> Markdown version of [/jobs/ext/960781-cybersecurity-analyst-threat-detection-automation-soc-operations](https://www.wearedevelopers.com/jobs/ext/960781-cybersecurity-analyst-threat-detection-automation-soc-operations). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst - Threat Detection, Automation & SOC Operations - **Company:** PROPERTY VALUE, INC. - **Location:** Los Angeles, CA, United States (Remote available) - **Experience:** Starter - **Salary:** $90,000.0 - $106,000.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cyber Security, Intrusion Detection and Prevention, Python (Programming Language), Microsoft Software, Performance Tuning, Windows PowerShell, Security Information and Event Management, Data Logging, Scripting, Okta, System Availability, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Microsoft Sentinel, Cortex XSOAR Platform, Active Optical Networks, Cyber Warfare, Splunk, Security Orchestration, Automation & Response - **Published:** June 19, 2026 - **Apply:** https://www.dice.com/job-detail/8cdd1d81-50bc-45a9-b378-cc05dfdaaec8 ## About the Role Skills and experience that will lead to success * Minimum 2+years of experience in a SOC, Cyber Defense Center, MDR, or similar environment (L1-L3) will be preferred * Strong understanding of attack techniques, alerting, and MITRE ATT&CK framework * Hands-on experience with SIEM platforms such as LogScale, Splunk, Microsoft Sentinel, or Elastic * Familiarity with EDR tools (preferably CrowdStrike Falcon) * Exposure to SOAR platforms (e.g., XSOAR) and interest in automation * Basic scripting experience (Python, PowerShell, or similar) preferred * Strong analytical, troubleshooting, and evidence-based decision-making skills * Effective written and verbal communication, including incident documentation and handoffs Preferred Backgrounds * SOC Analyst (Tier 1-3) * MDR Analyst * Incident Response Analyst * Threat Detection Analyst * Detection Engineer (with SOC experience) * Security Operations Engineer * Security Content Developer (with SOC exposure) Education : Bachelor's degree in Computer Science or equivalent years of industry experience. For positions in San Francisco and Los Angeles, we will consider for employment qualified applicants with arrest and conviction record in accordance with local Fair Chance ordinances. ## Description The Cybersecurity Analyst - Threat Detection, Automation & SOC Operations is a hands-on role supporting Aon's global Cybersecurity Command Center (AC3). This position is designed for SOC analysts (Level 1-Level 3) focused on alert triage, incident investigation, and continuous improvement of detection and automation capabilities. The role involves monitoring and analyzing security events, responding to alerts, and enhancing alert quality, playbooks, and workflows. The analyst will collaborate closely with Security Operations, Threat Intelligence, Security Engineering, and Incident Response teams to ensure comprehensive coverage across endpoint, identity, cloud, email, and network environments. The ideal candidate is curious, analytical, and comfortable working directly with security tooling-investigating alerts, understanding attacker behavior, and contributing to the tuning and automation of SOC workflows., * Monitor and triage alerts across platforms including LogScale, CrowdStrike Falcon, XSOAR, Microsoft, and Okta * Perform initial investigation and validation of security events to determine severity and scope * Escalate incidents with clear documentation, supporting evidence, and recommended actions * Conduct in-depth investigations into suspicious endpoint, identity, network, and cloud activity (L2/L3) * Support incident containment and remediation in coordination with Incident Response and Engineering teams Detection Development & Tuning * Provide feedback on alert quality, noise, and detection gaps based on operational experience * Assist in creating and refining detection rules and correlation logic using real-world cases and threat intelligence * Tune existing detections to reduce false positives and improve SOC efficiency * Validate detection effectiveness against known attacker behaviors and MITRE ATT&CK techniques Investigation Enablement * Design and refine investigative workflows to guide analysts from triage through resolution * Develop and maintain runbooks, playbooks, and procedural guides for common alert types * Identify missing context or data needed to accelerate investigations (e.g., enrichment, logging, asset data) * Recommend and implement improvements that reduce analyst effort and decision time Security Automation & Playbooks * Utilize and enhance XSOAR playbooks and automation workflows within daily SOC operations * Identify repetitive tasks suitable for automation and partner with engineering teams to implement solutions * Test, validate, and optimize automated actions to ensure they support investigations effectively * Contribute to continuous improvement initiatives focused on SOC scalability, speed, and consistency Security Analytics & Telemetry * Develop and execute queries in LogScale and other analytics platforms to support investigations and threat hunting * Analyze telemetry across endpoint, identity, cloud, email, and network sources to identify suspicious activity * Identify trends, recurring issues, and visibility gaps * Support development of dashboards and reporting for SOC performance and incident trends Collaboration & Knowledge Sharing * Partner with AC3 analysts to identify operational challenges and propose improvements * Work with Threat Intelligence and PTO teams to operationalize intelligence into detections and playbooks * Collaborate with Security Engineering to enhance logging, telemetry, and data availability * Contribute to post-incident reviews and continuously update runbooks and detections How this opportunity is different * Combines SOC operations, detection engineering, and automation-not just alert triage. * Lets analysts directly shape detections, playbooks, and workflows instead of only following them. * Proven focus on XSOAR and automation, giving a clear growth path into advanced detection and engineering roles. * Broad visibility across endpoint, identity, cloud, email, and network with modern tooling (LogScale, CrowdStrike, Microsoft, Okta). ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)