Senior Cyber Operations Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+20 more
Job description
The Senior Cyber Operations Analyst is an experienced team member responsible for monitoring, detecting and responding to cybersecurity threats and incidents in a fast-paced environment. This role requires advanced skills in analyzing, triaging and resolving investigations and incidents. The senior analyst uses a combination of commercial and open-source tools, including AI-powered solutions, to automate repetitive tasks, enhance threat detection and improve response effectiveness. They correlate alerts and events, execute queries and apply behavior-based and anomaly detection techniques to support timely response actions. This role requires experience across multiple technologies, including SOARs, SIEMs, MCP solutions, endpoints, applications, network devices, cloud infrastructure and threat intelligence feeds. As a senior team member, the analyst also supports escalation workflows, assists less experienced analysts, and handles complex incidents., The senior analyst is also responsible for mentoring junior team members to strengthen overall team capability. In this role, they will identify opportunities to use automation technologies & [RJ1] AI to automate repetitive tasks, enabling the team to focus on more complex analysis and response activities, which contributes to a more resilient security posture. The senior analyst operates in a cross-functional capacity, working across diverse technologies to support and secure business operations. They are expected to apply critical thinking and serve as the human in the loop when using AI-enabled tools and making security decisions. Strong communication skills are essential, along with the ability to understand and respond to emerging cybersecurity threats at scale. This role operates within an advanced cybersecurity program designed to keep pace with adversaries using both traditional and AI-enabled attack techniques. The role reports to the manager or director of security operations.
- Serve as a subject matter expert for a team of analysts supporting managed 24/7/365 monitoring and response operations.
- Investigate and respond to cybersecurity incidents, including participating in off-hours and on-call rotations.
- Act as an escalation point for day-to-day SOC operations and identify opportunities to automate.
- Assess program strengths and weaknesses and recommend AI solutions to improve team skills and knowledge.
- Stay current on emerging cybersecurity threats, AI developments, risks and vulnerabilities that may impact services.
- Automate repetitive tasks within SOAR environments using Cloud technologies, ML and AI to improve efficiency.
- Develop detection capabilities aligned with the MITRE ATT&CK framework and enhance them using automation/AI.
- Validate alerts by interpreting confidence scores, risk ratings and recommended actions.
- Use NLP tools to analyze events alongside threat intelligence data.
- Improve AI model performance and alert tuning by labeling events and validating true and false positives.
- Use multiple-agent collaboration using MCP solutions within security workflows.
- Collaborate with data science and engineering teams to improve AI models used in SOC operations.
- Refine playbooks, policies, procedures and guidelines in alignment with industry best practices and AI capabilities.
- Partner with security engineering, incident response and IT teams to improve monitoring, workflows and response processes.
- Support the development and tracking of metrics, KPIs and service-level objectives for security events.
- Participate in tabletop exercises to identify gaps, improve skills and strengthen communication.
- Review reports from tabletop exercises, vulnerability assessments and penetration tests to drive improvements.
- Evaluate logging coverage to identify potential gaps in detection capabilities.
- Examine log data across endpoints, databases, applications, identity systems, networks, mobile platforms and cloud environments.
- Recommend adjustments to security tools to reduce false positives.
- Provide guidance on monitoring, logging, identity, data protection and detection strategies, including preventive controls.
- Report on SOC performance and posture to cybersecurity leaders and stakeholders as needed., CDM Smith Inc. and its divisions and subsidiaries (hereafter collectively referred to as “CDM Smith”) reserves the right to require background checks including criminal, employment, education, licensure, etc. as well as credit and motor vehicle when applicable for certain positions. In addition, CDM Smith may conduct drug testing for designated positions. Background checks are conducted after an offer of employment has been made in the United States. The timing of when background checks will be conducted on candidates for positions outside the United States will vary based on country statutory law but in no case, will the background check precede an interview. CDM Smith will conduct interviews of qualified individuals prior to requesting a criminal background check, and no job application submitted prior to such interview shall inquire into an applicant’s criminal history. If this position is subject to a background check for any convictions related to its responsibilities and requirements, employment will be contingent upon successful completion of a background investigation including criminal history. Criminal history will not automatically disqualify a candidate. In addition, during employment individuals may be required by CDM Smith or a CDM Smith client to successfully complete additional background checks, including motor vehicle record as well as drug testing., CDM Smith is committed to fair and equitable compensation practices. This pay range is a good faith estimate representative of all experience levels for the geographic location assigned to the position. In addition to geographic location, a candidate’s salary is determined by several other factors including, but not limited to, the role, function and associated responsibilities, relevant work experience, skills, required certifications, and education/training.
