# Senior Security Operations Analyst

**Company**: Anduril Industries
**Location**: Sydney, New South Wales
**Experience**: senior
**Job type**: full-time
**Category**: IT
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/andurilindustries/jobs/5047245007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_d853db77-7ce

## Description

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology.

Anduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defence technologies. As a SecOps analyst on the detection and response team, you'll be responsible for monitoring and responding to adversarial activity while helping incorporate key detection feedback loops with the detection engineering team.

## Responsibilities

- Triage and respond to alerts / incidents covering multiple disciplines including, but not limited to, phishing, endpoints, cloud infrastructure and services, and SaaS applications

- Build and optimise tailored detection signatures, response playbooks, and response automation using detection-as-code principles

- Lead the feedback loop for detections, ensuring alerts are fine tuned to reduce false positives

- Participate in threat modeling scenarios with cross-functional partners to understand weaknesses across Cloud, Mobile, Endpoints, and other environments incorporating findings into security controls and/or detection signatures

- Organise and conduct threat hunting and data baselines to identify anomalous patterns in data

- Participate in an on-call rotation responding to security events and conducting incident response investigations while effectively communicating findings to key stakeholders

- Proactively collaborate with a wide range of stakeholders

## Required Qualifications

- Experience in security monitoring, log analysis, and detection engineering within large data sets across endpoint, network, and a wide variety of application log sources

- Experience in Python development, specifically contributing to a shared codebase used for automating SOC operations

- Must have experience with one or more SIEM languages (SPL, KQL, SQL)

- Broad range of practical security knowledge across the spectrum of endpoint, network, identity, application, and cloud infrastructure

- Knowledge of attacker tactics, techniques, and procedures (TTPs) across Windows, Linux, MacOS, AWS/Azure, etc.

- Strong communication skills and experience collaborating with internal and external stakeholders

- Eligible to obtain and maintain an Australian NV2 clearance

## Preferred Qualifications

- Experience conducting incident response in the Cloud (AWS, Azure, GCP)

- Digital Forensics and/or reverse engineering experience is a plus!

The salary range for this role is highly competitive, and actual salary offer may vary based on work experience, education and/or training, critical skills, and/or business considerations. Anduril offers top-tier benefits for full-time employees, including comprehensive medical, dental, and vision plans, income protection, generous time off, family planning and parenting support, mental health resources, professional development, commuter benefits, relocation assistance, and retirement savings plans.

## Skills

### Required
- security monitoring
- log analysis
- detection engineering
- Python development
- SIEM languages (SPL, KQL, SQL)
- endpoint security
- network security
- cloud infrastructure
- communication skills

### Nice to have
- incident response in the Cloud (AWS, Azure, GCP)
- Digital Forensics
- reverse engineering

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/andurilindustries/jobs/5047245007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
