Security Operations Analyst

TAXWELLHaverford, PA
Remote

About The Position

Taxwell is seeking a Security Operations Analyst to join their IRM SecOps team. This role is ideal for someone who thrives in a fast-paced, lean environment, takes ownership, and possesses both hands-on detection and response expertise along with strong operational security capabilities. The analyst will support various security operations functions by implementing, configuring, and optimizing security tools and integrations. Key areas include monitoring, tuning detections, ensuring telemetry visibility, and driving continuous improvement. The role also involves incident response, including hands-on investigation, containment, remediation, and addressing root causes.

Requirements

  • 5+ years of experience in cybersecurity operations, security operations, incident response, or threat detection.
  • Hands-on expertise with Microsoft Azure security services, including Azure Monitor, Sentinel, and Entra ID.
  • Strong understanding of SIEM operations, telemetry visibility, detection logic, and incident response workflows.
  • Experience with threat hunting, log analysis, and identifying visibility gaps within security monitoring environments.
  • Proficiency in Python and/or PowerShell scripting for automation and operational support.
  • Excellent communication and collaboration skills.
  • Highly self-motivated with the ability to manage priorities and operate independently in a fast-paced environment.

Nice To Haves

  • Hands-on expertise with CrowdStrike Falcon (deployment, configuration, and response).
  • Familiarity with Amazon Web Services (AWS).
  • Familiarity with Defender XDR, Splunk, and osquery.
  • Experience in consulting, finance, or technology environments.
  • Experience with data visualization tools (e.g., Power BI).
  • Certifications such as GIAC, GCFA, or GCFR.

Responsibilities

  • Conduct proactive threat hunting and refine detection logic for improved accuracy and context.
  • Implement, configure, and optimize security tools, SIEM integrations, and data connections.
  • Monitor and validate security telemetry to identify visibility gaps and improve detection coverage.
  • Respond to escalated security incidents, performing analysis, containment, remediation, and root cause investigation.
  • Collaborate with IT, cloud, and development teams to strengthen security controls and visibility.
  • Create and maintain detailed incident documentation, timelines, and lessons learned.
  • Continuously improve playbooks, automation, operational processes, and detection effectiveness.
  • Contribute to process and capability development across the team.
  • Assist with onboarding and troubleshooting data sources and connectors within Microsoft Sentinel.

Benefits

  • Supportive, open, and inclusive atmosphere
  • Team that values your contributions
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service