CareerPlanSign in

Security Operations Analyst – Detection Engineering & Threat Hunting

San Jose, United States of America💼 Full-time🗓 2026-09-28

Core

Build and tune high-fidelity detections across endpoint, identity, cloud, and SaaS telemetry; conduct threat hunts; design SOAR playbooks; and monitor security alerts to reduce false positives.

Role type

Detection Engineering & Threat Hunting Analyst

Builds

Detection logic, SOAR playbooks, and automation workflows for the global SOC

Domain

Cybersecurity, Threat Intelligence, SOC Operations

Required skills

SIEM platforms (Splunk, Chronicle, Elastic), EDR tools (SentinelOne, CrowdStrike), detection logic (Sigma, EQL, KQL, YARA), MITRE ATT&CK frameworks, Python scripting, log investigation (identity, endpoint, cloud, network)

Preferred skills

SOAR platforms, detection-as-code pipelines (GitOps, CI/CD), threat hunt frameworks, purple team exercises, red teaming, penetration testing, malware analysis, digital forensics

Technologies

Splunk, Chronicle, Elastic, SentinelOne, CrowdStrike, Python, PowerShell, Sigma, EQL, KQL, YARA, MITRE ATT&CK

Responsibilities

Monitor security alerts from SIEM, IDS/IPS, firewalls, and EDR systems; Build and tune detections across endpoint, identity, cloud, and SaaS; Reduce alert fatigue via severity tagging and enrichment; Conduct threat hunts based on TTPs and intelligence; Design and maintain SOAR playbooks; Partner with CTI to operationalize threat intelligence; Contribute scripts for investigation efficiency; Support global SOC shift workflows; Assist in post-incident reviews.

Seniority

Mid-level, hands-on IC

Sourced via tiktok · Listed on CareerPlan, which tracks 862,000+ jobs from 20+ sources.