Saronic
Security Operations Analyst (mid level)
Austin, TX · Posted Jun 22
Job Description
Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.
Job Overview
Saronic Technologies is a leader in revolutionizing autonomy at sea, developing cutting-edge unmanned surface vessels (USVs) to enhance maritime operations for defense and national security. We're looking for a hands-on Senior Security Engineer to be a technical anchor for our Security Operations team.
You'll lead detection and response across endpoint, cloud, identity, network, and SaaS telemetry, owning the complex and ambiguous investigations end-to-end, partnering closely with Detection Engineering to turn what you see on the front line into better detections, and turning post-incident lessons into durable improvements to our playbooks and runbooks. You'll be a trusted escalation point on the on-call rotation, lead the threat hunts that catch what automation misses, and mentor the engineers around you. This is a formative, high-autonomy role on a SecOps team being built from the ground up, where you'll set the technical bar and help shape how Saronic operates across security domains.
Responsibilities
Detection & Alert Operations
Operate across endpoint, cloud, identity, network, and SaaS telemetry in our SIEM and XDR to tune and refine detections in-flight, and be the primary front-line voice driving detection improvements back to Detection Engineering
Lead root-cause analysis on complex, novel, or cross-domain events, and structure investigations others can follow
Own coverage from the operator's seat and map what you're seeing to MITRE ATT&CK, identify gaps, and set the priorities Detection Engineering builds against
Incident Response & Investigation
Lead incident response end-to-end for complex and higher-severity incidents across endpoint, cloud, and identity to contain, eradicate, recover
Serve as a trusted escalation point on the on-call rotation, and brief status and impact to security leadership and stakeholders
Own post-incident reviews, translating detection, response, and containment gaps into prioritized, durable improvements
Coordinate cross-team with Security Engineering and IT during active incidents to reduce dwell time
SecOps Foundation & Enablement
Define and mature the response playbooks, runbooks, and analyst workflows the team runs on
Lead targeted threat hunts informed by intelligence and detection-gap analysis
Own SecOps metrics, reporting, and operational-readiness reviews
Mentor Security Engineers and analysts, and raise the bar for technical judgment and execution across the team
Qualifications
6+ years of hands-on Security Operations, detection engineering, or incident response experience, or an equivalent combination of experience and demonstrated ability
Track record leading complex or ambiguous investigations and incidents end-to-end across at least two of: endpoint, cloud, identity, network, or SaaS
Deep hands-on proficiency with enterprise SIEM/XDR query languages for investigation and hunting; able to tune detections and translate front-line findings into detection requirements
Operational EDR expertise to lead hunts, triage, and response using endpoint telemetry
Strong command of attacker TTPs mapped to MITRE ATT&CK, applied during live investigations
Scripting proficiency in Python, PowerShell, or Bash for enrichment, automation, and triage
Strong network fundamentals: TCP/IP, DNS, HTTP/S, firewall and proxy logs, and lateral-movement patterns
Clear, structured communication skills and can brief non-technical stakeholders and be the calm, trusted voice during an incident
Ownership mindset: drives incidents to closure and makes durable, risk-based tradeoff decisions
Experience standing up or maturing SOC capabilities from the ground up
Experience leading purple-team or adversary-emulation exercises to validate and improve coverage
Ability to obtain and maintain a U.S. security clearance
Preferred Qualifications
Experience with XDR platforms and cross-domain correlated detection across endpoint, identity, and cloud
Familiarity with cloud-native security operations and log sources in AWS or Azure
Experience with SOAR platforms or building response-automation workflows
Exposure to supply-chain and CI/CD pipeline security monitoring
Familiarity with data lake-based or pipeline-driven detection architectures
Background in defense, aerospace, robotics, or other high-assurance operational environments
Familiarity with compliance frameworks such as NIST SP 800-171 or NIST SP 800-53
Relevant certifications are a plus but never a gate, including GIAC GCIH, GCIA, GCFA, GCFE, GCDA, GSOM, CySA+, BTL1/2, OSCP, or CISSP
Experience mentoring analysts or setting technical direction for a security operations team
Active security clearance or prior clearance history is a strong differentiator
Physical Demands
Prolonged periods of sitting at a desk and working on a computer
Occasional standing and walking within the office
Manual dexterity to operate a computer keyboard, mouse, and other office equipment
Visual acuity to read screens, documents, and reports
Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies
Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages)
Benefits
Medical Insurance: Comprehensive health insurance plans covering a range of services
Saronic pays 100% of the premium for employees and 80% for dependents
Dental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision care
Saronic pays 100% of the premium under the basic plan for employees and 80% for dependents
Time Off: Generous PTO and Holidays
Parental Leave: Paid maternity and paternity leave to support new parents
Competitive Salary: Industry-standard salaries with opportunities for performance-based bonuses
Retirement Plan: 401(k) plan with company match
Stock Options: Equity options to give employees a stake in the company’s success
Life and Disability Insurance: Basic life insurance and short- and long-term disability coverage
Pet Insurance: Discounted pet insurance options including 24/7 Telehealth helpline
Additional Perks: Free lunch benefit and unlimited free drinks and snacks in the office
Saronic CCPA Notice for Candidates and California Employees
If this role is based in the United States, it requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).
Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits. We are also committed to providing reasonable accommodations for qualified individuals with disabilities.