Senior Cyber Operations Analyst
- Hiring from
- United States
- Work type
- Remote
- Posted
- Sep 23, 2026
Why CDM Smith?
Check out this video and find out why our team loves to work here!Join Us! CDM Smith – where amazing career journeys unfold.Imagine a place committed to offering an unmatched employee experience. Where you work on projects that are meaningful to you. Where you play an active part in shaping your career journey. Where your co-workers are invested in you and your success. Where you are encouraged and supported to do your very best and given the tools and resources to do so. Where it’s a priority that the company takes good care of you and your family.Our employees are the heart of our company. As an employer of choice, our goal is to provide a challenging, progressive and inclusive work environment which fosters personal leadership, career growth and development for every employee. We value passionate individuals who challenge the norm, deliver world-class solutions and bring diverse perspectives. Join our team, and together we will make a difference and change the world.
Job Description
The Senior Cyber Operations Analyst is an experienced team member responsible for monitoring, detecting and responding to cybersecurity threats and incidents in a fast-paced environment. This role requires advanced skills in analyzing, triaging and resolving investigations and incidents. The senior analyst uses a combination of commercial and open-source tools, including AI-powered solutions, to automate repetitive tasks, enhance threat detection and improve response effectiveness. They correlate alerts and events, execute queries and apply behavior-based and anomaly detection techniques to support timely response actions. This role requires experience across multiple technologies, including SOARs, SIEMs, MCP solutions, endpoints, applications, network devices, cloud infrastructure and threat intelligence feeds. As a senior team member, the analyst also supports escalation workflows, assists less experienced analysts, and handles complex incidents.
The senior analyst is also responsible for mentoring junior team members to strengthen overall team capability. In this role, they will identify opportunities to use automation technologies & [RJ1] AI to automate repetitive tasks, enabling the team to focus on more complex analysis and response activities, which contributes to a more resilient security posture. The senior analyst operates in a cross-functional capacity, working across diverse technologies to support and secure business operations. They are expected to apply critical thinking and serve as the human in the loop when using AI-enabled tools and making security decisions. Strong communication skills are essential, along with the ability to understand and respond to emerging cybersecurity threats at scale. This role operates within an advanced cybersecurity program designed to keep pace with adversaries using both traditional and AI-enabled attack techniques. The role reports to the manager or director of security operations.
- Serve as a subject matter expert for a team of analysts supporting managed 24/7/365 monitoring and response operations.
- Investigate and respond to cybersecurity incidents, including participating in off-hours and on-call rotations.
- Act as an escalation point for day-to-day SOC operations and identify opportunities to automate.
- Assess program strengths and weaknesses and recommend AI solutions to improve team skills and knowledge.
- Stay current on emerging cybersecurity threats, AI developments, risks and vulnerabilities that may impact services.
- Automate repetitive tasks within SOAR environments using Cloud technologies, ML and AI to improve efficiency.
- Develop detection capabilities aligned with the MITRE ATT&CK framework and enhance them using automation/AI.
- Validate alerts by interpreting confidence scores, risk ratings and recommended actions.
- Use NLP tools to analyze events alongside threat intelligence data.
- Improve AI model performance and alert tuning by labeling events and validating true and false positives.
- Use multiple-agent collaboration using MCP solutions within security workflows.
- Collaborate with data science and engineering teams to improve AI models used in SOC operations.
- Refine playbooks, policies, procedures and guidelines in alignment with industry best practices and AI capabilities.
- Partner with security engineering, incident response and IT teams to improve monitoring, workflows and response processes.
- Support the development and tracking of metrics, KPIs and service-level objectives for security events.
- Participate in tabletop exercises to identify gaps, improve skills and strengthen communication.
- Review reports from tabletop exercises, vulnerability assessments and penetration tests to drive improvements.
- Evaluate logging coverage to identify potential gaps in detection capabilities.
- Examine log data across endpoints, databases, applications, identity systems, networks, mobile platforms and cloud environments.
- Recommend adjustments to security tools to reduce false positives.
- Provide guidance on monitoring, logging, identity, data protection and detection strategies, including preventive controls.
- Report on SOC performance and posture to cybersecurity leaders and stakeholders as needed.
#LI-LP1
#LI-REMOTE
Skills & Abilities
- Experience in SOC monitoring and response or related experience.
- Working knowledge of ML and AI, as well as their application in security operations.
- Experience using NLP, query construction and AI-powered tools to analyze logs, threat intelligence and incident data.
- Experience using MCP servers and purpose-built agents to support investigation and response activities.
- Hands-on experience with AI assistants and platforms for investigation, security analysis and response.
- Demonstrated technical understanding of emerging cybersecurity threats, including adversary use of AI.
- Ability to develop detections aligned with the MITRE ATT&CK framework and relevant open-source AI frameworks.
- Proficient in scripting languages such as Python, Bash, JavaScript or PowerShell, as well as experience with KQL.
- Experience with SOAR, SIEM, threat intelligence platforms, identity systems, sandboxes, vulnerability management and EDR/XDR tools.
- Strong understanding of threats, vulnerabilities, and incident response principles.
- Familiar with one or more frameworks or regulations, such as CMMC, NIST CSF, CIS, GDPR, CCPA.
- Strong judgment and ability to make timely decisions in complex situations.
- Experience with Azure, AWS, and GCP. Bonus points for Gov Cloud deployments
- Experience managing/collaborating with MSSPs
- Exceptional written and verbal communication skills across multiple levels of the organization.
- Excellent written and verbal communication skills, with the ability to clearly communicate cybersecurity incidents and document post-incident reviews and root cause analyses.
- Strong analytical and problem-solving skills, with the ability to evaluate complex issues and recommend practical solutions.
- Highly organized and efficient, with the ability to manage multiple priorities and meet deadlines in a fast-paced environment.
- Ability to apply both strategic and tactical thinking to support effective security operations and continuous improvement.
- Ability to remain calm and focused under pressure while managing time-sensitive priorities and deadlines.
- Effective decision-making skills in complex and time-sensitive situations.
Qualifications
- Bachelor's degree.
- 6 years of related experience.
- Equivalent additional directly related experience will be considered in lieu of a college degree.
Domestic and/or international travel may be required. The frequency of travel is contingent on specific duties, responsibilities, and the essential functions of the position, which may vary depending on workload and project demands.
Preferred Qualifications
- One or more GIAC certifications: GCED, GCIH, GDAT, Microsoft Security Operations Analyst Associate
- Experience managing security information and event management (SIEM) systems, threat intelligence platforms, security automation and orchestration solutions, intrusion detection and prevention systems (IDS/IPS), file integrity monitoring (FIM), data loss prevention (DLP) and other network and system monitoring tools.
- Experience in investigations using formal chain-of-custody methods, forensic tools and best practices.