Senior Security Analyst, MDR
Posted 3ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Security Analyst leading cloud, identity, endpoint, and SaaS investigations for Artemis's AI-driven defense platform. Shaping Apollo's managed detection and response service.
Responsibilities:
- Lead investigations across cloud, identity, endpoint, and SaaS
- Own cases from pickup to closure, determining impact, blast radius, verdict, and severity
- Reconstruct attacker activity including initial access, lateral movement, persistence, and exfiltration
- Combine AI-assisted investigation with hands-on log analysis
- Recommend and execute containment within customer-authorized limits
- Communicate recommended actions, impact, and next steps to customers
- Work according to risk and severity response targets
- Provide customer-facing summaries, reasoning, and final analysis
- Conduct hypothesis-driven and AI-assisted threat hunts
- Turn threat-hunting findings into new cases and detections
- Help design Apollo's investigative standards, response workflows, reporting, and analyst console
- Feed verdicts, reasoning, and recognized patterns into detection engineering and product improvements
Requirements:
- 4+ years of hands-on security operations experience in a SOC, MSSP, or MDR environment
- Senior or Tier 3 experience where investigations ended with your decision
- Investigation experience across Okta, Entra ID, AWS, Azure, GCP, EDR, Microsoft 365, and Google Workspace
- Fluency in MITRE ATT&CK and attacker tactics, techniques, and procedures
- Strong evidence-based investigation skills
- Hands-on experience with AI-assisted investigation or automation
- Customer-facing experience explaining live security situations and recommended actions
- Excellent written communication
- Comfortable working a defined shift as analyst coverage expands to 24x7
- Bonus: multi-tenant MDR or MSSP experience
- Bonus: experience writing or tuning Sigma, YARA-L, SPL, KQL, or similar detection rules
- Bonus: incident command experience, including customer executive briefings
- Bonus: dedicated threat hunting or DFIR background
- Bonus: daily hands-on use of AI or agentic coding tools
Benefits:
- Join early enough to shape the service, standards, and customer experience
- Meaningful real-world impact protecting companies and their employees
- Broad experience across cloud, identity, endpoint, SaaS, and attacker behavior
- Exposure to AI-native security operations and emerging technology
- Innovative culture with open communication, mentorship, and learning
- Autonomy to drive investigations, shape the platform, and own outcomes


















