Full-Time

Security Analyst 3

Security Operations Center

Posted on 8/7/2025

Deepwatch

Deepwatch

201-500 employees

Managed security services for threat detection

Compensation Overview

$94.5k - $118.7k/yr

+ Stock Options + Benefits

No H1B Sponsorship

Tampa, FL, USA

In Person

US Citizenship Required

Category
IT & Security (1)
Required Skills
Splunk
Linux/Unix
Data Analysis
Requirements
  • A strong understanding of cyber security principles, concepts and practices which includes the ability to perform a complete and thorough incident investigation and triage as the final point of escalation
  • Extensive expertise with multiple SIEM environments such as SentinelOne, Google SecOps, Splunk and SPL; including the ability to navigate the console with ease and perform queries that result in efficient investigation and accurate alert analysis
  • Confidence to autonomously resolve the most complex investigations as the final point of escalation
  • Build accurate forensic timelines and identify anomalies matching TTPs/IOCs
  • Manage customer expectations in meetings which includes follow through and tracking action items to completion while keeping your leadership and peers informed
  • Communicate when help is needed and leverage internal resources to quickly resolve investigations and incidents
  • Have advanced knowledge of Adversary Tactics, Techniques, & Procedures (TTP), Event Logging, and Event Triage
  • Demonstrate the ability to pivot to other log sources, cloud systems or consoles to perform a comprehensive analysis from multiple data sources.
  • Have a strong understanding of modern EDR, email security and cloud identity platforms
  • A desire to support others and uplift the program and team through updating training materials and SOPs
  • Demonstrate the ability to write well-written reports and analysis that’s thorough, accurate and complete
  • Provide the customer with a complete understanding of the investigation and act as a trusted advisor
Responsibilities
  • Act as the final point of escalation for alert triage processes across multiple platforms and security technologies including Windows, Linux and macOS
  • Provide in depth analysis from escalated requests originating from any team member who needs support
  • Validate suspicious events by performing investigations using SIEM and SOAR technologies, leveraging Deepwatch proprietary tooling, intelligence and OSINT, TTPs and IOCs
  • Interface directly with customers when necessary, providing a high level of confidence and thoroughness during the investigative process
  • Act as a key resource for Management, providing opportunities for improvement and actionable recommendations on creating efficiencies
  • Act as an additional resource for the Threat Response team when a compromise is discovered or when a customer declares an Incident
  • Identify gaps in customer environments, data ingested or configuration errors which reduce telemetry quality
  • Work with customer and leadership to surface and resolve concerns
  • Provide support to all analysts, work collaboratively to coach and train others on a regular basis, and act as the technical escalation point for Analyst I & II
  • Produce high-quality written and verbal communications, recommendations, and findings to customer management in a timely manner
  • Lead the conversation for improvements in the process and for the customer and be a change agent for measurably improving our customer security posture and experience
  • Continue to sharpen your skills and capabilities on the job, and through the Deepwatch development program
Desired Qualifications
  • GCIH, GCIA, GDAT, GMON, GREM, OCSP, OCSE, or equivalent certification preferred

Deepwatch provides managed security services (MSS) and a managed security platform to monitor and protect clients’ digital assets. The platform augments existing security tools, increases visibility over the attack surface, and reduces alert volume and false positives while guiding continuous improvement of a client’s security posture through deep threat management metrics. A key differentiator is the patented Security Index framework, which helps identify the right metrics and KPIs to measure how well security operations are working, and the company positions itself as a security partner and extension of the client team rather than a one-time vendor. The goal is for clients to deliver their core outcomes securely by maintaining ongoing, measurable security improvements and resilience.

Company Size

201-500

Company Stage

Late Stage VC

Total Funding

$256M

Headquarters

Denver, Colorado

Founded

2019

Simplify Jobs

Simplify's Take

What believers are saying

  • Bengaluru facility opened 2025 scales R&D tapping India's AI and cybersecurity talent.
  • Dassana acquisition integrates CISO Copilot boosting threat detection productivity.
  • Securonix native support eliminates 6-12 month tuning for immediate SOC operations.

