About the role
Our Austin command centre runs one leg of a 24/7 follow-the-sun security operation. As an analyst you are the first decision-maker on live detections — investigating, escalating and containing against response times written into client service level agreements.
What you'll do
- Triage and investigate detections across client environments
- Contain confirmed incidents and hand off with complete context
- Tune detections to remove recurring false positives
- Contribute to threat-hunting campaigns between incidents
- Document findings clearly enough for a client executive to act on
What we're looking for
- 2+ years in a SOC, incident response or detection engineering role
- Working knowledge of MITRE ATT&CK and modern SIEM tooling
- Comfort reading logs across cloud, endpoint and identity sources
- Clear written communication under time pressure
- Willingness to work a rotating shift pattern