Senior Security Operations Analyst

Security OperationsSecurity OperationsFull TimeRemoteSeniorTeam 1,001-5,000Since 2021H1B SponsorCompany SiteLinkedIn

Location

Canada

Posted

11 days ago

Salary

0

Seniority

Senior

Job Description

Senior Security Operations Analyst

Newfold Digital

• Security Operations Analyst is responsible for the day-to-day monitoring, analysis, and investigation of security threats across enterprise systems and networks. • The role triages and responds to security alerts and incidents, working both independently and in collaboration with senior analysts on known or suspected threats. • The analyst supports incident response, threat intelligence, and forensic analysis activities in alignment with established security best practices and control frameworks. • This includes identifying anomalies, escalating issues as appropriate, and contributing to the improvement of detection and response processes. • Security Operations Analysts may work shifts and participate in on-call rotations to support global operations and ensure continuous security monitoring coverage. • Develop and deliver security reports and metrics to support operational awareness and leadership decision-making. • Identify and support mitigation of information security risks, including evaluating projects and initiatives for alignment with security requirements, policies, and standards. • Support internal and external audits by collecting and analyzing evidence, assessing control effectiveness, and ensuring adherence to established security frameworks and policies. • Track and manage remediation activities, including corrective action plans and audit findings, ensuring timely resolution of identified security issues. • Identify, investigate, and respond to security incidents, including analyzing root cause and impact to contain threats and reduce organizational risk. • Maintain and support security tools, controls, and monitoring capabilities to ensure effective detection and response. • Develop, implement, and continuously improve threat-informed detections and automated response playbooks, including use case development, rule creation, tuning, validation, and optimization through incident feedback and testing. • Monitor systems and security telemetry for violations, vulnerabilities, and anomalous activity. • Analyze and apply threat intelligence to enhance detection, response, and situational awareness. • Identify and support onboarding and validation of security telemetry to ensure effective detection and visibility. • Collaborate with cross-functional teams to support incident response, remediation, and security improvements. • Assist in the evaluation and selection of security technologies and solutions to support detection, monitoring, and response capabilities.

Job Requirements

  • A degree in Cybersecurity, Information Technology, Computer Science, or related field is desirable.
  • Industry-recognized certifications are a plus and may include: CompTIA Security+ or CySA+, Microsoft SC-200, GIAC Security Essentials (GSEC), GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), GIAC Cyber Threat Intelligence (GCTI), GIAC Security Operations Certified (GSOC), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), and relevant cloud or security vendor certifications (e.g., SIEM, SOAR, endpoint, or cloud security platforms).
  • Working knowledge of security controls including access control, authentication, encryption, system integrity, and logging as applied to security monitoring and detection.
  • Experience with security operations including monitoring, incident response, and incident management procedures, with the ability to investigate, escalate, and respond to security events.
  • Ability to develop, modify, and maintain threat detection rules within SIEM platforms, including tuning alerts and improving detection fidelity.
  • Understanding of security telemetry, including log collection and ingestion (e.g., syslog, Windows Event Forwarding, ELK), normalization, and data quality considerations to support effective detection and visibility.
  • Strong knowledge of operating systems (Windows, Linux, macOS), identity systems (e.g., Active Directory), and network fundamentals (TCP/IP, DNS) as they relate to security monitoring and investigation.
  • Experience with endpoint, network, and host-based security tools including EDR, IDS/IPS, firewalls, vulnerability scanners, and host-based detection/prevention systems.
  • Ability to analyze and correlate data across multiple security and telemetry sources to identify patterns, anomalies, vulnerabilities, and potential security threats.
  • Experience applying security frameworks such as MITRE ATT&CK to map adversary behaviors and support detection and response development.
  • Experience with malware analysis, network forensics, and digital forensics concepts and tools; reverse engineering skills are a plus.
  • Ability to assess security threats and implement timely mitigations under pressure.
  • Experience using scripting languages such as Python, PowerShell, or equivalent to support automation, analysis, and response activities.
  • Strong collaboration and communication skills with the ability to build effective relationships across technical and non-technical teams.
  • Experience with security platforms and tools including SIEM, SOAR, EDR, vulnerability management, and threat intelligence tools (e.g., Google SecOps/Chronicle, Microsoft Defender for Endpoint, SentinelOne Singularity, Tanium Threat Response, Recorded Future).
  • Experience with cloud security monitoring and native security services across AWS, Azure, Google Cloud, or OCI is a plus.
  • Familiarity with security-focused frameworks, methodologies, and best practices for detection, response, and vulnerability management is a plus.
  • Ability to analyze and apply threat intelligence to support detection, investigation, and response activities.
  • Experience developing or working with automated response workflows and playbooks (SOAR).

