Senior Security Analyst
Summary
A Senior Security Analyst monitors and mitigates security threats for managed clients using tools like EDR/XDR and SIEM, investigates incidents, hunts for emerging threats, and assists in deploying security services while collaborating with engineers and clients.
Responsibilities
- Investigate, manage,respond to,and escalatesecurity alerts from various security platforms, such as EDR/XDR, SIEM, etc.
- Analyze security events escalated from tier 1 tovalidatethreats and respond accordingly.
- Investigate and respond to reported phishing emails.
- Analyze, prioritize, and track vulnerabilitiesdetected by vulnerability scanners.
- Researchemerging threatsand perform global threat huntsto support correlating industrydata and threat feeds with our clients’ environments andattack surfaces.
- Conduct incident response procedures, investigatingindicators of compromise,identifyingroot causes, collecting evidence, anddrafting incident response reports.
- Collaborate with othersecurityanalysts,compliance analysts,Compassengineers,andvCISOs,lendingthem yourtechnicalexpertisein ordertoprovide exceptional managed security services toour clients.
- Interface directly with clients and end users wheninvestigating threats and managing/troubleshooting managed security tools.
- Assistin the deployment of the managed security services toolstackto new clients.
- Assistwithinternal quality projects, including developing standardsandsecurityservicesforCompassMSP.
- Stay current with the latest industry trends, best practices, and regulatory requirements tohelpcontinuously enhance our securityservices.
- Hunt for emerging threats using a combination ofmethods and tools such as SIEM querying, software testing, sandboxing, etc.Translate the results of threat hunts into actionable alerts andanalysisSOPs to aid the SOC in protecting clients.
- Create andmaintaininternal standard operating procedures.
- Participate in a flexible work schedule to includeafter hours/ on-call shifts.
Requirements
- 5+ years of experience in a SOC/incident response role.
- Demonstrated experience conducting alert and incident investigationsend-to-end with minimal oversight and sound escalation judgment
- Execution-oriented: able to perform containment, blocking, isolation, and basic remediation in small and mid-sized business environments.
- Experience monitoring and responding to threatsimpactingWindows, Microsoft 365 / Entra ID, and firewalls.
- Familiarity and comfort working acrossEDR,firewalladministration, identity and email security consoles, ticketing systems, RMM tools, and security telemetry sources.
Preferred Additional Experience:
- Infrastructure Recovery & IT Engineering
- Network, cloud, and endpoint recovery
- Firewall, VPN, and zero-trust environments
- Backup validation and isolated recovery environments
- Active Directory, virtual hosts, domain controllers, migrations, and secure system restoration
- Endpoint wipe-and-reload and related rebuild activities
Benefits
- Competitive pay
- Quarterly Bonuses
- Progressive PTO
- Medical/Dental/Vision/Life/Disability available
- Tax deferred retirement plan with company match
- Career Development and Coaching
- Fun work environment!
CompassMSP is committed to fair and equitable compensation practices. Salary range will reflect experience, location and other factors. This position is eligible for an annual bonus.