Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Security Operations Analyst (mid level)

Saronic
CompanySaronic
CategoryOperations & Admin
LocationAustin
RemoteOn-site (inferred)
EmploymentNot stated
LevelMid
SalaryNot stated by the employer
Posted17 Jun 2026
Last verified30 Jul 2026
SourceEmployer career page (ashby)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms. JOB OVERVIEW As a SecOps Analyst at Saronic, you'll be on the front line of our detection and response operations, triaging and investigating security alerts across endpoint, cloud, identity, network, and SaaS telemetry using our SIEM and XDR platforms. You'll run root cause analysis on real events, lead initial response for mid-tier incidents (contain, eradicate, recover), and tune detections to cut down on noise and sharpen what actually matters. Beyond the day-to-day, you'll join the on-call rotation, run targeted threat hunts to catch what automation misses, help build out our playbooks and runbooks, and contribute to post-incident reviews that turn gaps into real improvements. This is an early, formative role on a SecOps team being built from the ground up, so you'll have a direct hand in shaping how we operate, with room to grow across security domains rather than being boxed into one lane. RESPONSIBILITIES Detection & Alert Operations - Monitor and triage security alerts across endpoint, cloud, identity, network, and SaaS telemetry using enterprise SIEM and XDR platforms - Perform in-depth alert investigation and root cause analysis, documenting findings with clear, structured timelines and impact assessments - Tune detections to reduce false positive noise and improve signal fidelity; contribute to detection-as-code pipelines using structured query languages - Operate across multiple detection and visibility platforms as part of a maturing, layered security monitoring ecosystem Incident Response & Investigation - Lead initial incident response for mid-tier events: contain, eradicate, and recover across endpoint, cloud, and identity domains - Participate in the on-call incident rotation and effectively communicate status and findings to the SecOps Lead and relevant stakeholders - Conduct post-incident reviews, identifying gaps in detection, response, and containment and translating them into actionable improvements - Coordinate with Security Engineering and IT during active incidents to accelerate response and reduce dwell time SecOps Foundation & Enablement - Support the SecOps Lead in developing and refining response playbooks, runbooks, and analyst workflow documentation - Conduct targeted threat hunting operations to identify attacker activity not surfaced by automated detections - Contribute to SecOps metrics tracking, reporting, and operational readiness reviews - Help onboard and mentor junior analysts as the team grows, serving as a technical resource and process guide QUALIFICATIONS - 3+ years of hands-on experience in a Security Operations, detection engineering, or incident response role - Demonstrated experience triaging and investigating alerts across at least two of the following: endpoint, cloud, identity, network, or SaaS environments - Hands-on proficiency with enterprise SIEM platforms and their query languages; ability to write and iterate on detection logic from scratch - Experience with EDR tooling in an operational context; ability to hunt, triage, and respond using endpoint telemetry - Solid understanding of attacker TTPs mapped to MITRE ATT&CK, and the ability to apply that knowledge during active investigations - Experience writing or iterating on detection logic, response playbooks, or SOC operational documentation - Scripting proficiency in Python, PowerShell, or Bash for alert enrichment, automation, or triage support - Strong understanding of network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral movement patterns - Clear and structured written and verbal communication — you can brief a non-technical stakeholder and write a thorough incident report - Ownership mindset: you follow incidents through to clos
HOUSE ADYour CV gets thirty seconds.CV writing and honest review. English & Greek.kaeros.app →