Security Analyst, Cloud Security Operations
Overview
You will own threat detection and incident response for cloud-based workloads at a growing fintech. You will triage alerts, hunt for malicious activity, and tune detections across AWS and Azure. You will partner with engineering and IT to reduce risk and improve response workflows. This role stands out for its emphasis on building detection content and automating response with Python and Splunk.
What You'll Do8
- 1Triage security alerts from Splunk and CrowdStrike within 15 minutes of notification.
- 2Investigate suspected intrusions and phishing attempts across AWS and Azure workloads.
- 3Hunt for adversary behavior using MITRE ATT&CK framework on endpoint and network telemetry.
- 4Tune detection rules in Splunk and Microsoft Defender to reduce false positives by 20%.
- 5Automate alert enrichment with Python scripts that pull threat intel from VirusTotal.
- 6Document incident timelines and root cause analysis in Jira for leadership reviews.
- 7Partner with cloud engineers to implement AWS GuardDuty and Azure Sentinel best practices.
- 8Conduct weekly threat briefings to update the security team on new TTPs and mitigations.
Requirements8
- 13+ years in security operations or incident response roles.
- 2Hands-on experience with Splunk or Elastic Stack for log analysis and querying.
- 3Proficiency in Python for scripting and automation of security tasks.
- 4Familiarity with AWS or Azure security services, such as CloudTrail or Azure Security Center.
- 5Knowledge of MITRE ATT&CK framework and common attack vectors.
- 6Experience with CrowdStrike or Microsoft Defender endpoint detection and response tools.
- 7Ability to work onsite in San Francisco 3 days per week.
- 8Security+ or CISSP certification is a plus.
Salary Insight
$45 - $50k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

Dexperts Inc
VerifiedSenior Security Operations Engineer, Incident Response
Senior Security Operations Engineer owns incident response and security monitoring across a global infrastructure. You will partner with Engineering, IT, Legal, and Business leaders to reduce risk and raise the security bar. Build durable systems and playbooks, not just fight fires. This hybrid role in San Francisco offers the chance to shape security strategy in a fast-scaling company.
AssetMark Financial Holdings, Inc.
VerifiedSecurity Engineer II - Cloud & IAM | AssetMark
You will own security operations for AssetMark's hybrid cloud environment, protecting AWS and Azure workloads and IAM infrastructure. You will work alongside engineering teams to embed security into the software development lifecycle, integrating CrowdStrike Falcon, Check Point Harmony, and Microsoft Defender. Your role focuses on incident response, vulnerability management, and threat modeling for key products. This position stands out for its hybrid schedule and direct impact on securing a leading advisor platform.

BCforward
VerifiedCyber Security Engineer, SOC & Incident Response
Own security monitoring and incident response for a Fortune 500 client in Phoenix, AZ. You will join BCforward's security operations team, working onsite to detect, investigate, and mitigate threats across a hybrid cloud and on-premise environment. This role demands hands-on expertise with SIEM platforms and EDR tools, with a direct impact on the client's security posture.

Visionaire Partners
VerifiedSenior Cybersecurity Engineer, Cloud Security
You will spearhead defensive operations, threat detection, and risk mitigation across complex enterprise networks, AWS and Azure, and endpoint environments. You will design security tool architecture to harden system baselines and drive security posture across cloud and containerized infrastructure. Your stack includes SIEM, EDR, CSPM, and IaC tools. You will partner with DevOps and network teams to embed security into the build pipeline. This role puts you at the center of security strategy for a critical infrastructure provider.
Deloitte
VerifiedLead Cloud Security Analyst, Azure & AWS
Own cloud security architecture and risk remediation for Deloitte's global infrastructure. You will drive embedded collaboration, shape scalable solutions with Azure, AWS, and GCP, and serve as a technical authority across cyber and engineering teams. Join a 3,000-person technology organization protecting data for the world's largest firms. This role offers direct influence on zero trust adoption and incident response at enterprise scale.

Innova Solutions, Inc
VerifiedCyber Security Research Consultant
You will own cyber security research initiatives at a large financial client, delivering threat intelligence that shapes security strategy. Working within a team of security analysts and engineers, you will analyze attack patterns, assess vulnerabilities, and produce actionable reports. This contract role demands deep technical expertise in cyber security and a proven record of solving complex security challenges. You will directly influence security controls and incident response, making an immediate impact in a high-stakes environment.