← Todos los empleos

Senior Security Analyst, MDR

Sobre el puesto

• Lead investigations across cloud, identity, endpoint, and SaaS
• Own cases from pickup to closure, determining impact, blast radius, verdict, and severity
• Reconstruct attacker activity including initial access, lateral movement, persistence, and exfiltration
• Combine AI-assisted investigation with hands-on log analysis
• Recommend and execute containment within customer-authorized limits
• Communicate recommended actions, impact, and next steps to customers
• Work according to risk and severity response targets
• Provide customer-facing summaries, reasoning, and final analysis
• Conduct hypothesis-driven and AI-assisted threat hunts
• Turn threat-hunting findings into new cases and detections
• Help design Apollo's investigative standards, response workflows, reporting, and analyst console
• Feed verdicts, reasoning, and recognized patterns into detection engineering and product improvements

• 4+ years of hands-on security operations experience in a SOC, MSSP, or MDR environment
• Senior or Tier 3 experience where investigations ended with your decision
• Investigation experience across Okta, Entra ID, AWS, Azure, GCP, EDR, Microsoft 365, and Google Workspace
• Fluency in MITRE ATT&CK and attacker tactics, techniques, and procedures
• Strong evidence-based investigation skills
• Hands-on experience with AI-assisted investigation or automation
• Customer-facing experience explaining live security situations and recommended actions
• Excellent written communication
• Comfortable working a defined shift as analyst coverage expands to 24x7
• Bonus: multi-tenant MDR or MSSP experience
• Bonus: experience writing or tuning Sigma, YARA-L, SPL, KQL, or similar detection rules
• Bonus: incident command experience, including customer executive briefings
• Bonus: dedicated threat hunting or DFIR background
• Bonus: daily hands-on use of AI or agentic coding tools

• Join early enough to shape the service, standards, and customer experience
• Meaningful real-world impact protecting companies and their employees
• Broad experience across cloud, identity, endpoint, SaaS, and attacker behavior
• Exposure to AI-native security operations and emerging technology
• Innovative culture with open communication, mentorship, and learning
• Autonomy to drive investigations, shape the platform, and own outcomes