L3 SOC Analyst / Incident Response Analyst
Core
Advanced incident detection, investigation, and response to complex cybersecurity threats within a Managed Security Services Provider (MSSP) environment.
Role type
L3 SOC Analyst / Incident Response Analyst
Builds
Production security detection rules, automated response workflows, and forensic evidence for diverse client environments.
Domain
Cybersecurity, MSSP, Cloud Security, Identity Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident Response, Threat Investigation, Detection Engineering, DFIR Operations, SOC Automation, Threat Hunting, Microsoft Sentinel, Microsoft Defender XDR, KQL, SOAR platforms, MITRE ATT&CK mapping, Cloud security, Identity security, Malware analysis, Ransomware response, BEC handling, Root cause analysis, Playbook development, SOP creation
Preferred skills
MSSP environment experience, US-based team collaboration, AI-orchestrated attack response
Technologies
Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, Microsoft Purview, Entra ID, Logic Apps, SOAR platforms
Responsibilities
Lead advanced security incident investigations and threat triage across multiple customer environments; Design and maintain advanced detection rules and KQL queries in Microsoft Sentinel; Develop and implement SOC automation workflows using Playbooks and Logic Apps; Perform deep-dive analysis on account compromise, BEC, malware, ransomware, and lateral movement; Coordinate containment, remediation, and recovery activities with customer and internal teams; Conduct proactive threat hunting and digital forensics; Support onboarding of new customer environments and maintain investigation playbooks and operational runbooks.
Seniority
Mid-Senior, hands-on IC