← Back to all jobs

Senior Security Operations Analyst

Saronic Technologies · TX · Full-time · Posted 2026-08-19

Apply on the company site →

Job description

Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms. JOB OVERVIEW Saronic Technologies is a leader in revolutionizing autonomy at sea, developing cutting-edge unmanned surface vessels (USVs) to enhance maritime operations for defense and national security. We're looking for a hands-on Senior Security Engineer to be a technical anchor for our Security Operations team. You'll lead detection and response across endpoint, cloud, identity, network, and SaaS telemetry, owning the complex and ambiguous investigations end-to-end, partnering closely with Detection Engineering to turn what you see on the front line into better detections, and turning post-incident lessons into durable improvements to our playbooks and runbooks. You'll be a trusted escalation point on the on-call rotation, lead the threat hunts that catch what automation misses, and mentor the engineers around you. This is a formative, high-autonomy role on a SecOps team being built from the ground up, where you'll set the technical bar and help shape how Saronic operates across security domains. RESPONSIBILITIES Detection & Alert Operations - Operate across endpoint, cloud, identity, network, and SaaS telemetry in our SIEM and XDR to tune and refine detections in-flight, and be the primary front-line voice driving detection improvements back to Detection Engineering - Lead root-cause analysis on complex, novel, or cross-domain events, and structure investigations others can follow - Own coverage from the operator's seat and map what you're seeing to MITRE ATT&CK, identify gaps, and set the priorities Detection Engineering builds against Incident Response & Investigation - Lead incident response end-to-end for complex and higher-severity incidents across endpoint, cloud, and identity to contain, eradicate, recover - Serve as a trusted escalation point on the on-call rotation, and brief status and impact to security leadership and stakeholders - Own post-incident reviews, translating detection, response, and containment gaps into prioritized, durable improvements - Coordinate cross-team with Security Engineering and IT during active incidents to reduce dwell time SecOps Foundation & Enablement - Define and mature the response playbooks, runbooks, and analyst workflows the team runs on - Lead targeted threat hunts informed by intelligence and detection-gap analysis - Own SecOps metrics, reporting, and operational-readiness reviews - Mentor Security Engineers and analysts, and raise the bar for technical judgment and execution across the team QUALIFICATIONS - 6+ years of hands-on Security Operations, detection engineering, or incident response experience, or an equivalent combination of experience and demonstrated ability - Track record leading complex or ambiguous investigations and incidents end-to-end across at least two of: endpoint, cloud, identity, network, or SaaS - Deep hands-on proficiency with enterprise SIEM/XDR query languages for investigation and hunting; able to tune detections and translate front-line findings into detection requirements - Operational EDR expertise to lead hunts, triage, and response using endpoint telemetry - Strong command of attacker TTPs mapped to MITRE ATT&CK, applied during live investigations - Scripting proficiency in Python, PowerShell, or Bash for enrichment, automation, and triage - Strong network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral-movement patterns - Clear, structured communication skills and can brief non-technical stakeholders and be the calm, trusted voice during an incident - Ownership mindset: drives incidents to closure and makes durable, risk-based tradeoff decisions - Experience standing up or maturing SOC capabilities from the ground up - Experience leading purple-team or adversary-emulation exercises to validate and improve coverage - Ability to obtain and maintain a U.S. security clearance Preferred Qualifications - Experience with XDR platforms and cross-domain correlated detection across endpoint, identity, and cloud - Familiarity with cloud-native security operations and log sources in AWS or Azure - Experience with SOAR platforms or building response-automation workflows - Exposure to supply-chain and CI/CD pipeline security monitoring - Familiarity with data lake-based or pipeline-driven detection architectures - Background in defense, aerospace, robotics, or other high-assurance operational environments - Familiarity with compliance frameworks such as NIST SP 800-171 or NIST SP 800-53 - Relevant certifications are a plus but never a gate, including GIAC GCIH, GCIA, GCFA, GCFE, GCDA, GSOM, CySA+, BTL1/2, OSCP, or CISSP - Experience mentoring analysts or setting technical direction for a security operations team - Active security clearance or prior clearance history is a strong differentiator PHYSICAL DEMANDS - Prolonged periods of sitting at a desk and working on a computer - Occasional standing and walking within the office - Manual dexterity to operate a computer keyboard, mouse, and other office equipment - Visual acuity to read screens, documents, and reports - Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies - Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages) BENEFITS Medical Insurance: Comprehensive health insurance plans covering a range of services Saronic pays 100% of the premium for employees and 80% for dependents Dental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision care Saronic pays 100% of the premium under the basic plan for employees and 80% for dependents Time Off: Generous PTO and Holidays Parental Leave: Paid maternity and paternity leave to support new parents Competitive Salary: Industry-standard salaries with opportunities for performance-based bonuse