IT Security Operations Analyst Threat Detection (AWS)
Location: Remote California
Employment: Contract
Work Authorization: USC, GC, GC EAD, or H4 EAD
Job Overview
We are seeking a Senior IT Security Operations Analyst Threat Detection with strong expertise in security operations, threat detection, incident response, AWS security, SIEM, and data analytics.
This is a Tier-2/Tier-3 role focused on deep-dive threat analysis, detection engineering, forensic incident response, and large-scale security log analysis. The ideal candidate can independently own complex investigations and develop and tune security detections.
Responsibilities
- Lead complex threat investigations across IP, email, telephony, web, and software-package intelligence sources.
- Perform Tier-2/Tier-3 incident response, forensic analysis, containment, resolution, and recovery.
- Implement, validate, tune, and develop SIEM detection content and reduce false positives.
- Analyze large-scale AWS security logs using S3, Athena, CloudTrail, WAF, RDS, and Security Groups.
- Correlate security events across cloud, network, application, and enterprise systems.
- Use threat intelligence from sources such as Google Threat Intelligence, VirusTotal, and Twilio to identify and operationalize IOCs.
- Analyze vulnerability and penetration-test findings and drive remediation.
- Support security services including SIEM, vulnerability management, threat detection, phishing, and DLP.
- Develop automation and data-analysis solutions using Python, PowerShell, Bash, or equivalent.
- Apply data-driven methods and AI/LLM tools to accelerate security investigations and log analysis.
- Maintain security documentation, runbooks, and incident-response playbooks.
- Mentor junior security analysts and communicate security risks to technical and business stakeholders.
- Support security audit requirements, SOX controls, and systems with financial or regulatory impact.
Required Qualifications
- 6+ years of senior IT security operations, incident response, security engineering, or related experience.
- Strong experience independently handling complex security investigations.
- Deep forensic and incident-response experience.
- Hands-on experience with modern SIEM platforms, including detection engineering and tuning.
- Strong AWS security experience with:
- AWS WAF
- Security Groups
- RDS
- CloudTrail
- S3
- Athena
- Experience with threat intelligence and IOC analysis.
- Strong scripting skills in Python, PowerShell, Bash, or equivalent.
- Strong security data analytics and log-correlation capabilities.
- Knowledge of security across Linux, Windows, macOS, VMware, and Cisco environments.
- Understanding of encryption, public-key cryptography, and data protection.
- Strong written and verbal communication skills.
Preferred Qualifications
- Data Science or Data Analytics background.
- Experience with CrowdStrike / NG-SIEM.
- Experience with AI/LLM tools for security engineering and data analysis.
- Experience with PeopleSoft HCM, Pathlock, SSO, SoD, F5, or Entrust.
- Experience with IP, email, and telephony threat intelligence.
- Knowledge of SOX controls and security audit processes.
- Bachelor's degree in Computer Science, IT, Cybersecurity, or related field.
- Certifications such as CISSP, GCIA, GCIH, GCFA, Security+, or CCNA.
Additional Requirements
- Must currently reside in California.
- Must be able to provide proof of California residency upon offer.
- LinkedIn profile required.
- Strong communication skills required.
- Resume must be 4 pages or less.