Source Job

Australia 12w maternity 12w paternity

  • Triage and investigate intrusions, analyze logs and forensic artifacts to determine root causes.
  • Perform dynamic malware analysis and refine detection capabilities to address emerging threats.
  • Collaborate with product and engineering teams to evolve human-led agentic workflows.

Incident Response Windows Malware Analysis

20 jobs similar to Security Operations Analyst

Jobs ranked by similarity.

$75,600–$97,200/yr
Ireland

  • Triage, investigate, and respond to alerts from the Huntress platform daily.
  • Perform tactical review of EDR telemetry, log sources, and forensic artifacts to determine root causes and provide remediations.
  • Contribute to detection engineering and collaborate with a passionate team dedicated to protecting companies from cyber-attacks.

Huntress is a cybersecurity company founded in 2015 by former NSA cyber operators, providing enterprise-grade cybersecurity to businesses of all sizes. They secure over 5M endpoints and 14M identities worldwide with a 24/7 human-led SOC and a remote-first culture.

Canada

  • Monitor and triage alerts across endpoint, network, cloud, runtime, and identity data sources.
  • Perform structured investigations on escalated or ambiguous alerts to build coherent timelines.
  • Participate in incident response, including evidence collection and containment actions.

AlphaSense provides AI-driven market intelligence and search to help enterprises make informed decisions. The company has over 2,000 employees globally and fosters a culture of innovation and collaboration.

$70,000–$100,000/yr
US Unlimited PTO

  • Monitor SIEM, EDR/XDR, and other security platforms for threats and respond to incidents.
  • Engineer and maintain SIEM integrations, detection rules, and security automation.
  • Collaborate with IT, Engineering, and Product teams to embed security into systems.

$113,800–$139,000/yr
US

  • Monitor, investigate, and respond to security alerts from SIEM, EDR/XDR, IDS/IPS, firewall, cloud, identity, and endpoint security platforms.
  • Perform incident response and threat hunting activities, including alert triage, root cause analysis, containment, and documentation.
  • Analyze endpoint, authentication, firewall, VPN, cloud, and network activity to identify indicators of compromise and suspicious behavior.

Clear Capital is a national real estate analytics, data solutions, and valuation technology company that builds confidence in real estate decisions. The company values integrity, kindness, grit, empathy, attention to detail, and raising the bar.

$122,500–$175,000/yr
USA

  • Perform investigations into detected threats and leverage security products to analyze, contain, and remediate threats in customer environments.
  • Provide customers with thorough reports of actions taken to ensure clarity on environment cleanup and protection strategies.
  • Collaborate with Detection Engineering, Threat Hunting, Intel, and Product teams to develop innovative methods for timely threat remediation.

Zscaler accelerates digital transformation by providing cloud-based security solutions using its Zero Trust Exchange platform. The company fosters a culture of execution, collaboration, and ownership, with a focus on high-impact work.

Unlimited PTO

  • Lead and execute complex digital forensics and incident response investigations across a range of engagement types.
  • Deliver high-quality analysis, client communication, and tailored deliverables for both technical and managerial audiences.
  • Collaborate with peers to improve methodologies, tooling, and automation to respond to emerging threats.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services to help organizations make better decisions and minimize risk. With over 1,300 employees and a focus on collaboration and mentorship, the company serves Fortune 500 companies and government agencies.

$145,000–$155,000/yr
US

  • Participate in all Incident Response activities with deep expertise in Forensic Analysis, including malware detection and reverse engineering.
  • Manage digital evidence chain of custody and perform forensic analysis across networks, hosts, and cloud environments.
  • Collaborate with security leadership to convert forensic insights into detection rules and support threat hunting operations.

Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies and a Best Place to Work, Valiant fosters an employee-centric culture with great benefits and career development opportunities.

United States

  • Analyze, investigate, document, and report on security alerts and potential incidents in customer environments.
  • Serve as an incident coordinator for urgent security events requiring response, containment, and remediation.
  • Stay up-to-date on security training, certifications, and emerging threats while providing security consultation to customers.

CyberSheath is a rapidly growing Managed Security Services Provider offering cybersecurity compliance and threat mitigation for the Defense Industrial Base. The company is expanding its team and fosters a fully remote work environment with a focus on security operations.

$96,798–$125,268/yr
Canada

  • Monitor security events and provide technical analysis on alerts
  • Lead information security incidents as Incident Commander, developing response strategies and coordinating across teams
  • Champion Samsara's cultural principles while delivering security guidance for incident response and insider threat initiatives

Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, a platform that enables organizations to harness IoT data for actionable insights and improved operations. They are a recently public company with a culture that encourages rapid career development and a focus on digitizing large sectors of the global economy.

$123,850–$161,000/yr
US

  • Monitor, detect, and respond to security events across enterprise environments using the SIEM.
  • Build and maintain dashboards, visualizations, and KPIs that demonstrate SIEM effectiveness and security visibility.
  • Use frameworks such as MITRE ATT&CK to contextualize detections and identify coverage gaps.

