> Markdown version of [/jobs/ext/1250924-senior-security-operations-center-analyst](https://www.wearedevelopers.com/jobs/ext/1250924-senior-security-operations-center-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Operations Center Analyst - **Company:** Shutterfly, Inc. - **Location:** Colorado, United States (Remote available) - **Experience:** Expert - **Salary:** $102,000.0 - $141,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Bash Shell, CompTIA Security+, Cyber Security, Computer Programming, Information Leak Prevention, Domain Name System Security Extensions, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Network Intrusion Detection Systems, Packet Analyzer, Open Source Intelligence, Windows PowerShell, Red Team (Cyber Security), Security Information and Event Management, In-Plane Switching (IPS), Mitre Att&ck, Malware, Cybercrime, Purple Team (Cyber Security), Splunk, Blue Team (Cyber Security), Vulnerability Analysis - **Published:** July 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=74cf5afa80ddd22b ## About the Role * Proficient operator of security tools such as endpoint protection/EDR, SIEM, IPS/IDS, HIDS/NIDS, WAFs, Edge/DNS security, vulnerability scanning, malware analysis tools, networking tool for full packet analysis, data loss prevention (DLP), etc. * Hands-on experience developing, tuning, and validating detection content (e.g., SIEM correlation/analytics and EDR detections), and familiarity with a detection framework such as MITRE ATT&CK. * 2+ of the following certifications: CEH, CISM, GIAC, GCIH, GCIA, GSLC, GICSP, GSEC, CEH, GWAP, CompTIA Net+, CompTIA A+, CompTIA Security+, CASP CE, SEC+, Splunk Core, OSCP, etc. * Linux/Unix OS, Windows and Mac administration skills * Intimate understanding of technology and be motivated to constantly learn new technologies. * Strong ability to learn and research new things, including tools, languages, frameworks, etc. It's Not Required But It's Nice To Have: * Programming/scripting experience (bash, python, PowerShell) * Forensics or malware analysis experience ## Description Shutterfly is looking for a Sr. Security Operations Center Analyst (Defensive / Blue Team) to become a key member of our Security Operations Center (SOC) to monitor for malicious activity and act on alerts/detections, as well as investigate, respond (contain/triage/mitigate) and threat hunt. This analyst will collaborate with other members of the team to help simplify, streamline, automate and enhance the overall security capabilities of Shutterfly's Security Operations. This role is highly technical and requires advanced skills in intrusion detection, detection engineering, and threat hunting to identify credible risks/adversaries across all Shutterfly's systems. It centers as much on building, testing, and maintaining high-fidelity detections as it does on responding to them. A key to success for this role will be to collaborate with security engineers, developers, and business units to constantly improve the overall security posture at Shutterfly. How can we apply threat modeling to daily security operations? How can we automate remediation and incorporate human judgement from users at scale? What open-source technology and OSINT can be applied as part of our toolset? If these topics excite you, then this role is for you. What You'll Do Here: * Monitor our alert channels, SIEM/SOAR notifications and EDR/IDS/IPS/DLP solutions for detections/incidents and threat hunt for malicious activity. Investigate, contain, triage and mitigate as needed; as well as continuously tune rules to reduce false positives. * Provide incident response and be a key point of contact during all incidents; which includes investigation, correlation, triage, response, mitigation, ticketing, documentation and postmortem analyses. Note Shutterfly's analysts are empowered to work an alert from start to finish, including any containment, investigation and mitigative actions needed. * Detection Engineering: Design, develop, test, and maintain detection content - treating detections as code where feasible - map detection coverage against a framework such as MITRE ATT&CK, and continuously measure and improve detection fidelity and efficacy over time. * Develop, tune, and validate detections across EDR/IDS/IPS/DLP and SIEM solutions to improve detection, reduce noise, add IOAs, and retire low-value rules. * Purple Team Collaboration: Partner with the offensive/Red Team as the Blue Team counterpart to produce Purple Team outcomes. Use adversary emulation and Red Team findings to build and validate new detections, close coverage gaps, and drive measurable improvements to detection and response based on those findings. * AI-Augmented Operations: Leverage AI and LLM-based technologies to augment analysis and automation across the SOC - accelerating triage and investigation, enriching and correlating alerts, summarizing incidents, and reducing manual toil - while applying sound analyst judgement to validate AI-assisted outputs. * Partner with the Information Security Engineering team to ensure thorough, consistent tool usage and coverage, and to mature monitoring and response capabilities. Build security automation workflows, enrichments, and mitigations that integrate across complex systems and tools. * Evaluate SOC policies and procedures and recommend updates to management where appropriate. * Grow and mature our threat intelligence program - gather, analyze and assess threat intelligence to report on the current and future threat landscape, and provide a realistic overview of risks and threats in the enterprise environment. * Enhance our detection capabilities with correlation, situational awareness and intel enrichment. ## Related Videos - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)