Security Operations Analyst II

Prometheus Real Estate GroupSan Mateo, CA
$105,000 - $135,000Hybrid

About The Position

The IT Team is looking for a Security Operations Analyst II responsible for leading in-depth investigations and incident response to escalated events and be involved in security-based projects as well as manage security solutions/systems. This role correlates data across SIEM/XDR, identity, endpoint, network, and SaaS/cloud sources; determines true blast radius; separates routine administrative activity from attacker behavior; and coordinates containment and remediation with Infrastructure/IT. Security Operations: Lead investigations for escalated incidents such as account compromises, endpoint malware, suspicious network activity, and SaaS misuse. Correlate data across SIEM/XDR, identity/SSO, endpoint/EDR, network, and cloud/SaaS logs to build attack timelines, identify entry vectors, and assess lateral movement. Coordinate containment and remediation with Infrastructure/IT—disabling or recovering compromised accounts, isolating infected endpoints and removing malware, validating EDR coverage and system integrity, and confirming cleanup success. Produce clear, audit-ready incident documentation detailing scope, evidence, actions, timelines, decisions, and resolution rationale. Act as an escalation point for the Service Desk and junior analysts, provide real-time guidance, and apply chain-of-custody and evidence-preservation practices for high-severity events, maintaining case files with hashes, screenshots, and IOC/IOA sets. Detection, Playbooks, Threat Intelligence, and Continuous Improvement Response: Tune and improve detections, automate repetitive workflows, and drive incident response improvements. Refine existing rules and propose new use cases based on investigations and recurring patterns; enrich cases with threat intelligence (IOCs and TTPs) and incorporate those learnings into future detections and playbooks; Contribute and evolve response playbooks for major incident types (account compromise, endpoint malware, SaaS abuse, suspicious network activity), participate in post-incident reviews with root-cause analyses and practitioner-level technical narratives, and recommend prioritized, practical prevention and mitigation improvements. Conduct targeted threat hunts (e.g., OAuth abuse, living-off-the-land binaries, credential-stuffing against legacy protocols), define and track alert-quality KPIs (true/false positive ratios, suppression coverage), and collaborate to improve MTTD/MTTR.

Requirements

  • Bachelor’s Degree in the field of Computer Science, technology, or a related area
  • 2–5 years in Security Operations or Infrastructure/IT Operations with a security focus.
  • 2+ years Windows/sysadmin experience; macOS/Linux a plus.
  • 2+ years core networking (IP, DNS, ports, VPN, firewalls).
  • Hands-on experience with SIEM/XDR, EDR, identity/SSO, and cloud/SaaS logs.
  • Able to read Windows event logs, perform basic endpoint triage, and apply MITRE ATT&CK for triage.
  • Strong written/verbal communication and incident leadership skills.
  • CompTIA Security+ required

Nice To Haves

  • Master's degree preferred.
  • Other security certifications preferred.

Responsibilities

  • Lead investigations for escalated incidents such as account compromises, endpoint malware, suspicious network activity, and SaaS misuse.
  • Correlate data across SIEM/XDR, identity/SSO, endpoint/EDR, network, and cloud/SaaS logs to build attack timelines, identify entry vectors, and assess lateral movement.
  • Coordinate containment and remediation with Infrastructure/IT—disabling or recovering compromised accounts, isolating infected endpoints and removing malware, validating EDR coverage and system integrity, and confirming cleanup success.
  • Produce clear, audit-ready incident documentation detailing scope, evidence, actions, timelines, decisions, and resolution rationale.
  • Act as an escalation point for the Service Desk and junior analysts, provide real-time guidance, and apply chain-of-custody and evidence-preservation practices for high-severity events, maintaining case files with hashes, screenshots, and IOC/IOA sets.
  • Tune and improve detections, automate repetitive workflows, and drive incident response improvements.
  • Refine existing rules and propose new use cases based on investigations and recurring patterns.
  • Enrich cases with threat intelligence (IOCs and TTPs) and incorporate those learnings into future detections and playbooks.
  • Contribute and evolve response playbooks for major incident types (account compromise, endpoint malware, SaaS abuse, suspicious network activity).
  • Participate in post-incident reviews with root-cause analyses and practitioner-level technical narratives, and recommend prioritized, practical prevention and mitigation improvements.
  • Conduct targeted threat hunts (e.g., OAuth abuse, living-off-the-land binaries, credential-stuffing against legacy protocols).
  • Define and track alert-quality KPIs (true/false positive ratios, suppression coverage).
  • Collaborate to improve MTTD/MTTR.

Benefits

  • Medical; Vision; Dental:100% Company-paid plans (including eligible dependents) and affordable buy-up options
  • Life Insurance; Accidental Death & Dismemberment Insurance; Long Term Disability
  • Behavioral Health Program Accessible 24/7
  • Tax-Free Flexible Spending Accounts
  • 401(K) Retirement Plan with Employer Matching
  • Recognition & Rewards Program (Torch)
  • Vacation: 10 days per year with accrual increase overtime
  • Anniversary Vacation: 40-hour Vacation Granted at Tenured Milestones
  • Sick Leave: 9 days per year
  • 12 paid holidays, including your birthday!
  • Paid Volunteer Time
  • Tenure-based Housing discounts
  • Educational Assistance, Tuition Reimbursement
  • Referral Bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service