jira and GRC tools to automate risk intake, tracking, and remediation, ensuring seamless integration with R&D and IT workstreams. - Pragmatic Problem Solving: Deliver "outside the box" based risk solutions that balance risk mitigation with business velocity. Ensure the security organization is viewed as an enabler, not a blocker. - Stakeholder Management: Act as a primary point of contact for external auditors and regulators, clearly articulating Twilio’s risk posture and the effectiveness of our controls. Qualifications Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply. If your career is just starting or hasn't followed a traditional path, don't let that stop you from considering Twilio. We are always looking for people who will bring something new to the table! *Required - Experience: 8+ years in Cybersecurity or Information Security, with at least 4+ years in a people management role leading international teams. A "no-ego" approach to leadership; someone who is comfortable "taking the heat" for the program while giving credit to the team for successes. - Negotiation & Diplomacy: The ability to navigate high-tension situations finding the "win-win" middle ground. - Technical Domain Expertise: Deep understanding of hybrid cloud environments (AWS/GCP), on-premise infrastructure, and microservices. Experience in the Telecommunications sector is highly preferred. - Framework Fluency: Proven track record of implementing and maturing risk frameworks such as NIST RMF, ISO 3100. Specific experience in AI Risk Management or Data Governance frameworks is a significant plus. - Tooling Mastery: Power-user level proficiency in Jira (for workflow orchestration) and experience with security tooling (e.g., Wiz, Orca, Snyk) and GRC platforms (e.g., LogicGate, Jira, Archer, ServiceNow). - Strategic Mindset: Ability to pivot quickly between tactical "firefighting" and long-term strategic planning. You must be able to identify which risks are the most valuable to report on at any given time. - Communication: Exceptional written and verbal communication skills, with a proven ability to present complex risk topics to non-technical executive audiences. Ability to highlight and report on shared risk responsibility is key. - Adaptability: Proven ability to adapt to a specific company culture while driving necessary change and maturity. *Desired: - This role will have a deep fascination with how AI is changing the threat landscape and have ideas on how to govern it without stifling innovation. - Familiarity with the NIST AI RMF or ISO 42001 and the ability to assess the risks of data leakage and prompt injection in internal AI tools. - Risk Appetites & Tolerance Modeling: Ability to move beyond "High/Medium/Low" to help the business define and document specific risk appetite statements that guide engineering trade-offs. - Cost-Benefit Analysis: Skill in quantifying the cost of a security control versus the value of the risk it mitigates, ensuring pragmatic investment.This individual will understand that a perfect security score is impossible and instead focus on 'Intelligent Risk Taking' that keeps the company safe while it scales. - Threat Modeling: Experience integrating threat modeling into the early stages of a CI/CD pipeline rather than performing assessments after production. - Infrastructure as Code (IaC) Familiarity: Understanding how risk is managed in automated environments (Terraform, Pulumi) where "policy-as-code" can be implemented. - Product Security Mindset: Experience working with Product Managers to prioritize security features in a roadmap alongside revenue-generating features. Location This role will be remote, but is not eligible to be hired in CA, CT, NJ, NY, PA, WA. Travel We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings. What We Offer Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location. Compensation *Please note the salary range information provided applies only to candidates residing in California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Washington D.C., and Washington State due to local requirements. Compensation for candidates in other locations will be discussed during the hiring process. Please note that hiring for this role is not restricted to the locations listed above. The estimated pay ranges for this role are as follows: - Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C. : $207,200 - 259,000. - Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $219,360 - 274,200. - Based in the San Francisco Bay area, California: $243,680 - 304,600 - This role may be eligible to participate in Twilio’s equity plan and corporate bonus plan. All roles are generally eligible for the following benefits: health care insurance, 401(k) retirement account, paid sick time, paid personal time off, paid parental leave. The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location. Applications for this role are intended to be accepted until May 20th, 2026, but may change based on business needs. Twilio thinks big. Do you? We like to solve problems, take initiative, pitch in when needed, and are always up for trying new things. That's why we seek out colleagues who embody our values — something we call Twilio Magic. Additionally, we empower employees to build positive change in their communities by supporting their volunteering and donation efforts. So, if you're ready to unleash your full potential, do your best work, and be the best version of yourself, apply now! If this role isn't what you're looking for, please consider other open positions. Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.

United States
Job Closed
AHEAD, Inc. logo

Senior Technical Consultant-Network Security Operations

AHEAD, Inc.

