SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Operations Analyst

Anduril - Costa Mesa, CA, United States - In-office - posted 2026-08-21

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 0 - 100,000 / annual

Anduril Industries, a defense technology company, is seeking a Security Operations Analyst to join the Detection and Response team. This role serves as the frontline security watchtower for Anduril's critical defense technologies, monitoring and responding to adversarial activity targeting the company's AI-powered Lattice OS and military systems. Key responsibilities include triaging and responding to security alerts and incidents across multiple disciplines—phishing, endpoints, cloud infrastructure, and SaaS applications. You will build and optimize detection signatures, response playbooks, and automation using detection-as-code principles, working closely with the detection engineering team to reduce false positives and improve alert quality. The role involves threat hunting, data normalization, and analysis across large datasets to identify anomalous patterns in user behavior. You'll participate in on-call incident response rotations, conducting investigations and communicating findings to stakeholders. Senior-level analysts serve as incident commanders. Cross-functional collaboration is essential, working with teams across cloud, mobile, endpoints, and other environments to understand security weaknesses and incorporate findings into controls and detection signatures. Required qualifications include hands-on experience in security monitoring, log analysis, and detection engineering across endpoint, network, and application sources. You must have Python development experience contributing to shared codebases for SOC automation, proficiency with SIEM languages (SPL, KQL, SQL), and experience in data lake environments. Broad practical security knowledge across endpoint, network, identity, application, and cloud infrastructure is essential, along with understanding of attacker tactics and techniques (TTPs) across Windows, Linux, macOS, AWS, and Azure. Strong communication and stakeholder collaboration skills are required. U.S. Top Secret security clearance eligibility is mandatory. Preferred qualifications include cloud incident response experience (AWS, Azure, GCP) and digital forensics or reverse engineering expertise.

Similar roles