hirly

Saronic Technologies

Senior Security Operations Analyst

Austin, TX · San Diego, CA

Apply through hirly

Upload your resume and get a version tailored to this job, plus a cover letter, in about thirty seconds — before you create an account.

Apply with hirly

hirly's read of this role

Seniority
Senior
Country
US
Work mode
On-site / unstated
First seen by hirly
28 Sept 2026

Derived automatically from the posting. Sign up to see how the role scores against your own resume.

the posting

Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.

Job Overview

Saronic Technologies is a leader in revolutionizing autonomy at sea, developing cutting-edge unmanned surface vessels (USVs) to enhance maritime operations for defense and national security. We're looking for a hands-on Senior Security Engineer to be a technical anchor for our Security Operations team.

You'll lead detection and response across endpoint, cloud, identity, network, and SaaS telemetry, owning the complex and ambiguous investigations end-to-end, partnering closely with Detection Engineering to turn what you see on the front line into better detections, and turning post-incident lessons into durable improvements to our playbooks and runbooks. You'll be a trusted escalation point on the on-call rotation, lead the threat hunts that catch what automation misses, and mentor the engineers around you. This is a formative, high-autonomy role on a SecOps team being built from the ground up, where you'll set the technical bar and help shape how Saronic operates across security domains.

Responsibilities

Detection & Alert Operations

Operate across endpoint, cloud, identity, network, and SaaS telemetry in our SIEM and XDR to tune and refine detections in-flight, and be the primary front-line voice driving detection improvements back to Detection Engineering

Lead root-cause analysis on complex, novel, or cross-domain events, and structure investigations others can follow

Own coverage from the operator's seat and map what you're seeing to MITRE ATT&CK, identify gaps, and set the priorities Detection Engineering builds against

Incident Response & Investigation

Lead incident response end-to-end for complex and higher-severity incidents across endpoint, cloud, and identity to contain, eradicate, recover

Serve as a trusted escalation point on the on-call rotation, and brief status and impact to security leadership and stakeholders

Own post-incident reviews, translating detection, response, and containment gaps into prioritized, durable improvements

Coordinate cross-team with Security Engineering and IT during active incidents to reduce dwell time

SecOps Foundation & Enablement

Define and mature the response playbooks, runbooks, and analyst workflows the team runs on

Lead targeted threat hunts informed by intelligence and detection-gap analysis

Own SecOps metrics, reporting, and operational-readiness reviews

Mentor Security Engineers and analysts, and raise the bar for technical judgment and execution across the team

Qualifications

6+ years of hands-on Security Operations, detection engineering, or incident response experience, or an equivalent combination of experience and demonstrated ability

Track record leading complex or ambiguous investigations and incidents end-to-end across at least two of: endpoint, cloud, identity, network, or SaaS

Deep hands-on proficiency with enterprise SIEM/XDR query languages for investigation and hunting; able to tune detections and translate front-line findings into detection requirements

Operational EDR expertise to lead hunts, triage, and response using endpoint telemetry

Strong command of attacker TTPs mapped to MITRE ATT&CK, applied during live investigations

Scripting proficiency in Python, PowerShell, or Bash for enrichment, automation, and triage

Strong network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral-movement patterns

Clear, structured communication skills and can brief non-technical stakeholders and be the calm, trusted voice during an incident

Ownership mindset: drives incidents to closure and makes durable, risk-based tradeoff decisions

Experience standing up or maturing SOC capabilities from the ground up

Experience leading purple-team or adversary-emulation exercises to validate and improve coverage

Ability to obtain and maintain a U.S. security clearance

Preferred Qualifications

Experience with XDR platforms and cross-domain correlated detection across endpoint, identity, and cloud

Familiarity with cloud-native security operations and log sources in AWS or Azure

Experience with SOAR platforms or building response-automation workflows

Exposure to supply-chain and CI/CD pipeline security monitoring

Familiarity with data lake-based or pipeline-driven detection architectures

Background in defense, aerospace, robotics, or other high-assurance operational environments

Familiarity with compliance frameworks such as NIST SP 800-171 or NIST SP 800-53

Relevant certifications are a plus but never a gate, including GIAC GCIH, GCIA, GCFA, GCFE, GCDA, GSOM, CySA+, BTL1/2, OSCP, or CISSP

Experience mentoring analysts or setting technical direction for a security operations team

Active security clearance or prior clearance history is a strong differentiator

Physical Demands

Prolonged periods of sitting at a desk and working on a computer

Occasional standing and walking within the office

Manual dexterity to operate a computer keyboard, mouse, and other office equipment

Visual acuity to read screens, documents, and reports

Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies

Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages)

Benefits

Medical Insurance: Comprehensive health insurance plans covering a range of services

Saronic pays 100% of the premium for employees and 80% for dependents

Dental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision care

Saronic pays 100% of the premium under the basic plan for employees and 80% for dependents

Time Off: Generous PTO and Holidays

Parental Leave: Paid maternity and paternity leave to support new parents

Competitive Salary: Industry-standard salaries with opportunities for performance-based bonuses

Retirement Plan: 401(k) plan with company match

Stock Options: Equity options to give employees a stake in the company’s success

Life and Disability Insurance: Basic life insurance and short- and long-term disability coverage

Pet Insurance: Discounted pet insurance options including 24/7 Telehealth helpline

Additional Perks: Free lunch benefit and unlimited free drinks and snacks in the office

Saronic CCPA Notice for Candidates and California Employees

If this role is based in the United States, it requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3) .

Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits. We are also committed to providing reasonable accommodations for qualified individuals with disabilities.

Original posting on Saronic Technologies's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job