L3 SOC Analyst
Core
Senior technical escalation point leading complex investigations, automation initiatives, and mentoring within a modern Security Operations Centre.
Role type
Senior IC SOC Analyst (L3)
Builds
Automated response playbooks, detection rules, and forensic analysis for cloud and hybrid environments.
Domain
Cybersecurity, Cloud Security, Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Cloud security monitoring, Incident response, Threat hunting, Detection engineering, Security automation (SOAR), Scripting (Python, Go, PowerShell, Bash), Forensics, SIEM management, EDR tooling, MITRE ATT&CK framework
Preferred skills
AWS expertise, Kubernetes security, Hybrid environment security, Mentoring junior analysts
Technologies
AWS, Kubernetes, CrowdStrike Fusion SOAR, CrowdStrike Falcon, Splunk, QRadar, Microsoft Sentinel, AWS GuardDuty, CloudTrail, Proofpoint
Responsibilities
Act as final escalation point for complex incidents; Lead investigations into high-severity security events; Perform advanced forensic analysis across endpoints, cloud workloads, and network telemetry; Design and maintain automated response playbooks within the SOAR platform; Conduct proactive threat hunting across enterprise and cloud environments; Provide technical mentoring and guidance to L1/L2 analysts.
Seniority
Senior, hands-on IC