Overview WELCOME TO SITA At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry. You’ll find us in 95% of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We don’t just move the world forward—we’re proud to be recognized as a Great Place to Work® by our employees and certified in most of our growing locations. Here, we feel empowered, supported, and inspired to grow. Are you ready to love your job? The adventure begins right here, with you, at SITA. ABOUT THE ROLE & TEAM As Senior Security Analyst , you will perform advanced investigations and validation of security alerts and incidents to ensure accurate threat identification and effective response. You will play a key role in improving detection quality, monitoring effectiveness, and operational excellence across the Security Operations Center (SOC). You will be accountable for leading technical investigations, mentoring SOC Analysts, enhancing detection capabilities, and ensuring timely identification, analysis, escalation, and documentation of security incidents. Reporting to the Senior Manager, Service Operations, you will be part of the SOC Team , responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the enterprise while continuously improving SOC processes, tools, and capabilities. WHAT YOU WILL DO Serve as the primary escalation point for SOC Analysts during complex security investigations and incident analysis. Lead technical investigations of security alerts and incidents across endpoint, network, identity, cloud, and application environments. Validate alert classifications, severity ratings, incident scope, and escalation decisions to ensure investigation quality and consistency. Perform advanced correlation and analysis across SIEM, EDR/XDR, cloud, identity, network, and endpoint telemetry. Build investigation timelines, collect evidence, document findings, and support escalation decisions in accordance with incident response procedures. Escalate confirmed or suspected security incidents to the Security Incident Response Team (SIRT) and collaborate throughout the response lifecycle. Develop, maintain, optimize, and tune detection rules, correlation logic, SOC use cases, and investigation playbooks to improve detection effectiveness. Identify false positive trends, detection gaps, and monitoring deficiencies, and drive continuous improvements to monitoring capabilities. Mentor SOC Analysts through technical coaching, investigation support, quality reviews, and knowledge sharing. Support vulnerability management activities, cyber simulations, tabletop exercises, post-incident reviews, and continuous SOC improvement initiatives. WHO YOU ARE You have 3-5 years of experience as a SOC L2 Analyst or in an equivalent Security Operations role. You possess advanced experience investigating security events using SIEM and EDR/XDR platforms, preferably Elastic, Cortex XDR, Microsoft Defender XDR, and CrowdStrike Falcon. You have experience analyzing logs and telemetry from endpoints, identity platforms, cloud services, firewalls, proxies, DNS, VPN, and applications. You have proven experience developing, tuning, and optimizing detection rules, correlation logic, and SOC use cases. You demonstrate a strong understanding of the incident investigation, triage, escalation, and response lifecycle. You are proficient in security query languages such as KQL, Lucene, EQL, and Sigma. You have working knowledge of PowerShell and/or Python for security investigations, automation, and operational efficiency. You possess solid knowledge of Windows, Linux, Active Directory, Microsoft 365, Azure/AWS, networking, and common attack techniques. You have strong practical knowledge of the MITRE ATT&CK framework and its application to detection engineering and security monitoring. You hold a Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, along with at least one recognized cybersecurity certification such as SC-200, GCIH, GCIA, CySA+, or ECIH. NICE-TO-HAVE Experience supporting Vulnerability Management activities, including vulnerability validation, risk prioritization, and remediation tracking. Experience participating in cyber simulations, red-team exercises, tabletop exercises, and post-incident reviews. Familiarity with security automation, orchestration technologies, and operational reporting for SOC performance metrics. Qualifications WHAT WE OFFER We're all about diversity. We operate in 200 countries and speak 60 different languages and cultures. We're really proud of our inclusive environment. Our offices are comfortable and fun places to work, and we make sure you get to work from home too. Find out what it's like to join our team and take a step closer to your best life ever. 🏡 Flex Week: Work from home up to 2 days/week (depending on your team's needs) ⏰ Flex Day: Make your workday suit your life and plans. 🌎 Flex-Location: Take up to 30 days a year to work from any location in the world. 🌿 Employee Wellbeing: We have got you covered with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year. We also offer Champion Health - a personalized platform that supports a range of wellbeing needs. 🚀 Professional Development: At SITA, we believe growth fuels innovation. Our learning ecosystem offers access to world-class platforms and programs designed to help you thrive. From LinkedIn Learning, Microsoft's Enterprise Skills Initiative, and Airport Council International -available to all employees-to specialized solutions like Pluralsight for technology upskilling, Harvard Business Publishing for people leadership, Stanford for strategic development and many others, we align learning opportunities with your Development Plan and our business priorities. Your development journey is supported every step of the way. 🙌 Competitive Benefits: Competitive benefits that make sense with both your local market and employment status. SITA is an Equal Opportunity Employer. We value a diverse workforce. In support of our Employment Equity Program, we encourage women, aboriginal people, members of visible minorities, and/or persons with disabilities to apply and self-identify in the application process. Starting Compensation Starting Compensation Compensation Note Hidden (-999)
Security Analyst / SOC
Globalhub2 Sita
AI-First Social Media Analyst
Storm Ideas
Railway Systems Interface and Integration Manager
Honeywell
Staff Software Engineer (iOS)
Koinz
Revit Modeler / Drafter
Outsourcing Advantage
Expert Service Operations Security / SOC
Globalhub2 Sita