HappyRobot is the infrastructure for enterprises to build and orchestrate AI workforces. Our AI workers don't just communicate - they make decisions, take action, and run operations autonomously across voice, email, and enterprise systems. Born in Y Combinator (S23) and backed by a16z and Base10 with over $60M raised, we power critical operations for global enterprises worldwide.
Our platform is battle-tested in the most demanding environments - where AI has real consequences. We started in logistics, built our own voice stack, models, and orchestration layer from the ground up, and are now bringing that infrastructure to every enterprise that runs the real economy. Learn more about our vision in our manifesto.
We are looking for a SOC Analyst to join our team. You will be the consistent, accountable owner of alert triage during coverage hours — bringing the speed, rigor, and communication discipline that transforms alert handling from a best-effort scramble into a reliable, measurable function.
This is not a detection engineering or research role. Your deepest strength is triage: prioritizing fast, distinguishing signal from noise, and escalating with the context that lets engineers act immediately rather than re-investigate from scratch. That said, you operate with a continuous improvement mindset — feeding a structured tuning loop with the SOC Engineer and proposing runbook fixes when the playbook doesn't match reality.
What You'll Do
Alert Triage Own the queue during coverage hours. Prioritize and disposition alerts accurately and fast — high-severity alerts acknowledged within 15 minutes, all alerts dispositioned within SLA. Know the difference between a true positive and noise, and act accordingly without waiting to be told.
Log & Threat Analysis Pivot across cloud, identity, and endpoint log sources to build a clear timeline when an alert warrants deeper investigation. Use MITRE ATT&CK as a reference frame to understand what you're looking at and what it means in context.
Incident Escalation & Communication Escalate incidents with complete, actionable context — severity reasoning, timeline, affected systems, and recommended next steps. Write clearly in English. Engineers receiving your escalations should be able to act without asking follow-up questions.
Runbook Discipline & Improvement Follow runbooks rigorously. When a runbook falls short — wrong steps, missing cases, outdated assumptions — flag it and propose a fix. Runbooks improve because analysts use them critically, not just obediently.
Tuning Feedback Loop Run a weekly feedback cycle with the SOC Engineer. Report false positives, patterns in noise, and cases where detection logic needs adjustment. Improve signal quality over time rather than just processing the same noise on repeat.
Audit Readiness Keep monitoring and response evidence current and organized for SOC 2, ISO 27001, and customer incident response commitments. Triage work that isn't documented doesn't exist for audit purposes — make sure yours does.
Must Have
2–3 years as a SOC analyst or in a blue team / detection and response role.
Hands-on alert triage experience with a SIEM and an EDR — investigation, disposition, and escalation.
Log analysis across cloud, identity, and endpoint sources.
Working knowledge of MITRE ATT&CK and common attack patterns.
Clear written incident notes and escalations in English (B2+).
Comfortable operating on a coverage-hours rotation.
Nice to Have
Cloud console familiarity with AWS, Azure, or GCP.
Scripting basics in Python or Bash.
Phishing and email threat analysis experience.
Certifications: BTL1, GCIH, Security+, or CySA+.
Exposure to detection tuning or writing simple detection rules.
Prior experience at a SaaS or tech startup.
Opportunity to work at a high-growth AI startup, backed by top investors.
Rapidly growing and backed by top investors including a16z, Y Combinator, and Base10.
Ownership & Autonomy - Take full ownership of projects and ship fast.
Comprehensive Benefits - Healthcare, dental, vision coverage.
Top-Tier Compensation - Competitive salary + equity in a high-growth startup.
Work With the Best - Join a world-class team of engineers and builders.
Extreme Ownership — We take full responsibility for our work and outcomes. No excuses, no blame-shifting. If something needs fixing, we own it.
Craftsmanship — We sweat the details because details compound. We never settle for "just fine" — whether it's a scoping document, a prototype demo, or a customer conversation.
We are "majos" — Be a good human. Friendly, genuine, kind. We're building something ambitious and it's better when we enjoy it together.
Urgency with Focus — Move fast, but in the right direction. Prioritize ruthlessly. Act decisively. Aim for the highest leverage action.
Talent Density and Meritocracy — Every hire raises the bar. Ability over seniority. Ownership goes to those who earn it.
First-Principles Thinking — Strip problems to their fundamentals, ignore industry dogma, and rebuild from scratch when needed. It's how we build what others think is impossible.
The personal data provided in your application and during the selection process will be processed by Happyrobot, Inc., acting as Data Controller.
By sending us your CV, you consent to the processing of your personal data for the purpose of evaluating and selecting you as a candidate for the position. Your personal data will be treated confidentially and will only be used for the recruitment process of the selected job offer.
In relation to the period of conservation of your personal data, these will be eliminated after three months of inactivity in compliance with the GDPR and legislation on the protection of personal data.
If you wish to exercise your rights of access, rectification, deletion, portability or opposition in relation to your personal data, you can do so through [email protected] subject to the GDPR.
For more information, visit https://www.happyrobot.ai/privacy-policy
By submitting your request, you confirm that you have read and understood this clause and that you agree to the processing of your personal data as described.