Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Core Specialty Insurance Holdings, Inc.

Senior Security Operations Analyst

Core Specialty Insurance Holdings, Inc.

. Investigate escalated alerts, validate threats, and perform deep-dive forensic analysis using SIEM, EDR, and threat intelligence tools .

Posted 10/6/2026full-timeCincinnati • Ohio • United StatesSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in incident response, threat analysis, and security automation, with a strong focus on SIEM and EDR tools. Capable of leading containment efforts, developing security workflows, and collaborating with cross-functional teams to enhance security posture.

Highest-signal resume keywords
SIEM Platform ExpertiseEDR Tool ProficiencySecurity Automation Workflow DesignSQL/KQL Query SkillsMITRE ATT&CK Framework Knowledge

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Incident ResponseThreat AnalysisForensic AnalysisNetwork Traffic AnalysisMalware AnalysisPython ScriptingPowerShell ScriptingBehavioral AnalyticsSecurity Tool TuningCloud Security Monitoring
Soft Skills
Excellent CommunicationDocumentation SkillsTeam CollaborationTraining and Mentoring
Tools & Technologies
SIEM ToolsEDR ToolsThreat Intelligence PlatformsAutomation WorkflowsCIS Benchmarks
Certifications & Qualifications
GCIHGCIACEHCompTIA CySA+CISSP
Industry Keywords
SOC OperationsCybersecurityIncident ResponseCyber Kill ChainCIS Benchmarks

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityGoogle Cloud PlatformPythonSQL

About the role

Key responsibilities & impact
  • Investigate escalated alerts, validate threats, and perform deep-dive forensic analysis using SIEM, EDR, and threat intelligence tools
  • Lead containment and remediation efforts for escalated incidents across multiple environments
  • Develop and tune SIEM use cases, correlation rules, and EDR detection logic
  • Design and implement automation workflows for incident response and investigations
  • Leverage AI platforms to automate SOC processes
  • Conduct proactive threat hunts using behavioral analytics and intelligence feeds
  • Collaborate with IT, network, and security engineering teams to contain incidents and strengthen defenses
  • Maintain and enhance SOC playbooks, runbooks, and SOPs
  • Prepare incident reports, root cause analyses, and preventive recommendations
  • Train and guide L1 analysts
  • Assess and recommend new security technologies and measures
  • Maintain endpoint security baselines aligned with CIS benchmarks
  • Support integration and operations of a new primary EDR/SIEM platform
  • Partner with IT operations to test and deploy endpoint security changes safely
  • Act as a senior technical escalation point during security incidents
  • Contribute to incident response playbooks and post-incident reviews
  • Produce technical documentation including security architecture diagrams, SOPs and runbooks, policy rationale and audit artifacts, and incident timelines

Requirements

What you’ll need
  • Onsite Monday through Friday in the Cincinnati office; not a hybrid or remote role
  • Applicants must be authorized to work for any employer in the U.S.; no sponsorship or transfer of work authorization is available now or in the future
  • Bachelor’s degree in Cybersecurity, Computer Science, IT, or equivalent practical experience
  • 3+ years of experience in SOC operations, cybersecurity, or incident response
  • Strong understanding of SIEM platforms, EDR tools, and network monitoring solutions
  • Experience maintaining and tuning security tools, alert logic, security settings, and IOC blocks
  • Proven experience designing and implementing security automation workflows
  • Strong SQL/KQL query capabilities
  • Deep knowledge of MITRE ATT&CK and Cyber Kill Chain frameworks
  • Ability to analyze network traffic, logs, and host-based artifacts
  • Ability to work in a fast-paced 24x7 environment with rotational on-call coverage
  • Excellent communication and documentation skills
  • Experience with malware analysis or reverse engineering
  • Experience with Python and PowerShell scripting for automation and SOC process improvement
  • Familiarity with threat intelligence platforms and integration
  • Experience in cloud security monitoring across AWS, Azure, and GCP
  • Certifications such as GCIH, GCIA, CEH, CompTIA CySA+, or CISSP preferred

Benefits

Comp & perks
  • Competitive salary
  • Professional development and advancement opportunities
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • Short-term disability
  • Long-term disability
  • Company-match of 100% of a 6% contribution 401(k) plan
  • Employee Assistance Plan
  • Health Savings Account
  • Flexible Spending Account
  • Health Reimbursement Account
  • Wellness program