What critics are saying

  • CrowdStrike Falcon captures 35% MDR share eroding Deepwatch position in 12-24 months.
  • Palo Alto Cortex XDR bundles free MDR with Prisma Access stealing mid-market clients in 6-12 months.
  • November 2025 layoffs degrade SOC expertise triggering Fortune 100 contract penalties.

What makes Deepwatch unique

  • Deepwatch Guardian MDR Platform uses decade of SOC telemetry with agentic AI and human oversight.
  • Dynamic Risk Scoring engine correlates alerts at machine speed for precise threat responses.
  • Tailored solutions assign named detection analysts, engineers, and threat hunters 24/7/365.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Unlimited Paid Time Off

Paid Sick Leave

Paid Holidays

Professional Development Budget

401(k) Retirement Plan

401(k) Company Match

Wellness Program

Growth & Insights and Company News

Headcount

6 month growth

-3%

1 year growth

1%

2 year growth

-3%
The Associated Press
Feb 24th, 2026
Deepwatch expands Guardian MDR platform with native Securonix SIEM support

Deepwatch has announced native support for Securonix within its Guardian MDR Platform, providing organisations with an "instant-on" security operations centre that operationalises Securonix's SIEM technology. The integration combines Securonix's AI-powered analytics with Deepwatch's 24/7 SOC, security experts and NEXA Agentic AI ecosystem. The partnership addresses the SIEM capability gap by eliminating the typical 6-12 month tuning period, offering immediate access to Deepwatch's detection platform and automated investigations. The integration expands Deepwatch's SIEM-agnostic strategy, which already supports Splunk, Microsoft Sentinel and Google SecOps. Key benefits include seamless operational continuity, AI-enhanced analysis using Dynamic Risk Scoring to reduce alert fatigue, operational transparency and SIEM flexibility. The solution aims to tackle challenges including resource constraints, alert overload and contextual fragmentation in security operations.

The Economic Times
Nov 19th, 2025
Deepwatch opens new facility in Bengaluru

Deepwatch opens new facility in Bengaluru. The company in a statement on Wednesday said the facility will function as a key engineering and technology centre, as it scales its research and development capabilities. AI cybersecurity firm Deepwatch has opened a new office in Bengaluru as part of its global expansion plans. The company in a statement on Wednesday said the facility will function as a key engineering and technology centre, as it scales its research and development capabilities. The new GCC will allow the US-based firm to tap into the country's engineering talent across software, agentic AI, and cybersecurity, it added. "Our investment in Bengaluru represents more than a new office, it's a testament to Deepwatch 's commitment to developing exceptional AI-powered solutions for the cyber industry," said John DiLullo, Chief Executive Officer at Deepwatch. The local teams will focus on leading efforts in product development while supporting the delivery and operational models for global customers. The investment is also part of its long-term plan to establish India as a key centre for its global cybersecurity R&D. "Our team in India is transforming the mundane into the marvelous every day. Deepwatch's Agentic solutions will keep customers safe from the scourge of cybercrimes while improving the efficiency of global SOC operations and the lives of overworked analysts. We're convinced India is the ideal location to advance this goal," DiLullo added. The firm said it plans to expand its Bengaluru's current 30-member team aggressively over the coming year with hires across engineering, cloud operations, and product roles. "The India GCC represents our strategic commitment to advance cyber resilience at scale. India's deep pool of cybersecurity talent gives us a unique advantage to accelerate product innovation, strengthen our threat intelligence capabilities, and deliver next-generation managed security outcomes to customers worldwide," added Prasad Channabasappa, Managing Director, Deepwatch India. The firm provides a managed security platform for enterprises, combining AI-driven solutions with expert human analysts to provide monitoring, threat detection, and rapid incident response.

