SOC Analyst Job at Mondo, Denver, CO

  • Mondo
  • Denver, CO

Job Description

Job Title: Lead Security Analyst
Location: Remote
Start Date: ASAP
Duration: 3 Month Contract-to-Hire
Compensation: $70-80/hr
Benefits: Eligible for Health, Dental, Vision, 401K

Job Description:
Our client, a large emergency medical services and transportation organization, is seeking a Lead Security Analyst with a strong SIEM engineering background. This role is heavily focused on the engineering side of the SIEM, including log onboarding and data source integration, rather than day-to-day analyst triage. The ideal candidate deeply understands how the SIEM works under the hood and can investigate logs, tables, and data to quickly identify attackers and attack vectors, while also supporting incident response efforts.

Day-to-Day Responsibilities:

  • Own the engineering and onboarding of new log sources and data connections into the SIEM (firewalls, EDR, cloud platforms, identity telemetry)
  • Maintain a deep understanding of how the SIEM works and how the SOC uses it, ensuring log/data health across sources
  • Assist with tuning detection logic and alerts, and support automation efforts to enable rapid response
  • Proactively engage technical and non-technical teams to onboard additional logs and maintain log health
  • Investigate logs (tables, columns, values) to identify attackers and attack vectors, supporting quick containment
  • Support incident response and act as a technically strong partner to the incident commander
  • Develop automation and integration scripts to enhance SOC workflows
  • Communicate consistently with the team through updates, feedback, and delivery of tangible work product
  • Partner cross-functionally with Infrastructure, Compliance, and Operations teams
  • Assist with documentation, reporting, runbooks, and SOPs

Minimum Requirements:

  • 5 years of security operations experience; 7 years of broad IT experience
  • Strong hands-on SIEM engineering background, especially log onboarding and data source integration (Microsoft Sentinel preferred)
  • Deep understanding of the mechanics of how a SIEM works and how a SOC uses it
  • Deep Microsoft ecosystem expertise, including Azure - considered a critical, non-negotiable component of this role
  • Experience assisting with detection tuning, alerting, and automation for rapid response
  • Strong PowerShell scripting skills
  • KQL (log query language)
  • Outgoing, proactive communicator able to work with both technical and non-technical teams
  • Consistently engaged team player who provides regular updates and delivers tangible work
  • Experience supporting enterprise environments of 35,000 users
Preferred Qualifications:
  • Bash scripting
  • Python scripting
  • Experience with CrowdStrike or other enterprise EDR platforms
  • Experience with Microsoft Copilot for Security or similar AI security tooling
  • Familiarity with healthcare or regulated environments (HIPAA, PCI)

Job Tags

Contract work, Immediate start

Similar Jobs

Kaiser Permanente

Seasonal RN Program - MST- Zion Job at Kaiser Permanente

 ...purpose, side effects, and administration instructions in the hospital as well as at the time of discharge . Documentation: Charting...  ...from start date. RN-s will be UNAC/UHCP or SEIU Local 121 union dues paying members. The initiation fee will be waived. Position... 

Mattel

Key Account Manager - Walmart Job at Mattel

 ...company, is seeking a high-impact Key Account Manager to lead the Walmart Dolls IP business and drive profitable growth across one of...  ...are sold in collaboration with the worlds leading retail and ecommerce companies. Since its founding in 1945, Mattel is proud to be a... 

GreenState Credit Union

Director Talent Acquisition (North Liberty) Job at GreenState Credit Union

 ...GreenState Credit Union Director Talent Acquisition US-IA-North Liberty Job ID: 2026-4717# of Openings: 1 Category: Human Resources GreenState Credit Union Overview The Director of Talent Acquisition provides strategic leadership for all talent... 

Binance

Binance Accelerator Programm - Software Engineer (Convert) Job at Binance

 ...industry-leading security, transparency, trading engine speed, protections for investors, and...  ...Binance Accelerator Program (BAP) is a 3-6 month internship program designed for Early Career talent to have firsthand experience in the rapidly expanding digital assets space... 

General Dynamics Information Technology

Information Systems Security Officer (ISSO) II Job at General Dynamics Information Technology

Public Trust: None Requisition Type: Regular Your Impact Own your opportunity to support our nation's defense. Make an impact by connecting and securing critical operations across the globe, keeping our country safe and secure. Job Description The ISSO...