Nasuni Logo

Nasuni

Senior Security Operations Analyst

Posted An Hour Ago
Be an Early Applicant
Easy Apply
Remote or Hybrid
Hiring Remotely in United States
Senior level
Easy Apply
Remote or Hybrid
Hiring Remotely in United States
Senior level
Lead complex security investigations across endpoint, identity, cloud, email, SaaS, and network environments. Own incidents through containment, remediation coordination, documentation, and post-incident review. Tune detections, queries, dashboards, workflows, and SOAR playbooks; improve SOC metrics, threat coverage, alert fidelity, and response processes. Partner on vulnerability and cloud-risk remediation, participate in global on-call rotation, use approved AI capabilities responsibly, and mentor analysts.
The summary above was generated by AI

United States — Remote

Role Overview

Nasuni is seeking a Senior Security Operations Analyst to strengthen enterprise security operations across cloud, identity, endpoint, email, and collaboration environments. You will independently lead complex investigations, improve detection quality, mature SOC processes, and turn operational data into measurable gains in detection, containment, and response.

This role is for an experienced, hands-on SOC practitioner who has owned incidents and operational improvements in a distributed enterprise or SaaS environment. It is not an entry-level, GRC-only, or advisory-only position.

Level & Scope Definition

You will operate as a senior individual contributor with authority to make incident triage, severity, and escalation decisions within Nasuni’s response framework. You will own cases from signal through containment, remediation coordination, documentation, and post-incident learning; improve detections, playbooks, dashboards, and procedures; and mentor other analysts. You will influence Security, IT, Cloud, Identity, Engineering, and external providers, while enterprise strategy, company-wide policy, and people management remain outside this role.

Responsibilities

  • Lead advanced investigations across endpoint, identity, cloud, email, SaaS, and network telemetry; determine scope, impact, root cause, containment, and follow-up actions.
  • Operate and improve an enterprise security stack that includes Sumo Logic Cloud SIEM, Wiz, Rapid7 InsightIDR and InsightVM/Exposure Command, and Darktrace / EMAIL, or comparable platforms.
  • Build and tune queries, correlation rules, detections, enrichments, threat hunts, dashboards, case workflows, and SOAR playbooks; improve MITRE ATT&CK coverage and reduce false positives.
  • Own the accuracy, reporting, and continuous improvement of SOC measures such as MTTD, MTTC, and MTTR, along with alert fidelity, aged backlog, escalation quality, and SLA attainment.
  • Improve SOC runbooks, incident procedures, severity criteria, escalation paths, analyst handoffs, case documentation, and post-incident review practices.
  • Partner with system owners to prioritize vulnerability and cloud-risk remediation using business context, exploitability, asset criticality, and compensating controls.
  • Use Nasuni-approved AI capabilities to accelerate log analysis, alert enrichment, case summarization, query development, and playbook drafting while validating outputs and protecting sensitive data.
  • Participate in the global on-call rotation and mentor analysts through case reviews, threat scenarios, and practical feedback.

Expected Outcomes

  • Reliable SOC metrics with documented, measurable improvement actions.
  • Consistent high-severity response, including timely escalation, containment, remediation follow-through, and post-incident learning.
  • Stronger detection coverage, alert fidelity, telemetry health, and reusable analyst playbooks.

Must-Have Qualifications

  • 5+ years of security experience, including 3+ years in an enterprise SOC, incident response, or detection-and-response function.
  • Demonstrated ownership of complex or high-severity investigations from triage through containment and remediation coordination.
  • Strong hands-on SIEM experience, including search, correlation, rule tuning, log onboarding, dashboards, and investigation workflows.
  • Experience improving SOC processes and using operational metrics to identify bottlenecks and validate improvement.
  • Working knowledge across cloud security, EDR, identity, vulnerability management, and email security.
  • Clear written and verbal communication with technical and business stakeholders.

Preferred Qualifications

  • Direct hands-on experience with two or more of Sumo Logic, Wiz, Rapid7 InsightIDR/InsightVM, and Darktrace / EMAIL.
  • Detection engineering, SOAR, threat hunting, PowerShell or Python, multi-cloud monitoring, or MDR coordination experience.
  • Responsible use of AI-assisted security or observability workflows with clear validation and data-handling controls.

