SPS Commerce is a leading provider of cloud-based supply chain management solutions, serving a global network of retail trading partners. The Senior Security Analyst will lead detection and response efforts, manage the SOC queue, and collaborate across various security domains to enhance threat detection and incident response capabilities.
Responsibilities:
- Lead alert triage and investigation: Serve as the escalation point for alerts raised by the managed SOC and monitoring systems. Pull together the full picture from whatever the investigation calls for: SIEM, EDR, identity and authentication activity, cloud audit trails, network and email telemetry, and other sources as the evidence leads. Reach accurate, defensible determinations under time pressure and decide what warrants escalation to a full incident
- Run incident response: Take point on confirmed higher-severity incidents: scoping, containment, coordinating with affected stakeholders, and keeping leadership informed with clear, timely updates. Document incidents thoroughly and drive them to genuine closure, not just ticket closure
- Hunt for what monitoring misses: Perform proactive threat hunting informed by current threat intelligence, surfacing coverage gaps and emerging risk before they become incidents
- Work AI and automation into the daily craft: Use AI-assisted tooling to accelerate investigation, summarization, and documentation, and identify where AI and automation can reduce repetitive manual work, speed response, or close gaps—partnering with engineering to make it real
- Partner across the team: Collaborate with exposure management on triage, prioritization, and remediation tracking, and work with security engineering and cloud security where investigations and detections cross over
- Sharpen detections and tooling: Execute established runbooks, identify stale or missing guidance, and feed concrete improvement requests back to engineering to strengthen detections, automations, and documentation
- Develop the SOC: Review SOC determination and escalation quality and provide coaching and feedback that helps analysts grow
- Participate in the team's on-call rotation
- Perform other duties as assigned
Requirements:
- 5+ years in security operations, incident response, or threat detection, with senior-level depth in digital forensics and incident response (DFIR) and SOC work
- Hands-on investigation experience with a SIEM and an EDR platform—the specific products matter less than the ability to search, pivot across identity, cloud, and network log sources, and scope an incident end to end
- Sound evidence-handling practice and forensic fundamentals, including preserving and reasoning over disk, memory, and log artifacts
- A working understanding of adversarial behavior (e.g., MITRE ATT&CK)
- Working familiarity with exposure management workflows—triage, prioritization, and remediation tracking
- Clear written and verbal communication, with the judgment to brief both engineers and executives appropriately
- A collaborative working style and genuine curiosity about security and technology—a seasoned professional who exercises sound judgment and collaborates effectively across a larger organization
- Internal candidates: SOC, security operations, or security engineering experience handling escalated investigations or incident response and working across detection, vulnerability management, or cloud security functions, with at least 1 year of SPS experience
- Key Skills: Digital forensics and incident response (DFIR), SIEM/EDR investigation, threat hunting, adversarial behavior analysis (MITRE ATT&CK), cloud security monitoring, cross-team communication and executive briefing
- Experience with Crowdstrike as an EDR platform
- Experience with SOAR platforms
- Experience with Crowdstrike NG-SIEM
- Cloud security monitoring experience, primarily AWS, with some exposure to Azure and GCP, and container environments such as EKS
- Windows Defender XDR
- Python programming experience for scripting, automation, or tooling
- Familiarity with infrastructure-as-code (e.g., Terraform, CloudFormation) and CI/CD pipelines, and how to investigate and secure them
- Familiarity with one or more of Oracle, Snowflake, Databricks, and the Atlassian suite
- Proactive threat hunting and threat-intelligence experience