> Markdown version of [/jobs/ext/2312725-security-operations-analyst](https://www.wearedevelopers.com/jobs/ext/2312725-security-operations-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Analyst - **Company:** enVista LLC - **Location:** Carmel-by-the-Sea, CA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Internet Security, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Microsoft Security Essentials, Microsoft Software, PCI Data Security Standards, Phishing, Data Logging, Scripting, Software Security, Information Technology, Microsoft Sentinel, Vulnerability Analysis - **Published:** August 30, 2026 - **Apply:** https://www.careerbuilder.com/job-details/sr-security-operations-analyst-carmel-in--b2960ea2-f7a0-4f37-8b7c-7ed807e844ad ## About the Role * Bachelor's degree in Cybersecurity, Information Technology or equivalent practical experience * 5-8 years of relevant cybersecurity experience, including substantial hands-on security operations or incident response responsibility * Demonstrated experience independently leading complex investigations and response activities * Experience with Microsoft Defender, Microsoft Sentinel, Entra ID, Azure security technologies, and the Microsoft security ecosystem * Experience with cloud security monitoring and cloud security posture management technologies * Familiarity with SOC 2, ISO 27001, NIST Cybersecurity Framework, PCI DSS, and related compliance frameworks * Experience supporting or governing third-party managed security service providers * Experience with phishing simulations, security awareness campaigns, and related communications * Relevant certifications such as Security+, CySA+, GSEC, SC-200, GCIH, GCIA, GCED, GMON, AZ-500, CISSP, or equivalent demonstrated expertise are strongly preferred * Experience developing detections, automations, operational improvements, or security workflows * Experience presenting technical findings and risk information to clients, business leaders, and technical teams * Strong understanding of threat detection, incident response methodologies, and security operations practices * This role will be based in our Carmel office in a hybrid capacity, Analysis Skills, Applications Security, Automation, CISSP - Certified Information Systems Security Professional, Campaigns, Cloud Computing, Communication Skills, CompTIA Security+, Computer Security, Consulting, Documentation, Ecosystems, GCIA - GIAC Certified Intrusion Analyst, GCIH - GIAC Certified Incident Handler, GSEC - GIAC Security Essentials Certification, ISO (International Organization for Standardization), Incident Response, Information Technology & Information Systems, Insurance, Internet Security, Mentoring, Microsoft Product Family, Microsoft Windows Azure, Operational Audit, Operational Improvement, PCI-DSS, Phishing, Problem Solving Skills, Profit & Loss, Protective Services, Quality Management, Risk, Robotics, Root Cause Analysis, Scripting (Scripting Languages), Security Analysis, Security Infrastructure, Security Monitoring, Service Delivery, Supply Chain, Technical Leadership, Technical Presentation, Technical Strategy, Technical Support, Testing, Thought Leadership, Time Management, U.S. National Institute of Standards and Technology (NIST) ## Description * Independently lead complex investigations involving multiple systems, technologies, data sources, or security domains. * Correlate endpoint, identity, network, cloud, email, application, and threat intelligence data to determine incident scope, cause, impact, confidence, and required response. * Coordinate technical response activities for significant security incidents and provide timely stakeholder communications. * Conduct root cause analysis and develop practical corrective and preventive recommendations. * Develop, tune, test, and document security detections, correlation rules, investigative procedures, and response playbooks. * Develop scripts, queries, integrations, and workflow automation that improve investigation quality, response time, and service consistency. * Lead vulnerability analysis and risk-based remediation discussions with system owners, clients, and technical teams. * Lead technical discussions with clients and translate findings into clear business and risk implications. * Review analyst investigations, reports, case documentation, and recommendations for quality, accuracy, and completeness. * Mentor analysts and provide technical guidance during investigations, escalations, and operational initiatives. * Serve as the operational owner for an assigned security platform, process, service component, procedure, or technical capability. * Identify material gaps in logging, monitoring, detection coverage, response procedures, or service delivery and lead corrective improvements. * Operates independently with minimal oversight. * Demonstrates advanced technical expertise across multiple security domains. * Exercises strong risk-based judgment and communicates recommendations clearly. * Serves as a trusted technical resource, reviewer, and mentor. ## Related Videos - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)