Senior SOC Analyst
Core
Lead triage and investigation of security alerts, conduct root cause analysis, and drive containment, eradication, and recovery efforts within a Security Operations Center.
Role type
Senior SOC Analyst (Tier 2/3)
Builds
SOC playbooks, runbooks, detection logic, and incident response workflows
Domain
Cybersecurity / Financial Services
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
SIEM tools (Splunk, QRadar, Sentinel), EDR, SOAR platforms, network security, Windows/Linux environments, identity systems, cloud log sources, MITRE ATT&CK framework, threat hunting, IOC/IOA creation, detection tuning, incident leadership, stakeholder alignment, scripting/automation (Python, PowerShell), NIST CSF/800-61, CIS Controls, regulatory compliance, documentation
Preferred skills
GCIA, GCED, GCIH, GCFA, GNFA, CISSP, CCSP, threat intelligence platforms, sandboxing tools, malware triage, ticketing systems (ServiceNow), knowledge management
Technologies
Splunk, QRadar, Sentinel, ServiceNow, Python, PowerShell
Responsibilities
Lead triage and investigation of security alerts; Conduct root cause analysis and drive containment/eradication/recovery; Correlate activity across SIEM, EDR, IDS/IPS, firewalls, cloud logs, and identity platforms; Build, refine, and maintain SOC playbooks and detection logic; Mentor junior analysts on investigation methods and documentation; Work with Threat Intelligence to enrich investigations and hunt for IOCs; Partner with Engineering to fine-tune detections and improve log quality; Produce clear incident reports and executive summaries; Support purple team exercises and post-incident reviews; Ensure compliance with regulatory and security policies
Seniority
Senior, hands-on IC with mentorship responsibilities