Saronic Logo

Saronic

Senior Security Operations Analyst

Posted One Month Ago
Be an Early Applicant
In-Office
Austin, TX, USA
Senior level
In-Office
Austin, TX, USA
Senior level
Lead detection and response across endpoint, cloud, identity, network, and SaaS telemetry. Own complex investigations and incident response end-to-end, tune detections, perform threat hunts, develop playbooks/runbooks, mentor analysts, and coordinate cross-team during incidents to reduce dwell time.
The summary above was generated by AI

Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.

Job Overview

Saronic Technologies is a leader in revolutionizing autonomy at sea, developing cutting-edge unmanned surface vessels (USVs) to enhance maritime operations for defense and national security. We're looking for a hands-on Senior Security Engineer to be a technical anchor for our Security Operations team.

You'll lead detection and response across endpoint, cloud, identity, network, and SaaS telemetry, owning the complex and ambiguous investigations end-to-end, partnering closely with Detection Engineering to turn what you see on the front line into better detections, and turning post-incident lessons into durable improvements to our playbooks and runbooks. You'll be a trusted escalation point on the on-call rotation, lead the threat hunts that catch what automation misses, and mentor the engineers around you. This is a formative, high-autonomy role on a SecOps team being built from the ground up, where you'll set the technical bar and help shape how Saronic operates across security domains.

Responsibilities

Detection & Alert Operations

  • Operate across endpoint, cloud, identity, network, and SaaS telemetry in our SIEM and XDR to tune and refine detections in-flight, and be the primary front-line voice driving detection improvements back to Detection Engineering

  • Lead root-cause analysis on complex, novel, or cross-domain events, and structure investigations others can follow

  • Own coverage from the operator's seat and map what you're seeing to MITRE ATT&CK, identify gaps, and set the priorities Detection Engineering builds against

Incident Response & Investigation

  • Lead incident response end-to-end for complex and higher-severity incidents across endpoint, cloud, and identity to contain, eradicate, recover

  • Serve as a trusted escalation point on the on-call rotation, and brief status and impact to security leadership and stakeholders

  • Own post-incident reviews, translating detection, response, and containment gaps into prioritized, durable improvements

  • Coordinate cross-team with Security Engineering and IT during active incidents to reduce dwell time

SecOps Foundation & Enablement

  • Define and mature the response playbooks, runbooks, and analyst workflows the team runs on

  • Lead targeted threat hunts informed by intelligence and detection-gap analysis

  • Own SecOps metrics, reporting, and operational-readiness reviews

  • Mentor Security Engineers and analysts, and raise the bar for technical judgment and execution across the team

Qualifications
  • 6+ years of hands-on Security Operations, detection engineering, or incident response experience, or an equivalent combination of experience and demonstrated ability

  • Track record leading complex or ambiguous investigations and incidents end-to-end across at least two of: endpoint, cloud, identity, network, or SaaS

  • Deep hands-on proficiency with enterprise SIEM/XDR query languages for investigation and hunting; able to tune detections and translate front-line findings into detection requirements

  • Operational EDR expertise to lead hunts, triage, and response using endpoint telemetry

  • Strong command of attacker TTPs mapped to MITRE ATT&CK, applied during live investigations

  • Scripting proficiency in Python, PowerShell, or Bash for enrichment, automation, and triage

  • Strong network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral-movement patterns

  • Clear, structured communication skills and can brief non-technical stakeholders and be the calm, trusted voice during an incident

  • Ownership mindset: drives incidents to closure and makes durable, risk-based tradeoff decisions

  • Experience standing up or maturing SOC capabilities from the ground up

  • Experience leading purple-team or adversary-emulation exercises to validate and improve coverage

  • Ability to obtain and maintain a U.S. security clearance

Preferred Qualifications

  • Experience with XDR platforms and cross-domain correlated detection across endpoint, identity, and cloud

  • Familiarity with cloud-native security operations and log sources in AWS or Azure

