SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Operations Analyst

Anduril - Seattle, WA, United States - In-office - posted 2026-08-21

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 129,000 - 171,000 / annual

Anduril Industries, a defense technology company, is seeking a Security Operations Analyst to join the Detection and Response team. This role serves as a critical watchtower for Anduril's advanced defense technologies, monitoring and responding to adversarial activity targeting the company's AI-powered Lattice OS and military systems. Key responsibilities include triaging and responding to security alerts and incidents across multiple domains: phishing, endpoints, cloud infrastructure, and SaaS applications. You will build and optimize detection signatures and response playbooks using detection-as-code principles, working closely with the detection engineering team to reduce false positives and improve alert quality. The role involves conducting threat hunting and data normalization operations to identify anomalies in user behavior and security patterns. You will participate in threat modeling scenarios with cross-functional partners to identify weaknesses across cloud, mobile, endpoint, and other environments, translating findings into security controls and detection signatures. An on-call rotation is required for incident response investigations, with clear communication of findings to stakeholders. Senior-level analysts serve as incident commanders as needed. Required qualifications include hands-on experience in security monitoring, log analysis, and detection engineering across large datasets (endpoint, network, and application logs). You must have Python development experience contributing to shared codebases for SOC automation, proficiency with at least one SIEM language (SPL, KQL, SQL), and experience in data lake environments. Broad practical security knowledge across endpoint, network, identity, application, and cloud infrastructure is essential, along with understanding of attacker tactics and techniques (TTPs) across Windows, Linux, macOS, AWS, and Azure. Strong communication and stakeholder collaboration skills are required. U.S. Top Secret security clearance eligibility is mandatory. Preferred qualifications include cloud incident response experience (AWS, Azure, GCP) and digital forensics or reverse engineering expertise.

Similar roles