Lead Security Operations Analyst

LEDGENT
Houston, TX, United States
8 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$110,000.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Artificial Intelligence Amazon Web Services Microsoft Antivirus Microsoft Azure Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Intrusion Detection and Prevention Intrusion Detection Systems
+16 more
Python (Programming Language) Linux Security Modules Microsoft Security Essentials Windows PowerShell Azure Active Directory Phishing Kusto Query Language Security Information and Event Management Google Cloud In-Plane Switching (IPS) Mitre Att&ck Spoofing Cybercrime Microsoft Sentinel Security Orchestration, Automation & Response Servicenow

Job description

Our client is seeking a Senior Information Security Analyst to join a mature and growing Security Operations team responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across a global enterprise environment.

This is an opportunity for a hands-on security professional who enjoys leading investigations, mentoring analysts, improving detection capabilities, and helping shape the future of security operations. The ideal candidate will bring deep experience working within Microsoft security technologies and can operate independently in a fast-paced environment with minimal oversight.

The team is heavily invested in security automation, threat detection, Microsoft Sentinel, Microsoft Defender, and AI-enabled security operations, creating an opportunity to contribute to both day-to-day security operations and long-term strategic security initiatives., * Lead investigation and response efforts for complex security incidents across endpoint, cloud, identity, email, and network environments.

  • Monitor, triage, and investigate security alerts generated by SIEM, EDR, and other security monitoring tools.
  • Serve as a technical escalation point and mentor for junior security analysts.
  • Conduct proactive threat hunting activities to identify malicious activity not detected through existing controls.
  • Build, tune, and maintain detection rules, monitoring logic, and security use cases.
  • Support phishing, impersonation, business email compromise, and social engineering investigations.
  • Develop and improve security automation workflows, response playbooks, and SOAR capabilities.
  • Collaborate with security, infrastructure, cloud, and IT teams to strengthen defensive capabilities and improve security posture.
  • Perform forensic analysis and support evidence preservation activities when required.
  • Maintain and improve operational procedures, security documentation, and incident response processes.
  • Participate in an on-call rotation supporting critical security incidents., * Exposure to a large-scale enterprise cybersecurity environment.
  • Opportunities to influence detection, response, and security automation strategies.
  • Access to advanced Microsoft security technologies.
  • Collaborative and highly skilled cybersecurity team environment.
  • Long-term career growth within an established organization.
  • Hands-on involvement in automation, AI-enabled security operations, detection engineering, and threat hunting initiatives.

Requirements

  • 5+ years of experience within Security Operations, Security Engineering, Incident Response, Cybersecurity, or a related discipline.
  • Strong hands-on experience with Microsoft Sentinel and Microsoft Defender.
  • Experience leading security investigations from detection through containment, remediation, and recovery.
  • Working knowledge of SIEM, EDR, IDS/IPS, email security, and threat detection technologies.
  • Experience investigating phishing attacks, account compromise incidents, and identity-based threats.
  • Strong understanding of Microsoft 365, Microsoft Entra ID (Azure AD), Active Directory, and cloud security concepts.
  • Experience utilizing ServiceNow or similar ticketing/service management platforms.
  • Strong written and verbal communication skills.
  • Ability to work independently and take ownership of issues through resolution., Candidates should possess strong expertise in one or more of the following disciplines:
  • Identity & Access Security
  • Cloud Security (Azure, AWS, or Google Cloud Platform)
  • Windows and Linux Security Operations
  • Detection Engineering
  • Security Automation and SOAR
  • Threat Hunting

Additional experience with the following is highly desirable:

  • KQL (Kusto Query Language)
  • PowerShell and/or Python
  • Security automation playbooks
  • MITRE ATT&CK Framework
  • Microsoft Security ecosystem technologies
  • AI-assisted security operations and automation

Preferred Certifications

  • Microsoft SC-200
  • Microsoft SC-300
  • Microsoft AZ-500
  • CompTIA Security+
  • CISSP
  • CCSP
  • GCIH
  • GSOC
  • GCFA
  • GCFE
  • Other cybersecurity and cloud security certifications

Ideal Candidate

The ideal candidate:

  • Thrives in a Security Operations Center (SOC) environment.
  • Can independently manage investigations with minimal oversight.
  • Possesses strong analytical and troubleshooting skills.
  • Enjoys mentoring and developing junior team members.
  • Communicates effectively with both technical and non-technical stakeholders.
  • Takes ownership and follows issues through to resolution.
  • Is passionate about continuous improvement, automation, and security innovation.
  • Works collaboratively within global teams and cross-functional environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

44 sec

Blocking container spoofing attacks by removing raw network access

Mathias Tausig · World Congress 2023

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:26 min

Spear phishing IT administrators with malicious VoIP spoofing

Mauro Verderosa · LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

Videos

See all

Related articles

See all