> Markdown version of [/jobs/ext/2722966-security-operations-center-soc-analyst](https://www.wearedevelopers.com/jobs/ext/2722966-security-operations-center-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Center (SOC) Analyst - **Company:** Alteryx, Inc. - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $139,000.0 - $151,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Audit Trail, Microsoft Azure, Bash Shell, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Security Information and Event Management, Data Logging, Scripting, Google Cloud, Snowflake, Mitre Att&ck, Multi-Cloud, Information Technology, Cybercrime, Microsoft Sentinel, Splunk, Alteryx - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-security-operations-center-soc-analyst-alteryx-9753812 ## About the Role * Bachelor's degree in computer science or related field (or equivalent experience/training). A master's degree is a plus. * 4+ years of relevant security operations / incident response experience * Strong understanding of the security incident management lifecycle and operational response practices. * Strong experience with SIEM/log management platforms (e.g., Microsoft Sentinel, Splunk, ELK, Snowflake-based analytics, or similar) and demonstrated ability to query and analyze telemetry. * Ability to analyze and interpret security-relevant data including security event logs, system logs, application logs, cloud logs, and device logs. * Hands-on investigation experience using cloud-native security services (e.g., AWS Security Hub, Microsoft Defender for Cloud, Google Security Command Center) and cloud logs. * Experience with one or more scripting languages (Python, PowerShell, shell) to support investigations, enrichment, and analysis. * Strong written and verbal communication skills, including clear ticket documentation, incident reporting, and stakeholder updates. * Excellent analytical and problem-solving skills with a bias toward action and operational rigor., * Forensics: Endpoint or cloud forensics, evidence handling, artifact interpretation, malware triage. * Threat Hunting: Demonstrated experience leading hypothesis-driven hunts and operationalizing results into detections, playbooks, and response improvements (e.g., ATT&CK mapping and coverage tracking). * Detection Engineering: Detection lifecycle ownership (build/test/deploy/tune/retire), alert quality improvement, playbook development. Alteryx is committed to fair, equitable, and transparent compensation. Final compensation will be determined by various factors such as your relevant work experience, education, certifications, skills, and geographic location. ## Description As a member of the Security Operations team, you will be on the front line of protecting Alteryx products, infrastructure, and applications. You will triage and investigate alerts, lead incident response activities, and improve detection coverage and response outcomes across endpoint, identity, SaaS, and multi-cloud environments (AWS, Azure, GCP). This role is SOC-focused and is intended for a Senior level analyst with demonstrated depth in one or more of the following areas: Forensics, Cloud Security Investigations (AWS/Azure/GCP audit logs and cloud-native security signals), Threat Hunting, and Detection Engineering., * Triage and respond to security alerts and incidents across on-prem and multi-cloud enterprise and product environments, leading in-depth investigations using SIEM, EDR, cloud audit logs, identity telemetry, and network data to determine scope, root cause, attacker TTPs, and business impact. * Lead incident communications (severity updates, stakeholder coordination, executive-ready summaries as needed) * Execute incident response activities through containment and remediation coordination with partner teams (IT, Cloud/Platform, Engineering), including clear escalation when needed. * Produce high-quality incident documentation (timelines, evidence collected, hypotheses tested, IOCs, actions taken, lessons learned) and ensure follow-ups are tracked to completion. * Conduct hypothesis-driven threat hunts mapped to common adversary behaviors (e.g., MITRE ATT&CK). * Translate hunt findings into actionable improvements: new detections, tuning, playbooks, and telemetry/visibility recommendations. * Develop, tune, and maintain detection content (correlation rules, SIEM analytics, alert logic) to improve coverage and reduce false positives. * Validate detections with testing and retrospective analysis; continuously improve alert fidelity and response workflows. * Collaborate with stakeholders to define and maintain monitoring and detection use cases that drive risk reduction and operational effectiveness. * Perform basic endpoints and/or cloud forensics during escalated incidents and preserve evidence appropriately. * Support malware triage and artifact analysis as needed during investigations. * Investigate cloud-related threats and anomalies using cloud-native security signals and audit telemetry (AWS/Azure/GCP). * Partner with Cloud/Platform teams to close investigation gaps (logging, retention, telemetry coverage) and validate remediation actions. * Participate in an on-call rotation to provide 24x7 incident response coverage and serve as an escalation point for high-severity events. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023)