About this role
Chief Analyst, Cyber Security Operations Primary Responsibilities / Key Results Areas Security Monitoring, Detection Engineering and Threat Hunting Own and continuously improve security monitoring capabilities across SIEM, EDR, SOAR and related security platforms. Lead the design, implementation, tuning and lifecycle management of detection use cases to improve visibility across endpoint, network, cloud, identity and application environments. Drive improvements in detection logic, correlation rules, log onboarding, alert quality and operational runbooks to ensure effective and actionable monitoring. Partner with technology teams to onboard and validate security telemetry and support proactive threat hunting activities using threat intelligence, attacker techniques and operational insights. Incident Response and Technical Leadership Act as the lead technical authority for high-impact and complex security incidents. Manage investigations from initial triage through containment, eradication, recovery and post-incident review while ensuring timely, coordinated and effective response actions. Provide expert guidance during critical incidents, support the on-call function, and continuously improve incident response processes, playbooks, escalation paths and operational readiness. Digital Forensics, Malware Analysis and Reverse Engineering Lead advanced technical investigations across Windows, Linux, cloud and enterprise environments. Conduct and oversee digital forensic activities, including evidence preservation, collection, analysis and interpretation. Provide hands-on expertise in malware analysis, malware deconstruction and reverse engineering. Analyse suspicious files, identify attacker techniques and indicators of compromise, and translate findings into improved detections, threat intelligence, containment strategies and analyst training. Serve as the technical lead for complex malware investigations and guide analysts through advanced forensic and reverse engineering activities when required. Security Operations Maturity and Automation Drive the continuous improvement of Cyber Security Operations capabilities, processes and tooling. Own the lifecycle of automation playbooks and use cases to improve efficiency, scalability and response effectiveness. Automate and optimize security operations platforms, including SIEM, SOAR, EDR, sandboxes and forensic tooling. Use scripting and automation to reduce manual effort, accelerate investigations and improve operational outcomes. Vulnerability Management and Technical Risk Review Support and enhance the vulnerability management program by identifying, prioritizing and tracking vulnerabilities across systems, applications and services. Provide technical risk assessments, remediation guidance and vulnerability prioritization based on exploitability, threat intelligence, business impact and asset criticality. Support vulnerability review forums, remediation tracking and compliance-related activities. Threat Intelligence and Security Improvement Collect, analyse and operationalize threat intelligence from incidents, malware investigations, threat feeds and other relevant sources. Ensure intelligence is transformed into actionable improvements across monitoring, detection engineering, incident response, threat hunting and vulnerability management. Share relevant intelligence with internal stakeholders and external partners where appropriate. Analyst Development and Knowledge Transfer Act as a technical mentor and role model for the Cyber Security Operations team. Coach analysts during investigations, improve investigation quality standards and support consistent technical practices across the team. Develop training material, knowledge articles, operational guidance and structured learning programs. Lead by example through hands-on technical work while helping analysts build expertise in incident response, forensics, malware analysis, detection engineering and security operations technologies. Documentation and Stakeholder Engagement Create and maintain policies, procedures, playbooks, runbooks and technical documentation that support Cyber Security Operations activities. Work closely with stakeholders across the organization to communicate risks, investigation findings and remediation recommendations. Translate complex technical issues into clear and actionable information for both technical and non-technical audiences. Competencies • Strong analytical and problem-solving skills with the ability to lead complex technical investigations. • High degree of autonomy, ownership and technical leadership. • Excellent incident coordination, stakeholder management and communication skills. • Strong focus on continuous improvement, automation and operational excellence. • Ability to manage multiple priorities and perform effectively under pressure. • Excellent mentoring, coaching and knowledge-sharing capabilities. • Strong collaboration skills and the ability to influence stakeholders across the organization. Qualifications and Experience Required • Bachelor's degree in Cyber Security, Computer Science, Information Technology or a related field, or equivalent professional experience. • 6–10 years of experience in Cyber Security Operations, Incident Response, Digital Forensics, Detection Engineering or related disciplines. • Strong hands-on experience with SIEM, SOAR, EDR, security monitoring, alert triage and detection engineering. • Advanced expertise in Windows and Linux security, incident investigation and digital forensics. • Proven experience leading complex or high-impact security incidents. • Strong experience in malware analysis, malware deconstruction and reverse engineering. • Experience with vulnerability management, threat intelligence and technical risk assessment. • Knowledge of cloud, network, application, endpoint and identity security. • Scripting or programming experience using languages such as Python, PowerShell, Bash, SQL or C/C++. • Ability to participate in an on-call rotation and support critical incident response activities. • Fluent English communication skills. div.content { background: #FFFFFF; } div.joqReqDescription { background: #FFF repeat-y!important; font-family:Arial, Helvetica, sans-serif!important; text-align:left; color:#000; width:700px!important; margin:0 auto!important; position:relative; -webkit-column-count: 1; /* Chrome, Safari, Opera */ -moz-column-count: 1; /* Firefox */ column-count: 1; padding-top:0px; padding-left: inherit; padding-bottom:50px; font-size:14px } div.joqReqDescription div.image-box { width: 700px; text-align: center; display: block; padding: 0 0 35px; } div.joqReqDescription p, div.joqReqDescription ul{ font-family:Arial, Helvetica, sans-serif!important; margin:0 15px; padding-bottom:12px; } div.joqReqDescription li{ padding-bottom:6px; } /* position: absolute; height: 389px; } div.joqReqDescription div.imagebox2 { text-align:center; } */ SES and its Affiliated Companies are committed to providing fair and equal employment opportunities to all. We are an Equal Opportunity employer and will consider all qualified applicants for employment without regard to race, color, religion, gender, pregnancy, sex, sexual orientation, gender identity, national origin, age, genetic information, protected veteran status, disability, or any other basis protected by local, state, or federal law. For more information on SES, click here .