Ideal Qualifications

  • Measurably improved MTTD, MTTC, MTTR, false-positive rates, backlog health, or response SLA performance.
  • Led post-incident reviews, established reusable SOC operating practices, or coached other analysts.

Experience Guidelines

Typically 5–9 years of relevant experience, with evidence of enterprise-scale ownership weighted more heavily than tenure alone.

Why work at Nasuni?   

As part of our commitment to your well-being, we are pleased to offer comprehensive benefits packages to employees across the US.  Benefits packages generally include:   

  • Best in class employee onboarding and training
  • "Take What You Need” paid time off policy
  • Comprehensive health, dental and vision plans
  • Company-paid life and disability insurance
  • 401(k) and Roth IRA retirement plan
  • Generous employee referral bonuses
  • Flexible remote work policy
  • 10 Paid Holidays
  • Wide array of wellbeing offerings
  • Pre-tax savings accounts with company contributions
  • Great team culture and social activities
  • Collaborative workspaces
  • Free on-site fitness centers and stocked kitchens in select office locations
  • Professional development resources

Compensation Transparency: 

In accordance with U.S. pay transparency laws, Nasuni is committed to providing visibility into compensation for all U.S.-based roles. Click HERE to view our compensation ranges by job grade. Actual compensation will be based on a variety of factors, including a candidate’s experience, skills, education, and work location.

To all recruitment agencies: Nasuni does not accept agency resumes. Please do not forward resumes to our job boards, Nasuni employees or any other company location. Nasuni is not responsible for any fees related to unsolicited resumes.
Nasuni is an equal opportunity employer. The equal employment opportunity policy at Nasuni protects employees and job applicants from discrimination on the bases of race, religion, color, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, family medical history or genetic information, political affiliation, military service, or other non-merit based factors. These protections extend to all management practices and decisions, including recruitment and hiring practices, appraisal systems, promotions, and training and career development programs. 



 

This privacy notice relates to information collected (whether online or offline) by Nasuni Corporation and our corporate affiliates (collectively, “Nasuni”) from or about you in your capacity as a Nasuni employee, independent contractor/service provider or as an applicant for an employment or contractor relationship with Nasuni. 

Similar Jobs at Nasuni

3 Days Ago
Easy Apply
Remote or Hybrid
2 Locations
Easy Apply
Mid level
Mid level
Artificial Intelligence • Big Data • Cloud • Security • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Own commercial and mid-market sales execution across an assigned territory, including prospecting, qualification, discovery, partner engagement, pipeline management, forecasting, presentations, negotiations, and closing net-new business. Build pipeline to at least three times quota, collaborate with VARs and cloud partners, maintain accurate Salesforce records, and translate cloud storage and data infrastructure capabilities into customer business outcomes.
Top Skills: Ai-Enabled Sales ToolsAWSBackup And RecoveryCloud StorageCybersecurityData ProtectionGCPHybrid Cloud InfrastructureMicrosoftNetworkingSaaSSalesforceVirtualization
8 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
Mid level
Mid level
Artificial Intelligence • Big Data • Cloud • Security • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Own and improve vulnerability management across cloud, on-premises, network, and endpoint environments. Responsibilities include scanning, triage, risk-based prioritization, remediation coordination, SLA tracking, exception management, closure validation, asset reconciliation, reporting, incident support, on-call participation, and audit documentation. The role partners with Engineering, SRE, IT, and Infrastructure teams and uses security tooling and AI-assisted workflows to reduce exposure and recurring vulnerabilities.
Top Skills: Api AutomationAWSCmdbQualysRapid7 InsightvmTenableWiz
20 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
Mid level
Mid level
Artificial Intelligence • Big Data • Cloud • Security • Software • Cybersecurity • Infrastructure as a Service (IaaS)
The Technical Account Manager will support enterprise customers, optimize cloud file data platform use, and ensure customer success through technical guidance and collaboration with engineers.
Top Skills: Active DirectoryAWSAzureCifsEsxGainsightGCPJIRALinuxNfsSalesforceSmbVMware

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account