SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Saronic Technologies, a leader in autonomous maritime defense systems, is seeking a Senior Security Operations Analyst to join its growing SecOps team in Austin. This is a foundational role on a team being built from the ground up, offering direct influence on how security operations will scale and mature.
You will serve as a frontline operator in detection and response, monitoring and triaging security alerts across endpoint, cloud, identity, network, and SaaS environments using enterprise SIEM and XDR platforms. Your core responsibilities include performing in-depth alert investigation and root cause analysis, tuning detections to reduce false positives and improve signal fidelity, and leading initial incident response for mid-tier events (contain, eradicate, recover). You'll participate in the on-call rotation, conduct post-incident reviews to identify gaps and drive improvements, and coordinate with Security Engineering and IT during active incidents.
Beyond reactive operations, you'll conduct targeted threat hunts to identify attacker activity missed by automation, help develop and refine response playbooks and runbooks, contribute to detection-as-code pipelines using structured query languages, and mentor junior analysts as the team grows. You'll also support SecOps metrics tracking and operational readiness reviews.
Required qualifications include 3+ years of hands-on experience in Security Operations, detection engineering, or incident response; demonstrated alert triage and investigation across at least two domains (endpoint, cloud, identity, network, SaaS); hands-on proficiency with enterprise SIEM platforms and their query languages; EDR tooling experience; solid understanding of MITRE ATT&CK and attacker TTPs; experience writing detection logic or SOC documentation; scripting proficiency in Python, PowerShell, or Bash; strong network fundamentals knowledge; and clear written and verbal communication skills. Security clearance eligibility is required.
Preferred qualifications include XDR platform experience, cloud-native security operations (AWS/Azure), SOAR platforms, supply chain and CI/CD security monitoring, data lake-based detection architectures, experience in classified or FedRAMP environments, background in defense or aerospace, familiarity with NIST or CMMC frameworks, and relevant certifications (GCIH, GCIA, GCFE, BTL1/2, CySA+, OSCP) or active/prior security clearance.