Quick Overview
Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Lake Mary, United States
Posted
2 weeks ago
SplunkPowerShellPython
Job Description
We’re seeking a future team member for the role of Senior SOC Analyst to join our Security Operations Center team. This role can be in Pittsburgh PA or Lake Mary FL. Schedule: Tuesday–Saturday.
Key Responsibilities
- Lead triage and investigation of security alerts, escalating and coordinating incident response as needed.
- Perform root cause analysis, scope affected assets, and drive containment, eradication, and recovery.
- Correlate events across SIEM, EDR, IDS/IPS, firewalls, cloud logs, and identity platforms to identify true positives and reduce false positives.
- Develop, refine, and maintain SOC playbooks, runbooks, and detection logic aligned to the MITRE ATT&CK framework.
- Mentor junior analysts and provide guidance on investigation techniques, documentation standards, and operational best practices.
- Coordinate with Threat Intelligence to enrich investigations, track adversary TTPs, and proactively hunt for indicators of compromise.
- Partner with Engineering teams to tune detections, improve log fidelity, and strengthen preventive controls.
- Create clear, actionable incident reports and executive summaries; contribute to metrics and trend analysis.
- Support purple team exercises and post-incident reviews to capture lessons learned and drive continuous improvement.
- Ensure adherence to regulatory and security policies; maintain audit-ready documentation for investigations and incidents.
Qualifications
- 6-10; years of experience in a SOC, incident response, or threat detection role, including Tier 2/3 investigations.
- Bachelor's degree in Information Security, Computer Science, or a related field - Advanced certifications such as CISSP or CISM are preferred
- Advanced proficiency with SIEM (e.g., Splunk, QRadar, Sentinel), EDR (e.g., CrowdStrike, Microsoft Defender), and SOAR platforms.
- Strong knowledge of network security, Windows/Linux, identity systems, and common cloud logging sources.
- Hands-on experience with the MITRE ATT&CK framework, threat hunting, IOC/IOA development, and detection tuning.
- Demonstrated ability to lead complex incidents, coordinate stakeholders, and communicate clearly under time pressure.
- Scripting or automation experience (e.g., Python, PowerShell) for investigation enrichment and workflow improvements.
- Familiarity with NIST CSF/800-61, CIS Controls, and common regulatory requirements impacting incident response.
- Excellent documentation skills and an evidence-driven approach to investigations.
Preferred Qualifications
- Relevant certifications: GCIA, GCED, GCIH, GCFA, GNFA, CISSP, CCSP, or equivalent experience.
- Experience with ticketing and case management systems (e.g., ServiceNow) and knowledge management practices.
- Prior experience with threat intel platforms, sandboxing tools, and malware triage is a plus.
Work Schedule
- This role is scheduled Tuesday–Saturday, 8:00 AM -4 PM Eastern Time to support operational coverage.
- Occasional flexibility may be required during major incidents or planned exercises.
Similar jobs
- CM
Cyber Security Engineering B-2, 01.6.35 with Security Clearance
NewCredence Management Solutions
Wpafb, OH🇺🇸Hybrid2 days agoTechnology - DI
Lead Cyber Threat Analyst - Washington, DC with Security Clearance
NewDirectViz, LLC
Washington, DC🇺🇸HybridYesterdayTechnology - DI
Senior Information Systems Security Officer with Security Clearance
NewData Intelligence LLC
Vienna, VA🇺🇸HybridYesterdayEncryptionTechnology - BA
Information Systems Security Engineer with Security Clearance
NewBooz Allen Hamilton
Fayetteville, NC🇺🇸$99k - $225k/yrOn-siteYesterdaySplunkDNSHTTP+2Technology - GO
Information System Security Officer (ISSO) with Security Clearance
NewG2 Ops, Inc.
San Diego, CA🇺🇸$110k - $135k/yrRemoteYesterdayTechnology - BS
Information System Security Officer with Security Clearance
NewBase-2 Solutions, LLC
Elkridge, MD🇺🇸$10k/yrHybridYesterdayTechnology