Position Summary
The Senior Security Operations Center (SOC) Analyst at Copperleaf plays a critical role in protecting our global SaaS platform, internal systems, and customer environments. This role requires deep technical expertise in cloud鈥慶entric security operations, advanced detection and response, and strong familiarity with enterprise technologies that support Copperleaf鈥檚 product ecosystem and operational security.
Senior Analysts lead complex investigations, support continuous operational improvement, and strengthen our ability to rapidly detect and respond to threats targeting cloud workloads (Azure), identity systems (Azure AD/Entra ID), clusters, endpoint platforms, and customer鈥慽ntegrated data pipelines. This role also mentors junior analysts and collaborates closely with Security Engineering, CloudOps, IT, and Incident Response to improve detection logic, logging visibility, automation, and resiliency across Copperleaf鈥檚 environment.
Key Responsibilities
Leadership & Team Support
Act as a senior escalation point for SOC investigations, providing guidance aligned to Copperleaf鈥檚 security architecture and operational practices.
Mentor junior analysts and help drive team maturity in cloud security, detection engineering, and SaaS鈥憇pecific monitoring.
Recommend training and process enhancements to support ongoing professional development.
Participate in tabletop exercises tailored to Copperleaf鈥檚 product, cloud, and operational risk scenarios.
Security Monitoring & Incident Response
Lead investigations into security alerts across Copperleaf鈥檚 Azure鈥慼osted environments, identity systems, corporate endpoints, and product infrastructure.
Support incident response activities including containment, remediation, documentation, and lessons鈥憀earned.
Analyze logs from Azure Monitor, Entra ID, Kubernetes clusters, application services, and customer鈥慺acing integrations.
Create detections mapped to MITRE ATT&CK for cloud and SaaS environments.
Maintain and improve SOC playbooks and SOPs specific to Copperleaf鈥檚 operational, compliance, and customer commitments.
Recommend tuning of cloud-native and third鈥憄arty detection tools to reduce false positives.
Threat Intelligence, Detection Engineering & Automation
Track emerging threats relevant to SaaS providers, cloud platforms, Kubernetes, identity infrastructure, and AI鈥慸riven attack techniques.
Conduct proactive threat hunting across cloud workloads, identity logs, endpoints, and product telemetry.
Develop and refine KQL queries, automation workflows, and SOAR playbooks.
Evaluate logging coverage across Azure, product services, and corporate systems, ensuring alignment to Copperleaf鈥檚 observability standards.
Cross鈥慒unctional Collaboration
Collaborate with Security Engineering, CloudOps, IT, and Platform teams to enhance detection capabilities and ensure appropriate telemetry.
Contribute to operational KPIs, metrics, and reporting used for Copperleaf leadership updates.
Share insights, documentation, and best practices to support overall team improvement.
Partner with CloudOps and Engineering on secure configuration, operational visibility, and incident readiness.