About The Position

Nasuni is seeking a Senior Security Operations Analyst to strengthen enterprise security operations across cloud, identity, endpoint, email, and collaboration environments. You will independently lead complex investigations, improve detection quality, mature SOC processes, and turn operational data into measurable gains in detection, containment, and response. This role is for an experienced, hands-on SOC practitioner who has owned incidents and operational improvements in a distributed enterprise or SaaS environment. It is not an entry-level, GRC-only, or advisory-only position. You will operate as a senior individual contributor with authority to make incident triage, severity, and escalation decisions within Nasuni’s response framework. You will own cases from signal through containment, remediation coordination, documentation, and post-incident learning; improve detections, playbooks, dashboards, and procedures; and mentor other analysts. You will influence Security, IT, Cloud, Identity, Engineering, and external providers, while enterprise strategy, company-wide policy, and people management remain outside this role.

Requirements

  • 5+ years of security experience, including 3+ years in an enterprise SOC, incident response, or detection-and-response function.
  • Demonstrated ownership of complex or high-severity investigations from triage through containment and remediation coordination.
  • Strong hands-on SIEM experience, including search, correlation, rule tuning, log onboarding, dashboards, and investigation workflows.
  • Experience improving SOC processes and using operational metrics to identify bottlenecks and validate improvement.
  • Working knowledge across cloud security, EDR, identity, vulnerability management, and email security.
  • Clear written and verbal communication with technical and business stakeholders.

Nice To Haves

  • Direct hands-on experience with two or more of Sumo Logic, Wiz, Rapid7 InsightIDR/InsightVM, and Darktrace / EMAIL.
  • Detection engineering, SOAR, threat hunting, PowerShell or Python, multi-cloud monitoring, or MDR coordination experience.
  • Responsible use of AI-assisted security or observability workflows with clear validation and data-handling controls.
  • Measurably improved MTTD, MTTC, MTTR, false-positive rates, backlog health, or response SLA performance.
  • Led post-incident reviews, established reusable SOC operating practices, or coached other analysts.

Responsibilities

  • Lead advanced investigations across endpoint, identity, cloud, email, SaaS, and network telemetry; determine scope, impact, root cause, containment, and follow-up actions.
  • Operate and improve an enterprise security stack that includes Sumo Logic Cloud SIEM, Wiz, Rapid7 InsightIDR and InsightVM/Exposure Command, and Darktrace / EMAIL, or comparable platforms.
  • Build and tune queries, correlation rules, detections, enrichments, threat hunts, dashboards, case workflows, and SOAR playbooks; improve MITRE ATT&CK coverage and reduce false positives.
  • Own the accuracy, reporting, and continuous improvement of SOC measures such as MTTD, MTTC, and MTTR, along with alert fidelity, aged backlog, escalation quality, and SLA attainment.
  • Improve SOC runbooks, incident procedures, severity criteria, escalation paths, analyst handoffs, case documentation, and post-incident review practices.
  • Partner with system owners to prioritize vulnerability and cloud-risk remediation using business context, exploitability, asset criticality, and compensating controls.
  • Use Nasuni-approved AI capabilities to accelerate log analysis, alert enrichment, case summarization, query development, and playbook drafting while validating outputs and protecting sensitive data.
  • Participate in the global on-call rotation and mentor analysts through case reviews, threat scenarios, and practical feedback.

Benefits

  • Best in class employee onboarding and training
  • Take What You Need” paid time off policy
  • Comprehensive health, dental and vision plans
  • Company-paid life and disability insurance
  • 401(k) and Roth IRA retirement plan
  • Generous employee referral bonuses
  • Flexible remote work policy
  • 10 Paid Holidays
  • Wide array of wellbeing offerings
  • Pre-tax savings accounts with company contributions
  • Great team culture and social activities
  • Collaborative workspaces
  • Free on-site fitness centers and stocked kitchens in select office locations
  • Professional development resources
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service