Lead SOC Analyst
Core
Leading daily Security Operations Center (SOC) operations, managing incident response, and coordinating with external MDR providers.
Role type
Lead SOC Analyst (hands-on IC with team leadership)
Builds
SOC processes, playbooks, detection rules, and incident response capabilities
Domain
Cybersecurity / Security Operations
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
incident response, threat hunting, SOC operations, MDR vendor management, process development, SIEM/XDR/EDR/SOAR platform usage, detection tuning, log analysis, team mentoring, stakeholder communication
Preferred skills
hybrid SOC model experience, compliance frameworks (NIST, CMMC), CISSP/GCIA/GCIH certifications
Technologies
Splunk, Microsoft Sentinel, Defender XDR
Responsibilities
Act as senior escalation point for security incidents, perform advanced threat hunting and root cause analysis, lead incident response across IT and infrastructure teams, validate and enrich alerts from internal tools and MDR providers, develop and maintain SOC SOPs and playbooks, mentor and develop SOC analysts, collaborate on detection logic and use cases, communicate security risks to stakeholders
Seniority
Senior, hands-on IC with leadership duties