I have a unique opportunity for a Security Analytics Analyst to join the team for one of our top tier investment banks located in Midtown Manhattan. You would be joining a team of 11 that handles SIEM/EDR activities as well as Security Governance and Engineering. Please see the job description below and let me know if you should have any questions. As the Security Analyst, you will triage alerts, investigate incidents, and improve detection capabilities through data analysis and automation. The role emphasizes critical thinking, analytical reasoning, and hands-on scripting to enhance SOC efficiency and detection quality.
This is 3 days onsite, 2 days remote.
*** This does come with a very generous base salary and bonus ***
Responsibilities
- Triage and investigate alerts from SIEM, EDR, identity, and cloud platforms
- Act as the internal escalation point for MSSP-generated alerts
- Provide direction and feedback to MSSP to improve alert quality and response consistency
- Validate MSSP findings and ensure appropriate prioritization and remediation
- Conduct structured investigations across endpoint, identity, and network telemetry
- Correlate data across multiple sources to determine root cause and scope
- Document incidents with clear timelines, impact assessments, and recommendations
- Analyze logs and datasets to identify detection gaps and improve signal quality
- Tune detection logic and reduce false positives
- Develop and maintain detection use cases aligned to threat frameworks (e.g., MITRE ATT&CK)
- Design, test, and deploy new detection rules and analytics based on emerging threats and internal findings
- Build scripts (Python, PowerShell, or similar) to automate triage, enrichment, and case workflows
- Integrate tools and APIs to streamline SOC processes
- Improve case management workflows and response playbooks through automation
- Propose and implement improvements to monitoring coverage and response processes
- Contribute to playbooks, runbooks, and detection standards
- Participate in threat hunting and simulation exercises
- Ability to analyze incomplete or ambiguous data and form defensible conclusions
- Strong hypothesis-driven investigation approach
- Demonstrated problem-solving in technical or analytical contexts
Qualifications
- Hands-on experience with scripting (Python, PowerShell, or similar)
- Any familiarity with SIEM, EDR, and log analysis would be helpful
- Understanding of common attack techniques and investigation methods
- Experience working with structured or semi-structured data
- Ability to challenge and validate security logs
- Any experience building detection rules or analytics (Splunk, Sentinel, Elastic, etc.)
- Exposure to AI/ML-assisted security workflows or automation tools
Senior Technical Recruiter, PRI Technology
#J-18808-Ljbffr