FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in security operations, particularly in leading investigations across cloud environments and identity management. Proficient in AI-assisted investigations, threat hunting, and effective communication of security findings to customers.
Highest-signal resume keywords
Security Operations ExperienceInvestigation Across Cloud EnvironmentsFluency In MITRE ATT&CKAI-Assisted Investigation SkillsCustomer-Facing Communication
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Investigation SkillsThreat HuntingIncident Command ExperienceDetection Rule WritingLog Analysis
Soft Skills
Excellent Written CommunicationCustomer Interaction
Tools & Technologies
OktaAWSAzureGCPMicrosoft 365Google WorkspaceEDR
Industry Keywords
SOCMSSPMDRAI-Assisted InvestigationMulti-Tenant Environments
Tech Stack
Tools & technologiesApolloAWSAzureCloudGoogle Cloud Platform
About the role
Key responsibilities & impact- Lead investigations across cloud, identity, endpoint, and SaaS
- Own cases from pickup to closure, determining impact, blast radius, verdict, and severity
- Reconstruct attacker activity including initial access, lateral movement, persistence, and exfiltration
- Combine AI-assisted investigation with hands-on log analysis
- Recommend and execute containment within customer-authorized limits
- Communicate recommended actions, impact, and next steps to customers
- Work according to risk and severity response targets
- Provide customer-facing summaries, reasoning, and final analysis
- Conduct hypothesis-driven and AI-assisted threat hunts
- Turn threat-hunting findings into new cases and detections
- Help design Apollo's investigative standards, response workflows, reporting, and analyst console
- Feed verdicts, reasoning, and recognized patterns into detection engineering and product improvements
Requirements
What you’ll need- 4+ years of hands-on security operations experience in a SOC, MSSP, or MDR environment
- Senior or Tier 3 experience where investigations ended with your decision
- Investigation experience across Okta, Entra ID, AWS, Azure, GCP, EDR, Microsoft 365, and Google Workspace
- Fluency in MITRE ATT&CK and attacker tactics, techniques, and procedures
- Strong evidence-based investigation skills
- Hands-on experience with AI-assisted investigation or automation
- Customer-facing experience explaining live security situations and recommended actions
- Excellent written communication
- Comfortable working a defined shift as analyst coverage expands to 24x7
- Bonus: multi-tenant MDR or MSSP experience
- Bonus: experience writing or tuning Sigma, YARA-L, SPL, KQL, or similar detection rules
- Bonus: incident command experience, including customer executive briefings
- Bonus: dedicated threat hunting or DFIR background
- Bonus: daily hands-on use of AI or agentic coding tools
Benefits
Comp & perks- Join early enough to shape the service, standards, and customer experience
- Meaningful real-world impact protecting companies and their employees
- Broad experience across cloud, identity, endpoint, SaaS, and attacker behavior
- Exposure to AI-native security operations and emerging technology
- Innovative culture with open communication, mentorship, and learning
- Autonomy to drive investigations, shape the platform, and own outcomes
