L3 SOC Internal Analyst
Core
Lead day-to-day operations of the Cyber Defense Center (CDC), managing monitoring, investigation, and incident response across SOC tiers while acting as the primary interface for the MSSP.
Role type
Senior IC SOC Analyst (L3)
Builds
SOC operational capabilities, detection rules, and incident response workflows
Domain
Cybersecurity / Security Operations
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SIEM/SOAR/EDR expertise, incident response leadership, threat hunting, vendor management, log source onboarding, detection rule tuning, KPI reporting, MITRE ATT&CK framework knowledge, EU cybersecurity regulations (NIS2)
Preferred skills
CISM/GCIA/GCIH/CISSP certifications, German language fluency
Technologies
SIEM, SOAR, EDR, IDS/IPS, DLP, WAF
Responsibilities
Manage MSSP vendor performance and service assurance; Serve as L3 escalation point for complex incidents; Coordinate cross-tier incident response and handover to CIRT; Own SIEM/SOAR detection lifecycle; Define and coordinate threat hunting activities; Produce monthly KPI dashboards; Provide rotational on-call operational oversight
Seniority
Senior, hands-on IC with team/vendor coordination