  • Experience with SOAR platforms or building response-automation workflows

  • Exposure to supply-chain and CI/CD pipeline security monitoring

  • Familiarity with data lake-based or pipeline-driven detection architectures

  • Background in defense, aerospace, robotics, or other high-assurance operational environments

  • Familiarity with compliance frameworks such as NIST SP 800-171 or NIST SP 800-53

  • Relevant certifications are a plus but never a gate, including GIAC GCIH, GCIA, GCFA, GCFE, GCDA, GSOM, CySA+, BTL1/2, OSCP, or CISSP

  • Experience mentoring analysts or setting technical direction for a security operations team

  • Active security clearance or prior clearance history is a strong differentiator

Physical Demands
  • Prolonged periods of sitting at a desk and working on a computer

  • Occasional standing and walking within the office

  • Manual dexterity to operate a computer keyboard, mouse, and other office equipment

  • Visual acuity to read screens, documents, and reports

  • Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies

  • Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages)

Benefits

Medical Insurance: Comprehensive health insurance plans covering a range of services

Saronic pays 100% of the premium for employees and 80% for dependents

Dental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision care

Saronic pays 100% of the premium under the basic plan for employees and 80% for dependents

Time Off: Generous PTO and Holidays

Parental Leave: Paid maternity and paternity leave to support new parents

Competitive Salary: Industry-standard salaries with opportunities for performance-based bonuses

Retirement Plan: 401(k) plan with company match

Stock Options: Equity options to give employees a stake in the company’s success

Life and Disability Insurance: Basic life insurance and short- and long-term disability coverage

Pet Insurance: Discounted pet insurance options including 24/7 Telehealth helpline

Additional Perks: Free lunch benefit and unlimited free drinks and snacks in the office

Saronic CCPA Notice for Candidates and California Employees

If this role is based in the United States, it requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).
Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits. We are also committed to providing reasonable accommodations for qualified individuals with disabilities.

HQ

Saronic Austin, Texas, USA Office

Austin, TX, United States

Similar Jobs

17 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
Senior level
Senior level
Artificial Intelligence • Big Data • Cloud • Security • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Lead complex security investigations across endpoint, identity, cloud, email, SaaS, and network environments. Own incidents through containment, remediation coordination, documentation, and post-incident review. Tune detections, queries, dashboards, workflows, and SOAR playbooks; improve SOC metrics, threat coverage, alert fidelity, and response processes. Partner on vulnerability and cloud-risk remediation, participate in global on-call rotation, use approved AI capabilities responsibly, and mentor analysts.
Top Skills: Cloud SecurityDarktrace EmailEdrEmail SecurityIdentity SecurityMitre Att&CkPowershellPythonRapid7 Exposure CommandRapid7 InsightidrRapid7 InsightvmSIEMSoarSumo Logic Cloud SiemVulnerability ManagementWiz
Junior
Financial Services
Provides comprehensive financial planning and investment advice to individuals and families, builds and manages a client book of business, develops personalized investment solutions, acquires and deepens client relationships, and educates clients on digital banking and investment tools. The role requires bilingual English and Spanish communication, active securities and insurance licenses, strong financial market knowledge, and relationship-focused business development.
40 Minutes Ago
Remote or Hybrid
United States
66K-89K Annually
Junior
66K-89K Annually
Junior
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Performs cybersecurity consulting engagements including vulnerability assessments, social engineering exercises, penetration testing, risk analysis, remediation recommendations, reporting, and client presentations. Coordinates engagement activities, monitors scope and budgets, documents findings, supports service development and sales opportunities, and mentors junior consultants. The role assesses networks, applications, cloud configurations, infrastructure, and employee awareness while maintaining current cybersecurity knowledge and pursuing relevant certifications.
Top Skills: Burp SuiteCloud ComputingNessus ProfessionalNetwork SecurityNipper StudioNmapOsintPhishing SimulationsSaaSTcp/IpTenable Vulnerability ManagementVirtualizationVulnerability AssessmentWireshark

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account