Sr. Security Analyst - Security Operations Center (SOC)
Core
Leading advanced incident response, threat hunting, and automation within a Security Operations Center (SOC) to protect digital infrastructure and secure business operations.
Role type
Senior SOC Analyst (Incident Response & Threat Hunting)
Builds
Automated playbooks, detection logic, and response workflows for endpoint, identity, network, and cloud telemetry.
Domain
Cybersecurity / SOC Operations / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident response triage and remediation, Threat hunting, SIEM/SOAR platform management, SOAR playbook development, Cloud security telemetry analysis, MITRE ATT&CK framework application, Root cause analysis, Detection content authoring and tuning, Network security concepts, Malware analysis techniques
Preferred skills
Python scripting, PowerShell automation, EDR platform migration experience, AI-assisted triage tooling familiarity, Multi-cloud security experience (AWS, Azure, OCI)
Technologies
Microsoft Sentinel, Microsoft Defender XDR, Palo Alto Cortex XDR, ServiceNow, Torq, Azure/Entra, AWS CloudTrail, Proofpoint
Responsibilities
Lead investigations of complex, high severity security incidents from detection through containment and recovery; Act as primary escalation point for Tier 3 alerts and perform root cause analysis; Conduct proactive, hypothesis-driven threat hunts across endpoint, identity, network, and cloud telemetry; Build, test, and maintain automated playbooks and response workflows in a SOAR platform; Mentor Tier 1 and Tier 2 analysts and lead knowledge-sharing; Generate executive-level and technical reports on SOC performance and incidents.
Seniority
Senior, hands-on IC with mentorship responsibilities