Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Core
Lead advanced investigations and full lifecycle incident response for ransomware, APTs, zero-day exploits, insider threats, and credential theft across hybrid cloud and on-premises environments.
Role type
Senior IC Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Builds
Incident response playbooks, forensic artifacts, detection rules, and technical reports for management
Domain
Cybersecurity, Incident Response, Digital Forensics, Threat Hunting
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Advanced incident response, forensic analysis, threat hunting, detection engineering, technical leadership, root cause analysis, attack timeline reconstruction, IOCs/IOAs/TTPs documentation
Preferred skills
Financial services industry experience, enterprise-scale incident investigation, DFIR engagement support, Active Directory Certificate Services (AD CS) abuse investigation
Technologies
Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, Python, CrowdStrike Falcon, Microsoft Defender XDR, Microsoft Entra ID, Microsoft 365, Azure, AWS, Kubernetes, MITRE ATT&CK, NIST CSF, NIST 800-61
Responsibilities
Lead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, and data exfiltration; Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review; Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, and Kubernetes; Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices; Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs; Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python; Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence; Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts; Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations
Seniority
Senior, hands-on IC with leadership responsibilities