Title: IT Security Operations Analyst (Threat Detection) (AWS)
Location: Remote (California)
Term: Long term contract
Need Local Candidate only
C2C or W2 Both
<>
><>
><>
Hiring manager notes …. ><>
>< style="margin: 0cm;">
o Someone with a solid Data Science and Data Analytics background will be best. >< style="margin: 0cm;">
o This role sits at the tier-2/tier-3 level of IT Security and Threat detection: deep-dive threat analysis, detection engineering, and forensic incident response — not alert triage. >< style="margin: 0cm;">
o The person in this seat is expected to independently own investigations end to end, validate and tune a newly implemented SIEM, and serve as an escalation point and technical mentor for less experienced analysts>< style="margin: 0cm;">
>< style="margin: 0cm;">
>< style="margin: 0cm;">
MUST HAVE’S…>< style="margin: 0cm;">
• 6+ years on an IT security operations / incident response team in a senior analyst, engineer, or systems administrator capacity, including demonstrated ownership of complex investigations without supervision.>< style="margin: 0cm;">
• >< style="margin: 0cm;">
• Deep forensic and incident response analysis of complex business systems.>< style="margin: 0cm;">
• >< style="margin: 0cm;">
• Experience using AI as an engineering tool to help with data analysis >< style="margin: 0cm;">
• >< style="margin: 0cm;">
• Substantial AWS security experience: WAF, security groups, RDS, CloudTrail/log pipelines, S3 and Athena for large-scale log analysis.>< style="margin: 0cm;">
• >< style="margin: 0cm;">
• Applied threat intelligence experience across multiple source types (IP, email, telephony, domain/file reputation) and the ability to operationalize it.>< style="margin: 0cm;">
• >< style="margin: 0cm;">
• Strong scripting ability (Python, PowerShell, Bash, or equivalent) for automation and data analysis.>< style="margin: 0cm;">
• >< style="margin: 0cm;">
• Working knowledge of security audit processes, SOX controls, and related expectations>< style="margin: 0cm;">
>< style="margin: 0cm;">
o Musth have 2 or 3 of these….Threat Intelligence types: IP threat intelligence (e.g. from Google Threat Intelligence GTI)>< style="margin: 0cm;">
>< style="margin: 0cm;">
Telephony threat intelligence (e.g. from Twilio)>< style="margin: 0cm;">
>< style="margin: 0cm;">
Email threat intelligence (e.g. from GTI)>< style="margin: 0cm;">
>< style="margin: 0cm;">
>< style="margin: 0cm;">
• Plus: Professional certifications (CISSP, GCIA, GCIH, GCFA, Security+, CCNA) will weigh in the candidate's favor.>< style="margin: 0cm;">
><>
><>
Position Summary>
Senior-level security operations resource supporting multiple complex, systemwide business services. This role sits at the tier-2/tier-3 level: deep-dive threat analysis, detection engineering, and forensic incident response — not alert triage. The person in this seat is expected to independently own investigations end to end, validate and tune a newly implemented SIEM, and serve as an escalation point and technical mentor for less experienced analysts.
Duties
- Lead deep-dive threat analysis across IP, telephony, email, web, and software-package threat intelligence sources (Google Threat Intelligence, Twilio, VirusTotal, and others), turning intelligence into actionable detections and response.
- Serve as tier-2/tier-3 escalation for security incident detection, response, containment, resolution, and recovery — including forensic analysis, security event analysis, data collection, packet analysis, and ticket management.
- Validate, tune, and mature detection content in CrowdStrike NG-SIEM (currently being implemented); confirm coverage, reduce false positives, and close visibility gaps.
- Perform large-scale log analysis and correlation using S3, Athena, and related tooling across AWS (WAF, RDS, security groups), F5, network logs, PeopleSoft HCM, Pathlock (SSO, A360, SoD), Entrust, and other enterprise systems.
- Administer and maintain one or more security services (SIEM, vulnerability management, threat detection, phishing, DLP), including patching, configuration changes, troubleshooting, and customer requests.
- Prioritize and drive resolution of security issues with material financial or regulatory impact, including SOX-relevant systems and controls.
- Analyze, report, and remediate findings from vulnerability scans and penetration tests; track risk acceptance and remediation to closure.
- Create and maintain thorough technical security documentation for IT systems, architecture, and environments.
- Mentor junior analysts, contribute to runbook and playbook development, and advise IT and business stakeholders on risk.
Required Skills / Experience
- 8+ years on an IT security operations / incident response team in a senior analyst, engineer, or systems administrator capacity, including demonstrated ownership of complex investigations without supervision.
- Deep forensic and incident response analysis of complex business systems.
- Hands-on experience with modern SIEM platforms — implementation, tuning, detection engineering, and content development. CrowdStrike NG-SIEM or equivalent next-gen platform strongly preferred.
- Substantial AWS security experience: WAF, security groups, RDS, CloudTrail/log pipelines, S3 and Athena for large-scale log analysis.
- Applied threat intelligence experience across multiple source types (IP, email, telephony, domain/file reputation) and the ability to operationalize it.
- Knowledge of security best practices across Linux, Windows, macOS, VMware, and Cisco IOS — including OS security tooling, configuration, logging, and patching.
- Working knowledge of public-key cryptography and best practices for protecting data at rest and in transit.
- Strong scripting ability (Python, PowerShell, Bash, or equivalent) for automation and data analysis.
- Strong verbal and written communication, including the ability to convey security risk to both technical administrators and non-technical executive stakeholders.
- Excellent analytical, design, and organizational skills; demonstrated ability to manage multiple concurrent assignments in a fast-paced environment.
Preferred Skills / Experience
- Background or formal education in data science; demonstrated use of statistical or data-driven methods in threat hunting and anomaly detection.
- Experience using AI/LLM tooling as an engineering aid for log analysis, correlation, and investigation acceleration.
- Experience supporting ERP/HCM environments (PeopleSoft HCM) and access governance tooling (Pathlock, SoD, SSO).
- Working knowledge of security audit processes, SOX controls, and related expectations.
- Bachelor's degree in CS, IT, CIS, or a related field. Professional certifications (CISSP, GCIA, GCIH, GCFA, Security+, CCNA) will weigh in the candidate's favor.
NOTES
Someone with data science background
High level expertise resource is what they are looking for
2nd tier analytics or 3rd tier (sox) – doing deep dive threat analysis
New Seim is doing what it is supposed to
Sercurity issues that have financial impact
Clone Graham Freeman – UCOP
New role because too much work
Look at threat intelligence
Looks at SEIM
Someone who can looks at logs
They have Peoplesoft, AWS, Crowdstrike, A360
Google Threat Intelligence
Twilio
AWS WAF Logs