AHEAD, Inc. is an IT services and consulting company that is on a mission to “accelerate the impact of technology on business.” As an employer, the company

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description The Technical Consultant, Network Security Operations, is a cybersecurity professional with knowledge around the Palo Alto XSIAM Platform, Cortex XDR, Cortex XSOAR and working knowledge around additional technologies. Responsible for the technical execution of XSIAM, XDR and XSOAR deployments with complex configurations. As a Technical Consultant, you will be a key player in implementing Security Operation tools for a diverse client base, helping them detect, respond and automate effectively. - Hands-on role in the end-to-end delivery of Palo Alto XSIAM, XSOAR, and XDR solutions to include deployment, configuration and customization to meet client requirements. - Develop and implement custom XSIAM, XSOAR and XDR content such as Correlations rules, data models, Automation Playbooks that streamline client SOC workflows. - Integrate a variety of data sources that ensure visibility across endpoint, network, cloud and identity. - Collaborate with clients to optimize and fine tune their deployment and provide guidance to assist with the optimization of the platform. - Act as a technical resource for troubleshooting and resolving complex XSIAM-related issues during and post-implementation. - Contribute to detection and Playbook strategies to enhance client security posture. - Contribute to project documentation, ensuring clarity and completeness of Solution Designs and As-Built configurations. - Mentor junior AHEAD consultants, sharing your XSIAM knowledge and fostering their technical development. Qualifications - 3-5 years of dedicated experience in cybersecurity, with a strong practical background in SIEM, SOAR, EDR/XDR, or SOC operations. - 2-4 years of demonstrated threat intelligence and/or Incident response experience. - Minimum of 2 years of direct experience implementing and configuring XSIAM or similar advanced SecOps Platforms. - Demonstrated expertise in SIEM and Soar development to include creating playbooks, log collection, parsing and normalization. - Demonstrated expertise in EDR/XDR deployment and management with CrowdStrike, Cortex and Cisco. - Proficient with XQL for data analysis and rule creation. - Solid Understanding of network security, cloud environments, Identity, Linux, Mac and Windows. - Strong analytical and troubleshooting capabilities. - Effective communication skills with the ability to engage with clients and Team members. - Palo Alto Network Certifications (PCNSE) or relevant industry certifications (CISSP, CYSA, CEH, Security+, Pentest+, OSCP) are a plus. Requirements - $130,000 - $200,000 a year Benefits - Medical, Dental, and Vision Insurance - 401(k) - Paid company holidays - Paid time off - Paid parental and caregiver leave - Plus more! See benefits here for additional details.

United States
Job Closed

Cyber Operations Intern

American Systems

Headquartered in Chantilly, Virginia, American Systems is a government contractor that provides professional, technical, and Information Technology services. Established in 1975, A

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description We are looking for an entry level IT Security Analyst summer intern to perform the day-to-day operations of the security solutions and use these solutions to identify, investigate and resolve security incidents on the network. This is a great opportunity for someone who likes to dig in and understand the intricacies of cyber defense, has a technical hands-on mindset, and exhibits good work ethic and a positive attitude to learning the ins and outs of information security operations for an enterprise environment. - Co-Op / Interns typically represent college students trying to gain related work experience while pursuing an undergraduate degree. - Under direct supervision, performs various tasks and assignments for the organization's professional staff in such disciplines as Engineering, Software Development, Database Management, Security Threat Analysis. - Maintain in-place security tools and processes. - Evaluate, test and implement new security tools & technologies. - Respond to computer security incidents. - Research system and network logs and alerts as they relate to incidents. - Identify gaps in cyber operations capabilities and assist in developing those capabilities. - Develop technical summary information for presentation to management. Qualifications - High School diploma and 1-2 years of college or related work experience. - Understanding of incident response process in an enterprise operations environment. - Understanding of cyber threats and defenses against those threats. - Knowledge of Windows, Linux, and networking. - Knowledge of enterprise security technologies such as web filtering, endpoint protection and forensics, sandbox, threat intel integration, firewalls, SIEM, patch and vulnerability management etc. - Familiarity with using scripting languages for security automation. - Ability to juggle multiple tasks and projects with varying priorities. - Ability to document findings for audiences with various levels of technical expertise. - MUST BE A US CITIZEN. - Cyber Defense Club membership a plus! Benefits AMERICAN SYSTEMS is committed to pay transparency for our applicants and employee-owners. The salary range for this position is USD $43,200.00/Yr. - USD $72,100.00/Yr. Actual compensation will be determined based on several factors permitted by law. AMERICAN SYSTEMS provides for the welfare of its employees and their dependents through a comprehensive benefits program by offering healthcare benefits, paid leave, retirement plans, insurance programs, and education and training assistance. EEO Statement EEO Race/Sex/Disability Status/Veteran Status

United States
$55K - $65K / year
Job Closed