Techstrong Group, Inc.
Oct 9th, 2025
Deepwatch Wins 2025 CyberSecurity Breakthrough Award for Managed Security Solution of the Year

Deepwatch wins 2025 CyberSecurity Breakthrough award for Managed Security Solution of the Year. PALO ALTO - October 9, 2025 - Deepwatch, the leader in Precision MDR powered by AI + humans, today announced that it has been named the "Managed Security Solution of the Year" in the 2025 CyberSecurity Breakthrough Awards. The mission of the CyberSecurity Breakthrough Awards is to honor excellence and recognize the innovation, hard work and success in a range of information security categories, including Cloud Security, Threat Detection, Risk Management, Fraud Prevention, Mobile Security, Email Security, and many more. Today's attack surface is expanding, threats are growing more sophisticated, and the cybersecurity talent gap continues to widen. Deepwatch's MDR platform stood out for its unique combination of advanced analytics, AI, and expert human validation. Purpose-built to address the expanding attack surface, increasingly sophisticated threats, and ongoing cybersecurity talent gap, Deepwatch redefines managed security with a hybrid SecOps model that ensures high-fidelity alerting, rapid response, and continuous improvement. * AI-driven threat analytics enhanced by human validation, delivering low-volume, high-fidelity alerts and insights that uncover the most critical risks. * 24/7/365 monitoring and rapid response that minimizes attacker dwell time. * Proactive and preemptive defense and exposure management that stops threats before they become incidents. * Dark Web Monitoring and Response with added Takedown Services that eliminate threats at the source. Deepwatch customers consistently see measurable outcomes, including improved ROI through reduced false positives, optimized tool utilization, and enhanced operational efficiency. Trusted by leading brands, Deepwatch delivers resilience at scale while aligning security programs with business objectives. "Being honored as Managed Security Solution of the Year isn't just another trophy for the shelf - it's further evidence that enterprises are utterly exhausted by vendors' utopian claims about their latest piece of software.," said John DiLullo, CEO of Deepwatch. "We put our money where our mouth is and guarantee efficacy against the scourge of cyber threats, both from crafty hackers and from rogue insiders. We blend AI automation with good old-fashioned human expertise to outsmart the bad guys and keep our customers from becoming the next headline." Deepwatch continues to set the standard for managed security through strong alliances with AWS, Splunk, CrowdStrike, Tenable, and Google Cloud Security's SecOps Partner Program. With an innovation roadmap focused on AI-driven detection, hyperautomation, and expanded integrations, Deepwatch is empowering organizations to achieve lasting cyber resilience. About deepwatch. Deepwatch is the leader in Precision MDR powered by AI and humans. We amplify human expertise with AI insights to reduce the risks that matter most to your business. Unlike one-size-fits-all MDR, Deepwatch delivers protection that is comprehensive, custom, clear, and ceaseless - stopping threats before and after they emerge with tailored responses at every step. Deepwatch is tuned to each customer's environment, trained on their priorities and the stack they've invested in to strengthen defenses and focus on what matters most. There are no black boxes - customers get clarity on every detection, decision, and data source, along with the name of the analyst behind it. Around-the-clock protection is delivered by security experts who act on real-time threats, powered by AI. Visit Deepwatch.com "Deepwatch" is a trademark of Deepwatch, Inc. and its subsidiaries. All other trademarks, trade names, service marks, and logos referenced herein belong to their respective companies. Media contact: Sena McGrand ICR for Deepwatch [email protected]

Deepwatch
Jul 15th, 2025
Deepwatch Joins the Google Cloud Managed Security Services Provider Initiative

PALO ALTO - July 15, 2025 - Deepwatch, the leader in human + AI-driven Managed Detection and Response (MDR), today announced its inclusion in the Google Cloud Managed Security Services Provider Initiative.

Cyber Technology Insights
May 20th, 2025
Deepwatch Appoints Alex Page as CRO, Warren Dewar as CFO

Deepwatch appoints Alex Page as CRO, Warren Dewar as CFO.

INACTIVE