Horizon3.ai is a fast-growing, remote cybersecurity company that provides production-safe autonomous pentests through its NodeZero platform to organizations of all sizes. We are a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.

Argentina

  • Own end-to-end security incident response, from triage to recovery, and drive post-incident learnings.
  • Build and improve detection coverage across cloud, endpoint, identity, and SaaS systems.
  • Develop security automation and workflows to reduce manual toil and improve response speed.

Front is the customer operations platform for B2B complexity, keeping teams, tools, and conversations in sync. Over 9,000 companies rely on Front, and it's backed by Sequoia Capital and Salesforce Ventures, with a highly recognized workplace culture.

Mexico

  • Lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments.
  • Partner with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents and communicate risk.
  • Support continuous improvement through automation, AI-assisted security workflows, and detection tuning.

Oportun is a mission-driven financial services company that empowers members with intelligent borrowing, savings, and budgeting capabilities. Since inception, it has provided over $21.3 billion in responsible credit and fosters a diverse, equitable, and inclusive culture.

US Unlimited PTO

  • Lead investigation and response for security incidents, suspicious activity, and emerging threats.
  • Design, implement, and improve security monitoring, detection, and response capabilities across AWS.
  • Develop detection rules, conduct post-incident reviews, and partner with teams to strengthen security controls.

CoLab is an AI platform that helps mechanical engineering teams bring life-changing products to market faster by driving stronger engineering decisions. Founded in 2019 and based in St. John's, Newfoundland, CoLab has grown rapidly, earning recognition on Deloitte's Fast 50 and Fast 500 lists.

$172,279–$249,640/yr
US Canada

  • Build and maintain SIEM for log collection and detection rules across corporate and production environments.
  • Design and deploy canary tokens and early warning mechanisms to detect threats before they reach critical assets.
  • Investigate security incidents end-to-end, including malware analysis, exfiltration assessment, and timeline reconstruction.

Quora operates two platforms: a global knowledge sharing platform with over 300M monthly unique visitors, and Poe, a platform for chatting and building with AI language models. The company is privately held, remote-first, and fosters a culture of transparency, collaboration, and experimentation.

$182,000–$182,000/yr
United States

  • Lead deep-dive analysis of ICS-related malware and firmware, developing novel detection methods and Yara signatures.
  • Write persuasive customer-facing technical reports that translate complex malware findings into clear operational impact.
  • Collaborate across teams with hunters, intelligence analysts, and detection engineers to drive malware-related threat research.

Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. They have a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.

$125,560–$173,010/yr
Canada Unlimited PTO

  • Lead and develop a team of security engineers to defend infrastructure, SaaS, and endpoints against real-world adversaries.
  • Own detection and response, including incident command, tuning CrowdStrike, and conducting cybersecurity risk assessments.
  • Drive AI security strategy and partner with cross-functional teams to build robust detection controls.

Forward Financing is a financial technology company that unlocks capital to fuel small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work with a culture focused on empowerment and collaboration.

$205,000–$215,000/yr
US Unlimited PTO

  • Architect the SOC strategy and roadmap, defining threat intelligence operations, detection frameworks, and defensive maturity metrics.
  • Build and tune detection logic across cloud stacks, identity layers, and endpoints, rejecting noise to accelerate incident response velocity.
  • Own incident command, leading containment and recovery operations while driving engineering change through rigorous post-mortems.

Second Front Systems is a public-benefit software company that accelerates secure software development and deployment for government and regulated networks. Founded by national security veterans, the company is a high-growth startup backed by top-tier venture capital with a culture of accountability and technical craft.

$87,400–$131,000/yr
US 4w PTO

  • Support ransomware and cyber extortion engagements by managing threat actor communications and maintaining accurate case documentation.
  • Conduct research on threat actor groups, campaigns, and malware to provide actionable intelligence for active cases.
  • Coordinate with internal teams and external partners to ensure timely and accurate communication throughout engagements.

The company specializes in ransomware and cyber extortion incident response, supporting active engagements. They foster a collaborative remote culture with opportunities for professional growth and development.

Global

  • Monitor, triage, and investigate security incidents across Kraken's infrastructure and client instances.
  • Develop and automate detection capabilities and incident response processes.
  • Collaborate with engineering and product teams to improve security posture and respond to incidents.

We power some of the most innovative global developments in energy by creating technology that redefines utilities. We are a growing global team committed to improving the lives of one billion humans within the decade.

Australia

  • Design and optimize threat detection capabilities using SIEM, SOAR, EDR, and NDR technologies.
  • Develop automation playbooks and cybersecurity data solutions to improve detection accuracy.
  • Collaborate with customer teams to close detection gaps and adapt defenses to emerging threats.

Our partner is a cybersecurity firm focused on building threat detection capabilities for enterprise environments. They foster a collaborative, engineering-led culture with significant autonomy for engineers.