Jobs · Manufacturing · New York

Senior Associate, Security Operations

Andersen · New York, NY · 2 wk ago
On-siteManufacturing$115k–$130k/yrFull-time

About the role

Andersen’s information security function is expanding, and this role sits at the operational core of that effort. The Senior Associate, Security Operations serves as the firm’s internal hub for day-to-day security operations, owning the relationship with our managed detection and response provider, triaging and coordinating incident response, managing security vendor relationships, and executing client security due diligence.

This role requires a candidate who is equally comfortable analyzing a threat escalation and drafting a vendor risk assessment. The Senior Associate reports to the Head of Security Engineering & Architecture, with dotted-line accountability to the Senior Manager, Governance, Risk & Compliance for client diligence and vendor risk.

After-hours availability is a firm requirement of this role; high-severity incidents do not observe business hours.

Responsibilities

  • Serve as the firm’s internal incident response coordinator, working alongside the managed detection and response provider during active security events
  • Execute, test, and continuously improve IR playbooks through regular tabletop exercises, lessons learned, and evolving threat intelligence
  • Produce post-incident reports that are clear, factual, and actionable for both technical and executive audiences
  • Serve as the primary day-to-day liaison to the firm’s MDR provider; review threat reports, detection summaries, and alert trends, and hold the provider accountable to SLAs
  • Triage MDR escalations – assess severity, validate findings, and initiate the appropriate internal response workflow
  • Execute responses to client security questionnaires and due diligence requests accurately and on time, drawing on the response library maintained by the Senior Manager, GRC
  • Support the Head of Security Engineering & Architecture in day-to-day security operations, including vulnerability management tracking and remediation follow-up
  • Manage operational relationships with security technology and service vendors, tracking contract terms, renewal dates, and SLA performance
  • Contribute to security awareness initiatives and serve as a resource for internal teams with security-related questions
  • Identify and assess security risks introduced by AI-assisted attacks, including AI-augmented phishing, deepfake-based social engineering, and adversarial use of AI agents

Requirements

  • 5+ years of experience in security operations, incident response, or a closely related discipline
  • Bachelor’s degree in Information Security, Computer Science, or a related field
  • Demonstrated experience triaging and coordinating incident response, including hands-on involvement during active security events
  • Ability to execute, test, and improve IR playbooks, evaluating their effectiveness and driving meaningful enhancements
  • Working familiarity with managed detection and response services, including how to interpret their outputs and manage them as an operational partner
  • Experience managing vendor relationships in a security context, including SLA oversight and contract coordination
  • Technical fluency across core security domains: endpoint security, network fundamentals, log analysis, and threat detection
  • Proficiency with enterprise security tooling including SIEM, EDR, and ticketing platforms
  • Working knowledge of AI-enabled threat vectors, including AI-augmented social engineering, adversarial AI agent activity, and the security risks introduced by citizen developer platforms and unsanctioned AI tool adoption within the enterprise
  • Strong written communication skills; able to produce clear incident reports and professional client-facing responses under time pressure
  • Availability and willingness to respond to high-severity incidents outside of business hours

Qualifications

  • Relevant certification in incident handling or security analysis (e.g., GCIH, GSEC, GSOC)
  • Background in professional services or consulting, where security posture directly impacts client relationships
  • Familiarity with SOC 2 or ISO 27001 control environments and how security operations intersect with compliance requirements
  • Exposure to threat intelligence platforms or processes
  • Familiarity with AI security risk frameworks such as NIST AI RMF or MITRE ATLAS, and practical exposure to assessing risks from AI agent deployments and employee use of generative AI tools

Benefits

Our firm offers competitive base compensation, benefits package, and a discretionary employee bonus program for eligible employees based on individual and firm performance metrics per the defined program guidelines.

Benefits: Employees (and their families) are covered by medical, dental, vision, and basic life insurance. Employees are able to enroll in our firm’s 401(k) plan upon hire. We offer paid time off, beginning at 160 hours annually and provides twelve paid holidays throughout the calendar year.

Pay

For individuals hired to work in the United States, the expected salary range for this role is $115,000-$130,000; the actual salary offer can vary based upon employee qualifications.

In addition to competitive base compensation, our firm offers annual discretionary bonuses based on firm and individual performance, a discretionary long-term cash incentive program, and other forms of discretionary compensation that would be offered to the hired applicant in addition to their established salary range scale.

Similar jobs