Senior Cybersecurity Operations Analyst
Listed on 2026-03-12
-
IT/Tech
Cybersecurity, Information Security, Security Manager
Metro’s mission is to provide a world-class transportation system that enhances the quality of life for all who live, work, and play within LA County.
DescriptionThe Senior Cybersecurity Analyst leads day-to-day security operations within the Security Operations Center and is responsible for advanced threat detection, investigation, and response across the enterprise. This role acts as a technical escalation point for complex incidents, drives incident response coordination, and ensures alerts are triaged and resolved efficiently. Monitors, detects, and responds to security incidents and collaborates with various security, crisis and emergency management teams to ensure the safety of Metro’s digital and physical assets.
RecruitmentTimeline
Interviews are projected to be scheduled for the week of March 23rd, 2026. These dates are subject to change. We encourage you to monitor your profile and emails for the latest updates.
Examples of Duties- Monitor cybersecurity events across assigned environment using advanced Security Information, Threat Intelligence, and Security Information and Event Management (SIEM) tools to detect and respond to security threats and incidents.
- Identify, analyze, and respond to security incidents, coordinating with teams to contain, mitigate, and recover from such breaches.
- Maintain awareness of local, national, and global threats and vulnerabilities and develop mitigation strategies to protect critical networks and assets.
- Analyze security data to identify potential security incidents, conduct root cause analysis, and offer actionable recommendations to prevent future occurrences.
- Identify and remediate vulnerabilities within assigned environments.
- Collaborate with Information Security and Information Technology Services (ITS) teams to implement security patches and updates.
- Maintain detailed and accurate records of security incidents, including timelines, actions taken, and outcomes.
- Prepare and furnish reports for management and relevant stakeholders on Cyber Security Operations Center (CSOC) activities and incident response metrics.
- Work closely with ITS, and other technical and security teams to ensure effective communication and coordination during security incidents.
- Participate in cross‑functional security initiatives and projects and take responsibility for associated tasks.
- Address relevant maintenance and tuning of CSOC tools, including SIEM, IDS/IPS, firewalls, and other security technologies.
- Address improvement plans to the development and enhancement of CSOC processes, playbooks, and procedures.
- Identify areas for improvement in incident response and threat detection capabilities.
- Address innovative ideas to security awareness campaigns, based on operations and incident response activities.
May be required to perform other related job duties.
Education- Bachelor’s Degree in Information Technology, Cybersecurity, Computer Science, or a related field.
- Five years of relevant experience performing information security, security monitoring, and incident response; some positions in this class may require specialized experience in area of assignment.
Special Requirements
- A valid California Class C Driver License or the ability to utilize an alternative method of transportation when needed to carry out job‑related essential functions.
- Certification in one or more areas of cyber security specialization:
Certified Information Systems Security Professional (CISSP), GIAC Certified Incident Handler (GCIH), Certified Ethical Hacker (CEH), or equivalent preferred. - Ability to work in a secure CSOC environment, which may require extended periods of time sitting and working at a computer.
- This is a 24/7 operation, and the role may require working in shifts, including nights, weekends, and holidays, to ensure continuous monitoring and response.
- Experience demonstrating hands‑on leadership in a 24x7 Security Operations Center (SOC) or advanced security operations environment for a large complex organization.
- Experience understanding of endpoint, email, network, identity, and cloud security controls and how they…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).