Robert Half
Robert HalfVerified Source

Security Analyst, Cloud Security Operations

45K–50K
Onsite · San Francisco, California
Posted August 12, 2026
contract

Overview

You will own threat detection and incident response for cloud-based workloads at a growing fintech. You will triage alerts, hunt for malicious activity, and tune detections across AWS and Azure. You will partner with engineering and IT to reduce risk and improve response workflows. This role stands out for its emphasis on building detection content and automating response with Python and Splunk.

What You'll Do8

  • 1Triage security alerts from Splunk and CrowdStrike within 15 minutes of notification.
  • 2Investigate suspected intrusions and phishing attempts across AWS and Azure workloads.
  • 3Hunt for adversary behavior using MITRE ATT&CK framework on endpoint and network telemetry.
  • 4Tune detection rules in Splunk and Microsoft Defender to reduce false positives by 20%.
  • 5Automate alert enrichment with Python scripts that pull threat intel from VirusTotal.
  • 6Document incident timelines and root cause analysis in Jira for leadership reviews.
  • 7Partner with cloud engineers to implement AWS GuardDuty and Azure Sentinel best practices.
  • 8Conduct weekly threat briefings to update the security team on new TTPs and mitigations.

Requirements8

  • 13+ years in security operations or incident response roles.
  • 2Hands-on experience with Splunk or Elastic Stack for log analysis and querying.
  • 3Proficiency in Python for scripting and automation of security tasks.
  • 4Familiarity with AWS or Azure security services, such as CloudTrail or Azure Security Center.
  • 5Knowledge of MITRE ATT&CK framework and common attack vectors.
  • 6Experience with CrowdStrike or Microsoft Defender endpoint detection and response tools.
  • 7Ability to work onsite in San Francisco 3 days per week.
  • 8Security+ or CISSP certification is a plus.

Salary Insight

$45 - $50k per year

Location

Typeonsite
LocationSan Francisco, California

Required Skills

splunkcrowdstrikeawspythonjira
Share:

Similar open positions

Explore active roles that match your skills and interests.

Dexperts Inc

Dexperts Inc

2h agoSan Francisco, Californiacontract

Senior Security Operations Engineer, Incident Response

Senior Security Operations Engineer owns incident response and security monitoring across a global infrastructure. You will partner with Engineering, IT, Legal, and Business leaders to reduce risk and raise the security bar. Build durable systems and playbooks, not just fight fires. This hybrid role in San Francisco offers the chance to shape security strategy in a fast-scaling company.

Competitive salary
splunkawspython+2 more
AssetMark Financial Holdings, Inc.

AssetMark Financial Holdings, Inc.

12d agoAtlanta, Georgiapayroll

Security Engineer II - Cloud & IAM | AssetMark

You will own security operations for AssetMark's hybrid cloud environment, protecting AWS and Azure workloads and IAM infrastructure. You will work alongside engineering teams to embed security into the software development lifecycle, integrating CrowdStrike Falcon, Check Point Harmony, and Microsoft Defender. Your role focuses on incident response, vulnerability management, and threat modeling for key products. This position stands out for its hybrid schedule and direct impact on securing a leading advisor platform.

Competitive salary
AWSAzurePowerShell+9 more
BCforward

BCforward

22h agoPhoenix, Arizonapayroll

Cyber Security Engineer, SOC & Incident Response

Own security monitoring and incident response for a Fortune 500 client in Phoenix, AZ. You will join BCforward's security operations team, working onsite to detect, investigate, and mitigate threats across a hybrid cloud and on-premise environment. This role demands hands-on expertise with SIEM platforms and EDR tools, with a direct impact on the client's security posture.

135K–146K
splunkcrowdstrikeaws+2 more
Visionaire Partners

Visionaire Partners

22h agoAtlanta, Georgiapayroll

Senior Cybersecurity Engineer, Cloud Security

You will spearhead defensive operations, threat detection, and risk mitigation across complex enterprise networks, AWS and Azure, and endpoint environments. You will design security tool architecture to harden system baselines and drive security posture across cloud and containerized infrastructure. Your stack includes SIEM, EDR, CSPM, and IaC tools. You will partner with DevOps and network teams to embed security into the build pipeline. This role puts you at the center of security strategy for a critical infrastructure provider.

100K–147K
defensive operationsthreat detectionrisk mitigation+7 more
Deloitte

Deloitte

1d agoAtlanta, Georgiapayroll

Lead Cloud Security Analyst, Azure & AWS

Own cloud security architecture and risk remediation for Deloitte's global infrastructure. You will drive embedded collaboration, shape scalable solutions with Azure, AWS, and GCP, and serve as a technical authority across cyber and engineering teams. Join a 3,000-person technology organization protecting data for the world's largest firms. This role offers direct influence on zero trust adoption and incident response at enterprise scale.

102K–211K
azureawsgcp+2 more
Innova Solutions, Inc

Innova Solutions, Inc

22h agoCharlotte, North Carolinacontract

Cyber Security Research Consultant

You will own cyber security research initiatives at a large financial client, delivering threat intelligence that shapes security strategy. Working within a team of security analysts and engineers, you will analyze attack patterns, assess vulnerabilities, and produce actionable reports. This contract role demands deep technical expertise in cyber security and a proven record of solving complex security challenges. You will directly influence security controls and incident response, making an immediate impact in a high-stakes environment.

Competitive salary
pythonawsazure+2 more