Security Operations Analyst

Mastery Logistics Systems•Minneapolis, MN

About The Position

As a Security Operations Analyst on Mastery's Information Security team, you'll monitor, triage, and investigate security alerts across our enterprise and Azure-native infrastructure. You'll work alongside our Security Operations Engineer and Team Lead to protect MasterMind, our transportation management platform, and the infrastructure it runs on from threats and attackers—following established playbooks to contain and escalate real threats, and building the pattern-recognition instincts that come from doing this work every day. This role is ideal for a curious, detail-oriented analyst who's already spent time in a SOC or similarly alert-driven environment and wants to keep sharpening their craft. You don't need to walk in knowing everything — but you should already know what it feels like to work a queue under pressure.

Requirements

  • 2+ years of experience in security operations, IT, or a related alert-driven, shift-based role.
  • Familiarity with SIEM platforms (Microsoft Sentinel or comparable) from hands-on work or coursework.
  • Working knowledge of MITRE ATT&CK and Cyber Kill Chain frameworks.
  • Eager and coachable: genuinely wants to grow technically and takes feedback well.
  • Clear communicator: can write and speak about technical findings in a way both teammates and non-technical stakeholders can follow.
  • Even-keeled under pressure: stays methodical when the queue is full or an alert requires immediate action.

Nice To Haves

  • Basic scripting exposure (Python or PowerShell).
  • Security+, SC-200, or a comparable entry-level certification.
  • Exposure to Azure or another major cloud platform.
  • Experience with case management or ticketing tools (Jira or similar).

Responsibilities

  • Monitor and investigate security alerts across Microsoft Sentinel and Mastery's Azure environment, distinguishing real threats from noise.
  • Execute documented triage and escalation procedures, taking containment or remediation action when appropriate.
  • Write investigation notes that are clear and defensible enough for anyone on the team, an auditor, or a customer to follow.
  • Apply Cyber Kill Chain and MITRE ATT&CK concepts to identify what an alert is actually telling you.
  • Know when and how to hand off to the Security Operations Engineer or Team Lead, with the context they need to act fast.
  • Flag false positives, missed detections, and visibility gaps back to the team that builds and tunes the rules.
  • Take on stretch assignments — basic scripting, log analysis, evidence collection — that build toward more senior SecOps work.

Benefits

  • Medical, Dental & Vision
  • Company-paid life insurance at 1× your salary, plus AD&D and additional voluntary coverage options.
  • Legal assistance and employee support programs
  • 401(k) with 4% Match
  • Flexible PTO
  • Giving Back — St. Jude Children's Research Hospital
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service