About the job
The Lead Security Operations Center (SOC) Analyst at Copperleaf is pivotal in safeguarding our global SaaS platform, internal systems, and customer environments. This position demands extensive technical proficiency in cloud-centric security operations, advanced detection and response, and an in-depth understanding of enterprise technologies underpinning Copperleaf's product ecosystem and operational security.
As a Senior Analyst, you will spearhead intricate investigations, facilitate continuous operational enhancements, and bolster our capacity for rapid threat detection and response across cloud workloads (Azure), identity systems (Azure AD/Entra ID), clusters, endpoint platforms, and customer-integrated data pipelines. This role also includes mentoring junior analysts and collaborating closely with Security Engineering, CloudOps, IT, and Incident Response teams to refine detection logic, enhance logging visibility, automation, and resilience throughout Copperleaf’s environment.
Key Responsibilities
Leadership & Team Support
- Serve as a senior escalation point for SOC investigations, offering guidance in line with Copperleaf’s security architecture and operational practices.
- Mentor junior analysts and promote team growth in cloud security, detection engineering, and SaaS-specific monitoring.
- Propose training and process improvements to foster ongoing professional development.
- Engage in tabletop exercises tailored to Copperleaf’s product, cloud, and operational risk scenarios.
Security Monitoring & Incident Response
- Lead investigations into security alerts within Copperleaf’s Azure-hosted environments, identity systems, corporate endpoints, and product infrastructure.
- Support incident response efforts, including containment, remediation, documentation, and lessons-learned.
- Analyze logs from Azure Monitor, Entra ID, Kubernetes clusters, application services, and customer-facing integrations.
- Develop detections mapped to MITRE ATT&CK for cloud and SaaS environments.
- Maintain and enhance SOC playbooks and SOPs specific to Copperleaf’s operational, compliance, and customer commitments.
- Recommend adjustments to cloud-native and third-party detection tools to minimize false positives.
- Participate in an on-call rotation to support business-critical operations outside of standard working hours.
Threat Intelligence, Detection Engineering & Automation
- Monitor emerging threats pertinent to SaaS providers, cloud platforms, Kubernetes, identity infrastructure, and AI-driven attack techniques.

