Confidential · 2 weeks ago
Senior SOC Analyst (Direct Hire EAD OKAY)
Confidential company is seeking an experienced and proactive Senior Security Operations Center (SOC) Analyst to join their Cybersecurity team. As a Tier 3 / Lead analyst, you will serve as the primary escalation point for complex security incidents, drive threat-hunting initiatives, and continuously improve incident response capabilities.
Marketing & Advertising
Responsibilities
Serve as the senior escalation point (Tier 3) for high-severity security incidents and complex threats detected by Tier 1 and Tier 2 analysts
Lead end-to-end incident response processes, including containment, eradication, and post-incident root-cause analysis (RCA)
Draft detailed, executive-level Incident Reports and Lessons Learned documentation following major events
Proactively search across endpoints, network traffic, and cloud environments to identify undetected advanced persistent threats (APTs) using the MITRE ATT&CK framework
Integrate Cyber Threat Intelligence (CTI) into security monitoring to generate actionable Indicators of Compromise (IoCs) and custom detection rules
Tune and optimize SIEM, SOAR, EDR/XDR, and NDR platforms to reduce false positives and improve alert fidelity
Develop automated playbooks and workflows to streamline routine SOC tasks and speed up Mean Time to Respond (MTTR)
Mentor and train junior SOC analysts, providing guidance on incident analysis, tool usage, and industry best practices
Participate in or lead on-call rotations for critical security escalations
Assist in conducting incident response tabletop exercises to validate procedures
Qualification
Required
5+ years of direct experience in cybersecurity, with at least 3+ years in a dedicated SOC or Incident Response environment
Strong experience investigating security events across cloud environments (AWS, Azure, or GCP) and on-premises enterprise networks
Advanced proficiency with enterprise tools (e.g., Splunk, Sentinel, CrowdStrike, SentinelOne, Palo Alto Cortex)
Deep understanding of network traffic analysis (Wireshark, PCAP), memory forensics, host-based artifacts, and log analysis (Windows Event Logs, Syslog)
Ability to write scripts in Python, PowerShell, or Bash to automate repetitive task workflows or parse complex datasets
Expertise in applying security frameworks like MITRE ATT&CK, NIST SP 800-61, and NIST CSF
Ability to dissect complex security scenarios under pressure and make sound decisions swiftly
Excellent written and verbal skills to articulate technical findings to non-technical business leaders and stakeholders
A strong sense of ownership combined with a passion for mentoring and uplifting teammates
Preferred
GIAC: GCIH, GCFA, GNFA, or GCDA
CompTIA: CySA+ or CASP+
OffSec: OSCP or OSDA
Other: CISSP, Azure/AWS Security Specialty
Benefits
Bonus
Benefits package (401k matching, healthcare, professional development/certification stipend)