Lead Security Operations Analyst
Houston, TX Direct-Hire $110000.00 - $150000.00 Hybrid

Job Description

Title: Lead Security Operations Analyst

Location: Houston, TX or Austin, TX (Must reside locally for occasional in-person office meetings; otherwise offers work-from-home flexibility)

Employment Type: Full-Time

Industry: Professional Services / Enterprise Environment

Compensation: $110,000 - 150,000 + Comprehensive Benefits Package

No C2C at this time

Overview

Our client is seeking a Senior Information Security Analyst to join a mature and growing Security Operations team responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across a global enterprise environment.

This is an opportunity for a hands-on security professional who enjoys leading investigations, mentoring analysts, improving detection capabilities, and helping shape the future of security operations. The ideal candidate will bring deep experience working within Microsoft security technologies and can operate independently in a fast-paced environment with minimal oversight.

The team is heavily invested in security automation, threat detection, Microsoft Sentinel, Microsoft Defender, and AI-enabled security operations, creating an opportunity to contribute to both day-to-day security operations and long-term strategic security initiatives.

Responsibilities

  • Lead investigation and response efforts for complex security incidents across endpoint, cloud, identity, email, and network environments.
  • Monitor, triage, and investigate security alerts generated by SIEM, EDR, and other security monitoring tools.
  • Serve as a technical escalation point and mentor for junior security analysts.
  • Conduct proactive threat hunting activities to identify malicious activity not detected through existing controls.
  • Build, tune, and maintain detection rules, monitoring logic, and security use cases.
  • Support phishing, impersonation, business email compromise, and social engineering investigations.
  • Develop and improve security automation workflows, response playbooks, and SOAR capabilities.
  • Collaborate with security, infrastructure, cloud, and IT teams to strengthen defensive capabilities and improve security posture.
  • Perform forensic analysis and support evidence preservation activities when required.
  • Maintain and improve operational procedures, security documentation, and incident response processes.
  • Participate in an on-call rotation supporting critical security incidents.

Required Qualifications

  • 5+ years of experience within Security Operations, Security Engineering, Incident Response, Cybersecurity, or a related discipline.
  • Strong hands-on experience with Microsoft Sentinel and Microsoft Defender.
  • Experience leading security investigations from detection through containment, remediation, and recovery.
  • Working knowledge of SIEM, EDR, IDS/IPS, email security, and threat detection technologies.
  • Experience investigating phishing attacks, account compromise incidents, and identity-based threats.
  • Strong understanding of Microsoft 365, Microsoft Entra ID (Azure AD), Active Directory, and cloud security concepts.
  • Experience utilizing ServiceNow or similar ticketing/service management platforms.
  • Strong written and verbal communication skills.
  • Ability to work independently and take ownership of issues through resolution.

Preferred Qualifications

Candidates should possess strong expertise in one or more of the following disciplines:

  • Identity & Access Security
  • Cloud Security (Azure, AWS, or GCP)
  • Windows and Linux Security Operations
  • Detection Engineering
  • Security Automation and SOAR
  • Threat Hunting

Additional experience with the following is highly desirable:

  • KQL (Kusto Query Language)
  • PowerShell and/or Python
  • Security automation playbooks
  • MITRE ATT&CK Framework
  • Microsoft Security ecosystem technologies
  • AI-assisted security operations and automation

Preferred Certifications

  • Microsoft SC-200
  • Microsoft SC-300
  • Microsoft AZ-500
  • CompTIA Security+
  • CISSP
  • CCSP
  • GCIH
  • GSOC
  • GCFA
  • GCFE
  • Other cybersecurity and cloud security certifications

Ideal Candidate

The ideal candidate:

  • Thrives in a Security Operations Center (SOC) environment.
  • Can independently manage investigations with minimal oversight.
  • Possesses strong analytical and troubleshooting skills.
  • Enjoys mentoring and developing junior team members.
  • Communicates effectively with both technical and non-technical stakeholders.
  • Takes ownership and follows issues through to resolution.
  • Is passionate about continuous improvement, automation, and security innovation.
  • Works collaboratively within global teams and cross-functional environments.

What You'll Gain

  • Exposure to a large-scale enterprise cybersecurity environment.
  • Opportunities to influence detection, response, and security automation strategies.
  • Access to advanced Microsoft security technologies.
  • Collaborative and highly skilled cybersecurity team environment.
  • Long-term career growth within an established organization.
  • Hands-on involvement in automation, AI-enabled security operations, detection engineering, and threat hunting initiatives.

All qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status. We consider all qualified applicants, including those with criminal histories, in a manner consistent with state and local laws, including the California Fair Chance Act, City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, Los Angeles County Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.

Job Reference: JN -082026-429512