Requirements
- Experience in SOC monitoring and response or related experience.
- Working knowledge of ML and AI, as well as their application in security operations.
- Experience using NLP, query construction and AI-powered tools to analyze logs, threat intelligence and incident data.
- Experience using MCP servers and purpose-built agents to support investigation and response activities.
- Hands-on experience with AI assistants and platforms for investigation, security analysis and response.
- Demonstrated technical understanding of emerging cybersecurity threats, including adversary use of AI.
- Ability to develop detections aligned with the MITRE ATT&CK framework and relevant open-source AI frameworks.
- Proficient in scripting languages such as Python, Bash, JavaScript or PowerShell, as well as experience with KQL.
- Experience with SOAR, SIEM, threat intelligence platforms, identity systems, sandboxes, vulnerability management and EDR/XDR tools.
- Strong understanding of threats, vulnerabilities, and incident response principles.
- Familiar with one or more frameworks or regulations, such as CMMC, NIST CSF, CIS, GDPR, CCPA.
- Strong judgment and ability to make timely decisions in complex situations.
- Experience with Azure, AWS, and GCP. Bonus points for Gov Cloud deployments
- Experience managing/collaborating with MSSPs
- Exceptional written and verbal communication skills across multiple levels of the organization.
- Excellent written and verbal communication skills, with the ability to clearly communicate cybersecurity incidents and document post-incident reviews and root cause analyses.
- Strong analytical and problem-solving skills, with the ability to evaluate complex issues and recommend practical solutions.
- Highly organized and efficient, with the ability to manage multiple priorities and meet deadlines in a fast-paced environment.
- Ability to apply both strategic and tactical thinking to support effective security operations and continuous improvement.
- Ability to remain calm and focused under pressure while managing time-sensitive priorities and deadlines.
- Effective decision-making skills in complex and time-sensitive situations., * Bachelor’s degree.
- 6 years of related experience.
- Equivalent additional directly related experience will be considered in lieu of a college degree.
Domestic and/or international travel may be required. The frequency of travel is contingent on specific duties, responsibilities, and the essential functions of the position, which may vary depending on workload and project demands., * One or more GIAC certifications: GCED, GCIH, GDAT, Microsoft Security Operations Analyst Associate
- Experience managing security information and event management (SIEM) systems, threat intelligence platforms, security automation and orchestration solutions, intrusion detection and prevention systems (IDS/IPS), file integrity monitoring (FIM), data loss prevention (DLP) and other network and system monitoring tools.
- Experience in investigations using formal chain-of-custody methods, forensic tools and best practices.
About the company
Check out this video and find out why our team loves to work here! (https://www.cdmsmith.com/resources/videos/meet-cdm-smith)
Join Us! CDM Smith - where amazing career journeys unfold.
Imagine a place committed to offering an unmatched employee experience. Where you work on projects that are meaningful to you. Where you play an active part in shaping your career journey. Where your co-workers are invested in you and your success. Where you are encouraged and supported to do your very best and given the tools and resources to do so. Where it’s a priority that the company takes good care of you and your family.
Our employees are the heart of our company. As an employer of choice, our goal is to provide a challenging, progressive and inclusive work environment which fosters personal leadership, career growth and development for every employee. We value passionate individuals who challenge the norm, deliver world-class solutions and bring diverse perspectives. Join our team, and together we will make a difference and change the world.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
What Are The Top Skills Required For Azure Developers?
Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity