JOBSEARCHER

Security Operations Analyst

Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.Job OverviewSaronic Technologies is a leader in revolutionizing autonomy at sea, developing cutting-edge unmanned surface vessels (USVs) to enhance maritime operations for defense and national security. We're looking for a hands-on Security Engineer to join our Security Operations team on the front line of detection and response.You'll triage and investigate security alerts across endpoint, cloud, identity, network, and SaaS telemetry using our SIEM and XDR platforms, run root-cause analysis on real events, and own initial response for well-scoped incidents to contain, eradicate, recover. You'll tune detections to cut noise, join the on-call rotation, run targeted threat hunts, and contribute to the playbooks and post-incident reviews that make the team better. This is an early, formative role on a SecOps team being built from the ground up, with senior engineers to learn from and real room to grow across security domains rather than being boxed into one lane.ResponsibilitiesDetection & Alert OperationsMonitor and triage alerts across endpoint, cloud, identity, network, and SaaS telemetry using enterprise SIEM and XDR platformsInvestigate alerts and perform root-cause analysis, documenting clear timelines and impact assessmentsTune existing detections to reduce false positives, and surface gaps and tuning needs to Detection EngineeringIncident Response & InvestigationOwn initial response for well-scoped, mid-tier incidents across endpoint, cloud, and identity to contain, eradicate, recoverParticipate in the on-call rotation and communicate status and findings to security leadership and stakeholdersContribute to post-incident reviews, surfacing gaps in detection, response, and containmentCoordinate with Security Engineering and IT during active incidents to accelerate responseSecOps Foundation & EnablementSupport security leadership and senior engineers in building response playbooks, runbooks, and analyst workflow documentationRun targeted threat hunts to find activity that automated detections missContribute to SecOps metrics, reporting, and operational-readiness reviewsGrow your depth across detection, investigation, and hunting as the team scalesQualifications2–5 years of hands-on Security Operations, alert triage/SOC, or incident response experience, or an equivalent combination of experience and demonstrated ability; we are open to strong early-career talentExperience triaging and investigating alerts across at least two of: endpoint, cloud, identity, network, or SaaSWorking proficiency with an enterprise SIEM platform and its query language; able to write investigative queries and tune existing detectionsHands-on experience with EDR tooling to triage, hunt, and respond using endpoint telemetrySolid understanding of attacker TTPs mapped to MITRE ATT&CK, applied during investigationsScripting proficiency in Python, PowerShell, or Bash for enrichment, automation, or triageStrong network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral-movement patternsClear, structured written and verbal communication skills and can brief a non-technical stakeholder and write a thorough incident reportOwnership mindset: follows incidents through to closure and flags what needs fixing, not just what needs documentingHands-on learning signals such as a home lab, CTF participation, personal detection/hunting projects, or public writeups/blogsInternship, rotational, or help-desk-to-SOC experience with a clear security operations trajectoryAbility to obtain and maintain a U.S. security clearancePreferred QualificationsExperience with XDR platforms and cross-domain correlated detection across endpoint, identity, and cloudFamiliarity with cloud-native security operations and log sources in AWS or AzureExperience with SOAR platforms or building response-automation workflowsExposure to supply-chain and CI/CD pipeline security monitoringFamiliarity with data lake-based or pipeline-driven detection architecturesBackground in defense, aerospace, robotics, or other high-assurance operational environmentsFamiliarity with compliance frameworks such as NIST SP 800-171 or NIST SP 800-53Relevant certifications are a plus but never a gate, including GIAC GCIH, GCIA, GCFA, GCFE, GCDA, GSOM, CySA+, BTL1/2, OSCP, or CISSPActive security clearance or prior clearance history is a strong differentiatorPhysical DemandsProlonged periods of sitting at a desk and working on a computerOccasional standing and walking within the officeManual dexterity to operate a computer keyboard, mouse, and other office equipmentVisual acuity to read screens, documents, and reportsOccasional reaching, bending, or stooping to access file drawers, cabinets, or office suppliesLifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages)BenefitsMedical Insurance: Comprehensive health insurance plans covering a range of servicesSaronic pays 100% of the premium for employees and 80% for dependentsDental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision careSaronic pays 100% of the premium under the basic plan for employees and 80% for dependentsTime Off: Generous PTO and HolidaysParental Leave: Paid maternity and paternity leave to support new parentsCompetitive Salary: Industry-standard salaries with opportunities for performance-based bonusesRetirement Plan: 401(k) plan with company matchStock Options: Equity options to give employees a stake in the company’s successLife and Disability Insurance: Basic life insurance and short- and long-term disability coveragePet Insurance: Discounted pet insurance options including 24/7 Telehealth helplineAdditional Perks: Free lunch benefit and unlimited free drinks and snacks in the officeSaronic CCPA Notice for Candidates and California EmployeesIf this role is based in the United States, it requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits. We are also committed to providing reasonable accommodations for qualified individuals with disabilities.