Sr SOC Analyst
Core
Detection, triage, and response operations across the enterprise, blending hands-on incident handling with detection engineering and automation.
Role type
Senior SOC Analyst (Detection & Response)
Builds
SOC playbooks, escalation workflows, detection strategies, and automated response capabilities.
Domain
Cybersecurity / Security Operations
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM (SecOps, Sentinel, QRadar), EDR (CrowdStrike, Defender, SentinelOne), SOAR platforms, alert triage, rule tuning, enrichment pipelines, incident response playbooks, containment/eradication, post-incident reviews, Python/PowerShell/Bash scripting
Preferred skills
Mentoring analysts, setting SOC standards, presenting to executive leadership, turning noisy telemetry into actionable signals
Technologies
SecOps, Sentinel, QRadar, CrowdStrike, Defender, SentinelOne, SOAR platforms
Responsibilities
Build and operationalize SOC playbooks and escalation workflows; Lead alert triage, enrichment, and false-positive suppression; Author detection requirements; write and tune SIEM rules; Develop hunt hypotheses; lead hunt programs using advanced telemetry and signals intelligence; Design detection strategies across the kill chain; Execute incidents end-to-end: containment/eradication, documentation, and communication; Conduct post-incident reviews and drive remediation and control improvements; Advocate and implement automation-first incident response.
Seniority
Senior, hands-on IC