> Markdown version of [/jobs/ext/470824-senior-security-operations-analyst](https://www.wearedevelopers.com/jobs/ext/470824-senior-security-operations-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Operations Analyst - **Company:** Monroe University - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $80,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Query Languages, Identity and Access Management, Information Technology Operations, Intrusion Detection and Prevention, Python (Programming Language), Performance Tuning, Windows PowerShell, Phishing, Red Team (Cyber Security), Kusto Query Language, Security Information and Event Management, Scripting, Mitre Att&ck, QRadar, Information Technology, Microsoft Sentinel, Splunk, SentinelOne Expertise - **Published:** June 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4b152ead74451b88 ## About the Role Do you have experience in Stakeholder relationship building?, Do you have a Bachelor's degree?, * Deep hands-on experience with enterprise SIEM platforms (Microsoft Sentinel, Splunk, IBM QRadar, or equivalent), including detection engineering, log source management, and query language fluency. * Strong working knowledge of endpoint detection and response platforms (CrowdStrike Falcon, Microsoft Defender XDR, SentinelOne, or equivalent), including policy design, response actions, and threat hunting. * Demonstrated incident response experience across multiple incident types - ransomware, credential compromise, phishing, insider risk, data exfiltration. * Fluency in the MITRE ATT&CK framework and ability to operationalize it within detection engineering and IR playbooks. * Experience managing outsourced SOC relationships - contract terms, SLAs, escalation paths, performance management, and vendor transition. * Strong scripting skills in Python, PowerShell, or KQL (Kusto Query Language) for detection development and automation. * Understanding of higher-education operational context - academic calendar impact on IT operations, student/faculty/staff authentication patterns, campus-level incident communication - or demonstrated ability to learn rapidly. * Excellent written and verbal communication skills; ability to produce clear incident documentation and communicate effectively during high-pressure situations. * Calm, deliberate judgment during incidents; ability to maintain clarity and structure when systems are compromised and stakeholders are anxious. * Collaborative orientation and comfort working with external vendors, internal IT teams, General Counsel, and senior leadership., * Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field; equivalent professional experience considered. * Minimum 6-8 years of progressive experience in security operations, incident response, or detection engineering, with at least 3 years in a senior analyst role. * Professional certifications such as CISSP, GIAC GCIH, GIAC GCFA, GIAC GCIA, or equivalent strongly preferred. * Experience in higher education, healthcare, financial services, or another regulated environment is preferred. * Demonstrated incident response leadership experience, ideally including engagements involving external forensics or IR firms. * Ability to work on-site at Monroe's Bronx and New Rochelle campuses at least four days per week, with after-hours on-call availability. ## Description The Senior Security Operations Analyst is a senior individual contributor supporting the Cybersecurity team at Monroe University. This role owns Monroe's operational security posture day-to-day - including the relationship with the outsourced Security Operations Center, incident response coordination, SIEM tuning and content development, and endpoint detection and response operations. The Senior Security Operations Analyst serves as the institution's internal operational leader for detection and response, translating external SOC output into actionable institutional response and driving continuous improvement of Monroe's detection capability. This role partners closely with the IT team, the outsourced SOC vendor, and external specialized firms engaged for forensics or incident response. Core Responsibilities: * Own the day-to-day relationship with Monroe's outsourced Security Operations Center reviewing alert quality, validating findings, driving SLA performance, and escalating vendor issues. * Serve as the institution's primary incident responder - coordinating response activities, engaging IT and business stakeholders, managing vendor escalations, and producing incident documentation and after-action reports. * Develop, maintain, and exercise Monroe's incident response playbooks and runbooks, aligned with NIST 800-61 and institutional regulatory obligations (GLBA Safeguards Rule, FERPA, state notification laws). * Conduct regular tabletop exercises with IT, legal, communications, and leadership to validate response capability and identify improvement areas. * Own SIEM tuning, content development, and log source onboarding - ensuring that Monroe's detection platform has the visibility required to support the outsourced SOC and internal threat hunting. * Administer and optimize endpoint detection and response (EDR/XDR) across the institution's endpoints and servers, ensuring consistent policy, current agent coverage, and response-ready tooling. * Collaborate with the Senior Vulnerability and Threat Analyst on threat-informed detection engineering - translating threat intelligence and red team findings into new detections. * Partner with the Senior IAM Engineer on identity-centric detections, including credential compromise indicators, anomalous authentication patterns, and privileged account misuse. * Collaborate with the Senior Vulnerability and Threat Analyst on threat-informed detection engineering - translating threat intelligence and red team findings into new detections. * Serve as Monroe's operational liaison to external specialized firms during compromise assessments, forensic investigations, or incident response engagements. * Produce operational metrics and reporting for the CISO and CIO, including mean-time-to-detect, mean-time-to-contain, alert volume trends, and SOC vendor performance. * Support GLBA Safeguards Rule compliance by maintaining documented evidence of monitoring, incident response, and detection capability. * Lead Monroe's incident response on-call rotation and serve as the primary escalation point for after-hours security events. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)