Security Operations Analyst

Anduril Industries

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Costa Mesa, CA
Salary
$129,000–$171,000 / yr
Posted
21 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $155k
This role $150k
$109k most similar roles pay here $204k

This role pays less than 57% of similar roles. Most pay $127,762–$182,962 — the shaded band above. At the midpoint, this role pays about $150k versus about $155k for comparable roles.

Based on 238 similar postings.

Employer

About Anduril Industries

Anduril Industries is a defense technology company that builds advanced hardware and software systems for national security, including autonomous drones, surveillance systems, and the Lattice AI command platform.

Anduril Industries currently has 1697 open roles on FindRole.

Listed pay typically runs $146,000–$194,000 across 1504 roles with salary data.

Most-posted roles

View all roles at Anduril Industries

At a glance

TL;DR · Security Operations Analyst

The Security Operations Analyst joins the Detection and Response team to serve as a watchtower for critical defense technologies. This role involves monitoring and responding to adversarial activity, triaging incidents across phishing, endpoints, cloud infrastructure, and SaaS applications. The analyst will build and optimize detection signatures, response playbooks, and automation using detection-as-code principles while conducting threat hunting and data normalization to identify anomalies. Key responsibilities include participating in threat modeling, managing feedback loops for alert fine-tuning, and performing incident investigations. Required skills include experience with Python development, SIEM languages such as SPL, KQL, or SQL, and analysis within a data lake environment. The role requires expertise in Windows, Linux, MacOS, and cloud environments like AWS, Azure, or GCP to address security challenges across network, identity, and application infrastructures.

What you'll do

  • Triage and respond to security incidents across phishing, endpoints, cloud infrastructure, and SaaS applications.
  • Build and optimize detection signatures, response playbooks, and automation using detection-as-code principles.
  • Manage the feedback loop for detections to fine-tune alerts and reduce false positives.
  • Conduct threat modeling with cross-functional partners to identify weaknesses in various environments.
  • Perform threat hunting and data normalization to identify anomalous patterns and establish baselines.
  • Participate in an on-call rotation to investigate security events and communicate findings to stakeholders.
  • Develop Python code to automate SOC operations within a shared codebase.
  • Mentor and guide junior analysts while leading large-scale data baseline projects.

What we're looking for

  • Experience in security monitoring, log analysis, and detection engineering across endpoint, network, and various application sources.
  • Experience in Python development for automating SOC operations within a shared codebase.
  • Proficiency in one or more SIEM languages such as SPL, KQL, or SQL.
  • Experience conducting analysis within a data lake environment.
  • Broad practical security knowledge across endpoint, network, identity, application, and cloud infrastructure.
  • Knowledge of attacker tactics, techniques, and procedures (TTPs) across Windows, Linux, MacOS, AWS, and Azure.
  • Strong communication skills and experience collaborating with internal and external stakeholders.
  • Must be able to obtain and hold a U.S. Top Secret security clearance.
  • Experience conducting incident response in the Cloud (AWS, Azure, GCP) (preferred).
  • Digital Forensics and/or reverse engineering experience (preferred).

More like this

Similar roles

Security Operations Analyst

Anduril Industries

Boston, MA 21 days ago $129,000$171,000
Python SIEM SPL KQL SQL AWS Azure GCP Detection-as-Code Incident Response Threat Hunting Data Lake Linux Windows MacOS Digital Forensics Reverse Engineering

Security Operations Analyst

Anduril Industries

Washington, DC 21 days ago $129,000$171,000
Python SIEM SPL KQL SQL AWS Azure GCP Detection-as-Code Incident Response Threat Hunting Data Lake Linux Windows MacOS Digital Forensics Reverse Engineering Cloud Infrastructure

Security Operations Analyst

Anduril Industries

Seattle, WA 21 days ago $129,000$171,000
Python SIEM SPL KQL SQL AWS Azure GCP Detection-as-Code Incident Response Threat Hunting Log Analysis Data Lake Windows Linux MacOS Digital Forensics Reverse Engineering

Senior Security Analyst

Microsoft

22 days ago $119,800$234,700
Kusto SQL Azure M365 Sentinel Defender XDR MITRE ATT&CK SIEM GitHub Actions Entra ID Threat Hunting Root Cause Analysis Forensics Reverse Engineering AI Copilot
4+ yrs exp Hybrid

Information Security Risk Analyst

Lam Research

Tualatin, OR 57 days ago
SIEM Microsoft Sentinel Splunk KQL SPL SQL Python PowerShell MITRE ATT&CK UEBA Azure AWS Cloud Platform Entra ID Logic Apps MISP STIX/TAXII Threat Hunting Incident Response

Information Security Risk Analyst

Lam Research

Tualatin, OR 68 days ago
SIEM Microsoft Sentinel Splunk KQL SPL SQL Python PowerShell MITRE ATT&CK UEBA Azure AWS Cloud Platform Entra ID Logic Apps STIX/TAXII MISP Threat Hunting Incident Response
Hybrid