Security Operations

Security Operations Analyst

Monitor, detect, and respond to security threats across client environments as part of AdVran's 24/7 Security Operations Center.

Apply for this position
Remote / Hybrid
Full-time
2-4 years
$75,000 - $105,000

About the role

Your day-to-day centers on monitoring SIEM alerts, investigating anomalies, and responding to security events across multiple client environments. You’ll work closely with escalation engineers and client delivery teams to triage incidents, tune detections, and support compliance efforts-all as part of AdVran’s 24/7 Security Operations Center.

About AdVran

AdVran is a Southern California managed IT and cybersecurity provider serving businesses from Anaheim to San Diego. This role supports our network infrastructure and managed IT delivery teams.

Learn about our services →

What you'll do

  • Monitor SIEM alerts and investigate potential security incidents
  • Perform threat hunting across client endpoints, networks, and cloud environments
  • Triage, escalate, and document security events per incident response procedures
  • Tune detection rules and reduce false positive rates
  • Conduct vulnerability assessments and track remediation progress
  • Support client compliance audits with security evidence and reporting

What we're looking for

  • 2+ years in a SOC, incident response, or security analyst role
  • Experience with SIEM platforms (Sentinel, Splunk, or similar)
  • Knowledge of MITRE ATT&CK framework and common threat vectors
  • Familiarity with EDR/MDR tools and endpoint security
  • Relevant certifications preferred (Security+, CySA+, GCIH)

Benefits & perks

Competitive salary with annual review
Remote-first with flexible schedule
Health, dental, and vision coverage
Professional development and certification reimbursement
Paid time off and company holidays

Job details

Location

Remote / Hybrid

Department

Security Operations

Type

Full-time

Experience

2-4 years

Salary range

$75,000 - $105,000

About working at AdVran

What you should know before applying for the Security Operations Analyst role

AdVran is a managed IT and cybersecurity services provider headquartered in Anaheim, California. Our clients are small and mid-sized businesses across Southern California in healthcare, financial services, legal and professional services, aerospace and defense, manufacturing, education, real estate, and non-profit. We operate as a single accountable team for our clients' IT and security, which means the work spans help desk, infrastructure, identity, endpoint protection, SOC monitoring, incident response, and compliance for frameworks like HIPAA, SOC 2, CMMC, PCI DSS, FINRA, NIST 800-53, and ISO 27001. Whatever role you join, you will be working directly with the people running these systems, not abstracted from them through layers of process.

How we work

AdVran runs on documentation, clear ownership, and predictable cadences. Every client has a written runbook for their environment, a named primary engineer, a named technical account manager, and a quarterly business review schedule. Engineers are expected to communicate in plain language with non-technical owners, write things down so the next person on the rotation can pick up where they left off, and bring evidence to internal post-mortems instead of opinion. We do not operate a paging culture of constant interruption: incidents have defined severities, scheduled change windows, and an on-call rotation rather than a 24/7 expectation across the whole team. We invest in tooling and automation so the team can focus on judgment calls instead of repetitive ticket churn.

Compensation, benefits, and growth

Salaries are calibrated against the Southern California market for managed services and security roles, and posted ranges reflect actual offer windows rather than ceilings nobody hits. Benefits include medical, dental, and vision coverage, a 401(k) plan with company match, paid time off including holidays and floating personal days, paid certification budgets for relevant industry certifications such as those from Microsoft, Cisco, CompTIA, ISC2, ISACA, and the SANS Institute, and a hybrid working arrangement that combines remote work with on-site time at the Anaheim office and at client sites in the Remote / Hybrid area as the work requires. We promote from within wherever possible: technical engineers move into architecture and consulting roles, account managers grow into client partnership leadership, and analysts step into senior security positions.

Application and interview process

Applications are reviewed by the hiring manager directly. After an initial screen, the process typically includes a technical or scenario-based conversation with the team you would be working with, a discussion with the leader of the department on how the role connects to the business, and a final meeting with leadership for cultural and values alignment. We try to give every candidate a decision within two weeks of the first conversation. If the Security Operations Analyst role is not quite the right fit, we keep candidate information on file with your consent and reach out when an adjacent role opens.

Interested in this role?

Apply now and we'll get back to you within 3–5 business days.