Security Analyst

PRI TechnologyNew York City Metropolitan Area, United States
Full TimeOn-siteMidLimited info disclosed
33 views0 applications

Description

This role operates within the internal SOC, partnering closely with an external MSSP to maintain 24x7 coverage. The analyst will triage alerts, investigate incidents, and improve detection capabilities through data analysis and automation. The role emphasizes critical thinking, analytical reasoning, and hands-on scripting to enhance SOC efficiency and detection quality. Core Responsibilities SOC Operations & MSSP Oversight · Triage and investigate alerts from SIEM, EDR, identity, and cloud platforms · Act as the internal escalation point for MSSP-generated alerts · Provide direction and feedback to MSSP to improve alert quality and response consistency · Validate MSSP findings and ensure appropriate prioritization and remediation Incident Investigation & Response · Conduct structured investigations across endpoint, identity, and network telemetry · Correlate data across multiple sources to determine root cause and scope · Document incidents with clear timelines, impact assessments, and recommendations Security Analytics & Detection Engineering · Analyze logs and datasets to identify detection gaps and improve signal quality · Tune detection logic and reduce false positives · Develop and maintain detection use cases aligned to threat frameworks (e.g., MITRE ATT&CK) · Design, test, and deploy new detection rules and analytics based on emerging threats and internal findings Automation & Engineering (Required) · Build scripts (Python, PowerShell, or similar) to automate triage, enrichment, and case workflows · Integrate tools and APIs to streamline SOC processes · Improve case management workflows and response playbooks through automation Continuous Improvement · Propose and implement improvements to monitoring coverage and response processes · Contribute to playbooks, runbooks, and detection standards · Participate in threat hunting and simulation exercises Required Skills & Characteristics Critical Thinking (Primary Evaluation Criteria) · Ability to analyze incomplete or ambiguous data and form defensible conclusions · Strong hypothesis-driven investigation approach · Demonstrated problem-solving in technical or analytical contexts Technical Skills · Hands-on experience with scripting (Python, PowerShell, or similar) · Familiarity with SIEM, EDR, and log analysis · Understanding of common attack techniques and investigation methods Analytical Skills · Ability to identify patterns and anomalies across datasets · Experience working with structured or semi-structured data Communication · Clear, concise incident documentation · Ability to challenge and validate MSSP outputs constructively Nice to Have · Experience building detection rules or analytics (Splunk, Sentinel, Elastic, etc.) · SQL or data querying experience · Exposure to AI/ML-assisted security workflows or automation tools · Threat hunting experience