{"schemaVersion":"jobsearcher.job.v1","id":"a5a4a2ea10047cc3d399eb5f","url":"https://jobsearcher.com/jobs/a5a4a2ea10047cc3d399eb5f","canonicalUrl":"https://jobsearcher.com/jobs/a5a4a2ea10047cc3d399eb5f","title":"Lead Security Operations Analyst","description":"Title: Lead Security Operations Analyst\n\nLocation: Houston, TX or Austin, TX (Must reside locally for occasional in-person office meetings; otherwise offers work-from-home flexibility)\n\nEmployment Type: Full-Time\n\nIndustry: Professional Services / Enterprise Environment\n\nCompensation: $110,000 - 150,000 + Comprehensive Benefits Package\n\nNo C2C at this time\n\nOverview\n\nOur client is seeking a Senior Information Security Analyst to join a mature and growing Security Operations team responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across a global enterprise environment.\n\nThis is an opportunity for a hands-on security professional who enjoys leading investigations, mentoring analysts, improving detection capabilities, and helping shape the future of security operations. The ideal candidate will bring deep experience working within Microsoft security technologies and can operate independently in a fast-paced environment with minimal oversight.\n\nThe team is heavily invested in security automation, threat detection, Microsoft Sentinel, Microsoft Defender, and AI-enabled security operations, creating an opportunity to contribute to both day-to-day security operations and long-term strategic security initiatives.\n\nResponsibilities\nLead investigation and response efforts for complex security incidents across endpoint, cloud, identity, email, and network environments.\nMonitor, triage, and investigate security alerts generated by SIEM, EDR, and other security monitoring tools.\nServe as a technical escalation point and mentor for junior security analysts.\nConduct proactive threat hunting activities to identify malicious activity not detected through existing controls.\nBuild, tune, and maintain detection rules, monitoring logic, and security use cases.\nSupport phishing, impersonation, business email compromise, and social engineering investigations.\nDevelop and improve security automation workflows, response playbooks, and SOAR capabilities.\nCollaborate with security, infrastructure, cloud, and IT teams to strengthen defensive capabilities and improve security posture.\nPerform forensic analysis and support evidence preservation activities when required.\nMaintain and improve operational procedures, security documentation, and incident response processes.\nParticipate in an on-call rotation supporting critical security incidents.\nRequired Qualifications\n5+ years of experience within Security Operations, Security Engineering, Incident Response, Cybersecurity, or a related discipline.\nStrong hands-on experience with Microsoft Sentinel and Microsoft Defender.\nExperience leading security investigations from detection through containment, remediation, and recovery.\nWorking knowledge of SIEM, EDR, IDS/IPS, email security, and threat detection technologies.\nExperience investigating phishing attacks, account compromise incidents, and identity-based threats.\nStrong understanding of Microsoft 365, Microsoft Entra ID (Azure AD), Active Directory, and cloud security concepts.\nExperience utilizing ServiceNow or similar ticketing/service management platforms.\nStrong written and verbal communication skills.\nAbility to work independently and take ownership of issues through resolution.\nPreferred Qualifications\n\nCandidates should possess strong expertise in one or more of the following disciplines:\n\nIdentity & Access Security\nCloud Security (Azure, AWS, or GCP)\nWindows and Linux Security Operations\nDetection Engineering\nSecurity Automation and SOAR\nThreat Hunting\n\nAdditional experience with the following is highly desirable:\n\nKQL (Kusto Query Language)\nPowerShell and/or Python\nSecurity automation playbooks\nMITRE ATT&CK Framework\nMicrosoft Security ecosystem technologies\nAI-assisted security operations and automation\nPreferred Certifications\nMicrosoft SC-200\nMicrosoft SC-300\nMicrosoft AZ-500\nCompTIA Security+\nCISSP\nCCSP\nGCIH\nGSOC\nGCFA\nGCFE\nOther cybersecurity and cloud security certifications\nIdeal Candidate\n\nThe ideal candidate:\n\nThrives in a Security Operations Center (SOC) environment.\nCan independently manage investigations with minimal oversight.\nPossesses strong analytical and troubleshooting skills.\nEnjoys mentoring and developing junior team members.\nCommunicates effectively with both technical and non-technical stakeholders.\nTakes ownership and follows issues through to resolution.\nIs passionate about continuous improvement, automation, and security innovation.\nWorks collaboratively within global teams and cross-functional environments.\nWhat You'll Gain\nExposure to a large-scale enterprise cybersecurity environment.\nOpportunities to influence detection, response, and security automation strategies.\nAccess to advanced Microsoft security technologies.\nCollaborative and highly skilled cybersecurity team environment.\nLong-term career growth within an established organization.\nHands-on involvement in automation, AI-enabled security operations, detection engineering, and threat hunting initiatives.