L3 SOC Analyst / Incident Responder
Core
Leading advanced threat detection, incident response, and security operations improvement to protect client digital assets from sophisticated cyber threats.
Role type
Senior L3 SOC Analyst / Incident Responder
Builds
Detection capabilities, incident response playbooks, and forensic analysis reports
Domain
Cybersecurity / Cyber Defense
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Advanced threat detection, incident response lifecycle management, forensic analysis, threat hunting, SIEM tuning, scripting for automation, network protocol analysis, malware analysis
Preferred skills
MITRE ATT&CK framework knowledge, NIST framework knowledge, threat intelligence platform usage
Technologies
Splunk, QRadar, EDR, NDR, firewalls, IDS/IPS, Python, PowerShell
Responsibilities
Monitor and analyze security events from SIEM, EDR, NDR, and firewalls; Lead incident response efforts including investigation, containment, eradication, and recovery; Perform in-depth forensic analysis on compromised systems; Proactively hunt for hidden threats using behavioral analysis and anomaly detection; Collaborate to tune SIEM rules and develop custom scripts; Mentor junior SOC analysts; Prepare detailed post-incident reports with root cause analysis; Develop and maintain incident response playbooks
Seniority
Senior, hands-on IC