Benefits

  • Flexible work arrangements
  • Professional development

Related Categories

Related Job Pages

More Security Operations Jobs

ContractRemoteTeam 51-200Since 1995H1B No Sponsor

• Building a mock-up environment on the NATO Software Factory to replicate the functionalities that exist in the operational version of COMS today. • Capturing the requirements and demonstrating to industry the functionalities of the current capabilities by demonstrating on the mock-up environment. • Identify and capture the functional and non-functional requirements of what COMS is able to deliver today into a NATO AQAP conforming format. • Create a recorded video introducing what COMS is today, and going through the different requirements captured in D2. • Present a live demo of the COMS mock-up environment as part of an industry engagement day organized by NCIA.

Netherlands
Fortis Games logo

Senior Security Operations Engineer, Detection and Response

Fortis Games

Games where you belong. Come build with us. Visit www.fortisgames.com to learn more.

Full TimeRemoteTeam 201-500H1B No Sponsor

• Design, implement, test, and tune detections across endpoint, identity, cloud, SaaS, network, and application telemetry. • Build detection-as-code practices using version control, testing, peer review, documentation, and repeatable deployment methods. • Improve SIEM and security telemetry pipelines, including log ingestion, parsing, enrichment, correlation logic, alert routing, and case management workflows. • Design and operate practical deception capabilities such as canary tokens, decoy accounts, honey assets, and other high-signal tripwires. • Lead and support incident response investigations — perform severity triage, coordinate containment and remediation, and produce clear post-incident findings. • Work closely with IT, infrastructure, engineering, and game development teams to improve security visibility and response readiness across the environment. • Support selected GRC activities including audit evidence collection, technical control documentation, third-party risk input, and policy or SOP documentation (approximately 20% of time).

United Kingdom
Wave Mobile Money logo

Director of Security Operations

Wave Mobile Money

Wave is building a cashless Africa in Senegal, Cote d'Ivoire, Uganda, Burkina Faso, Gambia & Mali. Find us @www.wave.com

Full TimeRemoteTeam 501-1,000Since 2017H1B Sponsor

• Lead security operations across 9+ markets including Mali, Burkina Faso, Niger, and the Democratic Republic of Congo. • Manage and train security leaders and consultants in each country while responding to crisis scenarios. • Translate Wave's risk appetite into practical security frameworks that protect employees and enable rapid business growth. • Design security systems and processes across Wave while remaining hands-on during critical incidents. • Serve as Wave's primary crisis response leader for security incidents across all markets, providing 24/7 on-call support during emergencies. • Establish and maintain crisis response protocols, evacuation procedures, and emergency communication systems across operating countries. • Build and maintain business continuity plans.

Senegal
Booz Allen Hamilton logo

Security Operations Analyst

Booz Allen Hamilton

Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp

Security Operations Analyst Location: Huntsville United States Job Description: Security Operations Analyst, Mid The Opportunity: Respond to and resolve cybersecurity incidents, and proactively prevent the reoccurrence of these incidents. Apply leading-edge principles, theories, and concepts. Contribute to the development of new principles and concepts. Work on unusually complex problems and provide highly innovative solutions. Operate with substantial latitude for unreviewed action or decision. Mentor or supervise employees and technical competencies. You Have: - 5+ years of experience supporting Information Technology or Intelligence Operations - Experience supporting a Computer Incident Response Team, Cyber Network Operations, or Security Operations Center (SOC) operations for a large and complex enterprise - Experience with Intelligence Driven Defense, Cyber Kill Chain methodology, or MITRE ATT&CK framework - Knowledge of industry-accepted standards for incident response actions and best practices for SOC operations - Knowledge of security operation tools, including SIMs or DCAP analysis - Knowledge of intrusion set tactics, techniques, and procedures - Top Secret clearance - Bachelor's degree Nice If You Have: - Experience with Microsoft Sentinel - Experience with Splunk - TS/SCI clearance with a polygraph - GIAC Continuous Monitoring (GMON) Certification - GIAC Certified Incident Handler (GCIH) Certification - GIAC Certified Forensic Analyst (GCFA) Certification - GIAC Certified Intrusion Analyst (GCIA) Certification - GIAC Network Forensic Analyst (GNFA) Certification - GIAC Cloud Threat Detection (GCTD) Certification - GIAC Cloud Forensics Responder (GCFR) Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Top Secret clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $61,900.00 to $141,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Alabama
$61.9K - $141K / year