\n\nAll qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status. We consider all qualified applicants, including those with criminal histories, in a manner consistent with state and local laws, including the California Fair Chance Act, City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, Los Angeles County Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.","company":"Ledgent Technology","rawCompany":"ledgent technology","city":"Houston","state":"TX","isRemote":false,"isActive":false,"createdAt":"2026-08-27T09:56:01.220Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Lead Security Operations Analyst","description":"Title: Lead Security Operations Analyst\n\nLocation: Houston, TX or Austin, TX (Must reside locally for occasional in-person office meetings; otherwise offers work-from-home flexibility)\n\nEmployment Type: Full-Time\n\nIndustry: Professional Services / Enterprise Environment\n\nCompensation: $110,000 - 150,000 + Comprehensive Benefits Package\n\nNo C2C at this time\n\nOverview\n\nOur client is seeking a Senior Information Security Analyst to join a mature and growing Security Operations team responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across a global enterprise environment.\n\nThis is an opportunity for a hands-on security professional who enjoys leading investigations, mentoring analysts, improving detection capabilities, and helping shape the future of security operations. The ideal candidate will bring deep experience working within Microsoft security technologies and can operate independently in a fast-paced environment with minimal oversight.\n\nThe team is heavily invested in security automation, threat detection, Microsoft Sentinel, Microsoft Defender, and AI-enabled security operations, creating an opportunity to contribute to both day-to-day security operations and long-term strategic security initiatives.\n\nResponsibilities\nLead investigation and response efforts for complex security incidents across endpoint, cloud, identity, email, and network environments.\nMonitor, triage, and investigate security alerts generated by SIEM, EDR, and other security monitoring tools.\nServe as a technical escalation point and mentor for junior security analysts.\nConduct proactive threat hunting activities to identify malicious activity not detected through existing controls.\nBuild, tune, and maintain detection rules, monitoring logic, and security use cases.\nSupport phishing, impersonation, business email compromise, and social engineering investigations.\nDevelop and improve security automation workflows, response playbooks, and SOAR capabilities.\nCollaborate with security, infrastructure, cloud, and IT teams to strengthen defensive capabilities and improve security posture.\nPerform forensic analysis and support evidence preservation activities when required.\nMaintain and improve operational procedures, security documentation, and incident response processes.\nParticipate in an on-call rotation supporting critical security incidents.\nRequired Qualifications\n5+ years of experience within Security Operations, Security Engineering, Incident Response, Cybersecurity, or a related discipline.\nStrong hands-on experience with Microsoft Sentinel and Microsoft Defender.\nExperience leading security investigations from detection through containment, remediation, and recovery.\nWorking knowledge of SIEM, EDR, IDS/IPS, email security, and threat detection technologies.\nExperience investigating phishing attacks, account compromise incidents, and identity-based threats.\nStrong understanding of Microsoft 365, Microsoft Entra ID (Azure AD), Active Directory, and cloud security concepts.\nExperience utilizing ServiceNow or similar ticketing/service management platforms.\nStrong written and verbal communication skills.\nAbility to work independently and take ownership of issues through resolution.\nPreferred Qualifications\n\nCandidates should possess strong expertise in one or more of the following disciplines:\n\nIdentity & Access Security\nCloud Security (Azure, AWS, or GCP)\nWindows and Linux Security Operations\nDetection Engineering\nSecurity Automation and SOAR\nThreat Hunting\n\nAdditional experience with the following is highly desirable:\n\nKQL (Kusto Query Language)\nPowerShell and/or Python\nSecurity automation playbooks\nMITRE ATT&CK Framework\nMicrosoft Security ecosystem technologies\nAI-assisted security operations and automation\nPreferred Certifications\nMicrosoft SC-200\nMicrosoft SC-300\nMicrosoft AZ-500\nCompTIA Security+\nCISSP\nCCSP\nGCIH\nGSOC\nGCFA\nGCFE\nOther cybersecurity and cloud security certifications\nIdeal Candidate\n\nThe ideal candidate:\n\nThrives in a Security Operations Center (SOC) environment.\nCan independently manage investigations with minimal oversight.\nPossesses strong analytical and troubleshooting skills.\nEnjoys mentoring and developing junior team members.\nCommunicates effectively with both technical and non-technical stakeholders.\nTakes ownership and follows issues through to resolution.\nIs passionate about continuous improvement, automation, and security innovation.\nWorks collaboratively within global teams and cross-functional environments.\nWhat You'll Gain\nExposure to a large-scale enterprise cybersecurity environment.\nOpportunities to influence detection, response, and security automation strategies.\nAccess to advanced Microsoft security technologies.\nCollaborative and highly skilled cybersecurity team environment.\nLong-term career growth within an established organization.\nHands-on involvement in automation, AI-enabled security operations, detection engineering, and threat hunting initiatives.\n\nAll qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status. We consider all qualified applicants, including those with criminal histories, in a manner consistent with state and local laws, including the California Fair Chance Act, City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, Los Angeles County Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.","datePosted":"2026-08-27T09:56:01.220Z","dateModified":"2026-08-27T09:56:01.220Z","hiringOrganization":{"@type":"Organization","name":"Ledgent Technology","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Houston","addressRegion":"TX","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"a5a4a2ea10047cc3d399eb5f"},"url":"https://jobsearcher.com/jobs/a5a4a2ea10047cc3d399eb5f"}}