Security Operations Engineer

Astranis · San Francisco · Engineering

Posted 2026-07-20

Apply for this role →

Security Operations Engineer

Astranis is looking for a Security Operations Engineer who isn’t afraid to dive headfirst into the digital abyss. Our ideal candidate is a seasoned defender with the technical depth to not only triage complex threats but to oversee the very systems that keep us secure. As a Tier 2/3 escalation point, you will be the backbone of our defense, untangling advanced malware, neutralizing sophisticated phishing schemes, and leading high-stakes incident response operations.

In an environment where threats evolve at breakneck speed, we need a resourceful engineer who can engineer resilience, mentor junior analysts, and protect our digital frontier with precision.

Role

Advanced Incident Triage: Act as the Tier 2/3 escalation point for complex security events. Investigate and resolve high-severity incidents escalated from initial monitoring tiers.

System Oversight: Oversee and optimize security infrastructure, ensuring that Google SecOps (Chronicle) and other SIEM/SOAR tools are tuned for maximum visibility and efficiency.

Incident Leadership: Lead the charge during active incident response operations, coordinating across teams to contain threats and performing deep-dive post-incident forensics.

Malware & Threat Analysis: Perform deep-tissue analysis of malware to understand behavior and origins, using that intelligence to build proactive technical controls.

Detection Engineering: Create, integrate, and maintain custom security tools and automated playbooks to streamline the "detect-to-remediate" lifecycle.

Strategic Defense: Investigate advanced phishing vectors and implement systemic preventive measures; assist in high-level purple team exercises to validate our posture.

Operational Excellence: Maintain and mature security documentation, including technical procedures, complex runbooks, and internal security policies.

Requirements

3–5 years of experience in a dedicated security operations or engineering role.

Tier 2/3 Expertise: Proven track record of handling complex escalations and leading incident response efforts.

Technical Depth: Advanced experience in malware analysis, digital forensics, and neutralizing sophisticated phishing campaigns.

Systems Mastery: Strong understanding of security standards, hardening principles, and the ability to oversee enterprise-grade security platforms.

Problem Solving: Exceptional analytical skills with the ability to think like an attacker to better defend the system.

Communication: Excellent written and oral communication skills, with the ability to translate technical findings into actionable leadership briefings.

Education/Experience: While we value experience, a degree in CS, Cybersecurity, or a related field is a plus.

Bonus

Certifications: Advanced certifications such as CISSP, GCIA, GCIH, or OSCP.

Platform Experience: Hands-on experience managing and tuning Google SecOps (Chronicle).

Automation: Experience with SOAR platforms or scripting (Python, Go) to automate response workflows.

What we offer:

All our positions offer a compensation package that includes equity and robust benefits.

Base pay is just one component of Astranis’s total rewards package. Your compensation also includes a significant equity package via incentive stock options, high-quality company-subsidized healthcare, disability and life insurance, 401(k) retirement planning, flexible PTO, and free on-site catered meals.

Astranis pay ranges are informed and defined through professional-grade salary surveys and compensation data sources. The actual base salary offered to a successful candidate will additionally be influenced by a variety of factors including experience, credentials & certifications, educational attainment, skill level requirements, and the level and scope of the position.

Base Salary

$150,000—$205,000 USD

Apply for this role →

← Back to all jobs