L3 SOC Engineer
Core
Lead complex security investigations, perform advanced threat hunting, and provide technical guidance to junior analysts within a mature security environment.
Role type
Senior Level 3 SOC Engineer
Builds
Incident response playbooks, automated detection rules, and security monitoring processes
Domain
Cybersecurity / Security Operations
Deliverable
client delivery
Required skills
Advanced SIEM/EDR/XDR knowledge, malware analysis, root-cause investigation, scripting (Python/PowerShell), automation, MITRE ATT&CK framework expertise, cloud security (Azure/AWS)
Preferred skills
Cybersecurity certifications
Technologies
Microsoft Sentinel, Splunk, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto Networks, Fortinet, Azure, AWS, SOAR, Wireshark
Responsibilities
Lead investigation and remediation of complex security incidents, perform advanced threat hunting and malware analysis, analyze alerts across SIEM/EDR/network/cloud platforms, develop detection rules and incident-response procedures, automate SOC processes, mentor Level 1 and 2 analysts, produce incident reports
Seniority
Senior, hands-on IC