Quick Overview
Job Description
ROLE_DESCRIPTION
"• 5+ years of experience in a Security Operations Center or similar cyber defense role, including at least 1-2 years in a lead, senior analyst, or shift-lead capacity
- Act as the primary liaison between Cyber Defense and Tech Operations on issues that span both teams (eg., system changes, outages, access requests, infrastructure-related findings).
- Lead day-to-day SOC operations, including monitoring, alert triage, and initial incident response.
- Working knowledge Of SIEM, EDR, and case/ticket management tooling"
"Case & Queue Management
- Own the SOC case queue: triage incoming alerts, tickets, and requests; assign priority and ownership; track cases through to resolution.
- Maintain SLAs for case handling and escalation; identify and clear bottlenecks before they become backlogs.
- Ensure consistent documentation, categorization, and closure quality across all cases.
Lead day-to-day SOC operations, including monitoring, alert triage, and initial incident response.
- Coordinate shift coverage and on-call rotations to maintain continuous monitoring.
- Serve as a senior escalation point for analysts on complex or ambiguous cases.
- Drive continuous improvement Of detection content, playbooks, and standard operating procedures.
- Act as the primary liaison between Cyber Defense and Tech Operations on issues that span both teams (eg., system changes, outages, access requests, infrastructure-related findings).
- Coordinate response and remediation activities that require Tech Operations involvement, ensuring clear handoffs and shared visibility into status.
- Participate in change management and operational reviews where security input is needed.
- Support incident response efforts, including initial triage, containment recommendations, and coordination across teams during active incidents.
- Contribute to post-incident reviews and help translate lessons learned into process or tooling improvements.
- Mentor and provide day-to-day guidance to SOC analysts; support onboarding and skills development.
- Help set expectations for case quality, communication, and escalation practices.
- Track and report on SOC operational metrics (case volume, time-to-triage, time-to-resolution, escalation rates) to the Director, Cyber Defense & Strategy.
- Flag trends or recurring issues that indicate a need for process, tooling, or staffing changes.
5+ years of experience in a Security Operations Center or similar cyber defense role, including at least 1-2 years in a lead, senior analyst, or shift-lead capacity
- Demonstrated experience managing case/ticket queues and driving them to resolution in a fast-paced environment.
- Working knowledge Of SIEM, EDR, and case/ticket management tooling
- Comfortable working cross-functionally with Technology Operations, IT, and Engineering teams.
- Strong written and verbal communication skills; able to translate technical detail for varied audiences.
- Willingness and ability to work on-site in Draper, UT, including participation in on-call/shift coverage as needed.
ESSENTIAL_SKILLS
"5+ years of experience in a Security Operations Center or similar cyber defense role, including at least 1-2 years in a lead, senior analyst, or shift-lead capacity
- Demonstrated experience managing case/ticket queues and driving them to resolution in a fast-paced environment.
- Working knowledge Of SIEM, EDR, and case/ticket management tooling
- Comfortable working cross-functionally with Technology Operations, IT, and Engineering teams.
- Strong written and verbal communication skills; able to translate technical detail for varied audiences.
- Willingness and ability to work on-site in Draper, UT, including participation in on-call/shift coverage as needed."
Cyber Defesne SOC, SIEM, EDR
EXPERIENCE_RANGE_IN_REQUIRED_SKILLS
8 to 10
Role Descriptions: Case Queue Management Own the SOC case queue triage incoming alerts| tickets| and requests assign priority andownership track cases through to resolution. Maintain SLAs for case handling and escalation identify and clear bottlenecks before theybecome backlogs. Ensure consistent documentation| categorization| and closure quality across all cases. SOC Leadership OperationsLead day-to-day SOC operations| including monitoring| alert triage| and initial incidentresponse. Coordinate shift coverage and on-call rotations to maintain continuous monitoring. Serve as a senior escalation point for analysts on complex or ambiguous cases. Drive continuous improvement Of detection content| playbooks| and standard operatingprocedures. Partnering with Technology Operations Act as the primary liaison between Cyber Defense and Tech Operations on issues that spanboth teams (eg.| system changes| outages| access requests| infrastructure-related findings). Coordinate response and remediation activities that require Tech Operations involvement|ensuring clear handoffs and shared visibility into status. Participate in change management and operational reviews where security input is needed. Incident Response Support incident response efforts| including initial triage| containment recommendations| andcoordination across teams during active incidents. Contribute to post-incident reviews and help translate lessons learned into process or toolingimprovements. Mentorship Team Development Mentor and provide day-to-day guidance to SOC analysts support onboarding and skillsdevelopment. Help set expectations for case quality| communication| and escalation practices. Reporting Metrics Track and report on SOC operational metrics (case volume| time-to-triage| time-to-resolution|escalation rates) to the Director| Cyber Defense Strategy. Flag trends or recurring issues that indicate a need for process| tooling| or staffing changes.
Essential Skills: Experience in a regulated industry (healthcare| financial services| or similar) handlingsensitive data. Relevant certifications such as GCIH| GCIA| Security| CySA| or equivalent. Familiarity with cloud environments (AWSlAzure) and common cloud security tooling. Prior experience building or refining SOC playbooks| runbooks| or standard operatingprocedures.
What Success Looks Like in the First 6 Months SOC case queue is triaged consistently with clear ownership and no unexplained aging Escalation paths to Tech Operations are documented and running smoothly| with fewerdropped handoffs. Analyst team has clear expectations| regular feedback| and improving case quality.
Director| Cyber Defense Strategy has reliable visibility into SOC health through regularreporting
Desirable Skills:
Keyword:
Skills: Digital : Microsoft Azure~Digital : Amazon Web Service(AWS) Cloud Computing~Cyber Security~MSS - Security Operations Center (SOC)~Microsoft Identity And Access Management
Experience Required: 8-10
Similar jobs
- NF
Senior Principal Data Scientist (Marketing Data Specialist)
NewNavy Federal Credit Union
United States🇺🇸Hybrid9 hours agoSQLScalaAWS+3Technology - SA
Sr. Sales Analytics Specialist (Bilingual - Korean)
NewSAMYANG AMERICA INC
United States🇺🇸$75k - $95k/yrHybrid8 hours agoKPI ManagementMicrosoft ExcelTechnology - TH
Industrial Controls Integration Engineer
NewTOMORROW HIRE
United States🇺🇸Remote10 hours agoRoboticsPLC ProgrammingSCADA+1Technology - HU
Senior Software Engineer - Salesforce Sales/Health Cloud
NewHumana
United States🇺🇸$106.9k - $147k/yrHybrid8 hours agoAgileAzureTechnology - PW
Finance Transformation - Systems Integration Lead, Manager
NewPwC
United States🇺🇸$99k - $232k/yrHybrid8 hours agoOracleAgileTechnology - RA
Data Engineer
NewRaydar
United States🇺🇸Remote12 hours agoSQLAWSCompliance+5Technology