Lead SOC Analyst

UFP Industries

Grand Rapids (MI)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

UFP Industries in Grand Rapids, MI is looking for a Lead SOC Analyst to oversee the Security Operations Center's daily operations. This role focuses on threat detection, incident response, and managing relationships with our external managed detection and response provider. The Lead SOC Analyst will also maintain SOC processes and documentation to enhance security standards.

Ideal candidates will have 7+ years in cybersecurity roles and a Bachelor's degree in Computer Science or a related field. Strong leadership and communication skills are essential, with experience using tools like Splunk preferred.

Qualifications

  • 7+ years of experience in a SOC, incident response, or cybersecurity operations role.
  • Proven experience leading incident investigations and managing escalations.
  • Strong written and verbal communication skills.

Responsibilities

  • Lead incident response activities across teams.
  • Serve as the primary liaison with the MDR provider.
  • Develop and maintain SOC procedures and documentation.

Skills

Incident response
Threat hunting
Security operations tools
Leadership and mentoring

Education

Bachelor’s degree in computer science or information security

Tools

Splunk
Microsoft Sentinel

Job description

Job Summary

The Lead SOC Analyst is responsible for leading the daily operations of the Security Operations Center (SOC) while actively participating in threat detection, investigation, and response activities. This role operates in a player/coach capacity, balancing hands‑on incident response with team leadership, process development, and SOC maturity initiatives. The Lead SOC Analyst serves as the primary point of coordination between the internal SOC and external managed detection and response (MDR) provider, ensuring effective monitoring, escalation, and response to security events. This role is also responsible for developing and maintaining SOC processes, playbooks, and documentation to improve the organization’s overall security posture. This role reports to the Manager of Cyber Defense.

Location: This role must work on‑site, full‑time out of our Grand Rapids, MI office.

Principal Duties And Responsibilities
SOC Operations and Incident Response
  • Act as the senior escalation point for security incidents, providing hands‑on investigation and response.
  • Perform advanced threat hunting, incident analysis, and root cause determination.
  • Lead and coordinate incident response activities across IT, infrastructure, and application teams.
  • Validate and enrich alerts generated by internal tools and external MDR provider.
  • Ensure timely containment, remediation, and closure of security incidents.
MDR Vendor Management
  • Serve as the primary operational liaison with our MDR provider.
  • Manage day‑to‑day interactions including alert triage alignment, escalation handling, and service quality.
  • Review MDR detections, investigations, and recommendations for accuracy and relevance.
  • Identify and drive improvements in detection coverage, alert fidelity, and response processes.
  • Participate in regular service reviews and ensure deliverables meet organizational expectations.
SOC Leadership and Team Development
  • Provide technical leadership and guidance to SOC analysts.
  • Lead daily SOC operations including prioritization of alerts, workload management, and escalation decisions.
  • Mentor and develop analysts through coaching, training, and knowledge sharing.
  • Establish expectations for investigation quality, documentation, and response timelines.
  • Support hiring, onboarding, and skill development of SOC team members.
SOC Maturity and Process Development
  • Develop, document, and maintain SOC standard operating procedures (SOPs), playbooks, and runbooks.
  • Identify gaps in SOC processes and implement improvements to increase consistency and effectiveness.
  • Define and track SOC metrics and KPIs (e.g., MTTR, alert volume, false positives, escalation rates).
  • Standardize incident documentation and evidence collection to support audit and compliance requirements.
  • Drive continuous improvement initiatives aligned to industry best practices and organizational goals.
Detection Engineering and Monitoring
  • Collaborate with engineering and security teams to improve detection logic and use cases.
  • Develop and tune detection rules within SIEM, XDR, and MDR platforms.
  • Identify gaps in logging and telemetry and work with teams to onboard required data sources.
  • Ensure monitoring coverage for systems handling sensitive or critical data.
  • Contribute to threat modeling and detection strategy development.
Communication and Stakeholder Engagement
  • Communicate security incidents, risks, and trends to technical and non‑technical stakeholders.
  • Provide clear and concise reporting on incident outcomes and lessons learned.
  • Partner with infrastructure, application, and business teams to improve security practices.
  • Support audit, compliance, and risk management activities as needed.
Qualifications
  • Bachelor’s degree in computer science, information security, or equivalent experience.
  • 7+ years of experience in a SOC, incident response, or cybersecurity operations role.
  • Proven experience leading incident investigations and managing escalations.
  • Experience working with a managed detection and response (MDR) provider (preferred).
  • Strong understanding of security operations tools (SIEM, XDR, EDR, SOAR platforms).
  • Experience with detection tuning, threat hunting, and log analysis.
  • Demonstrated ability to develop SOC processes, playbooks, and operational documentation.
  • Strong leadership, mentoring, and team development skills.
  • Excellent analytical, problem‑solving, and decision‑making capabilities.
  • Strong written and verbal communication skills.
Preferred Qualifications
  • Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms.
  • Experience working in a hybrid SOC model (internal + MDR).
  • Familiarity with compliance frameworks (e.g., NIST, CMMC).
  • Relevant certifications such as CISSP, GCIA, GCIH, or equivalent.

The Company is an Equal Opportunity Employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead SOC Analyst
Lead SOC Analyst

UFP Industries, Inc. • Grand Rapids (MI)

On-site
USD 90,000 - 120,000
Senior SOC Lead — Incident Response & MDR Liaison
Senior SOC Lead — Incident Response & MDR Liaison

UFP Industries • Grand Rapids (MI)

On-site
USD 100,000 - 130,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Senior SOC Lead: Incident Response & MDR Coordination
Senior SOC Lead: Incident Response & MDR Coordination

UFP Industries, Inc. • Grand Rapids (MI)

On-site
USD 90,000 - 120,000
Security Operations Center Manager
Security Operations Center Manager

Fidelity National Financial • Jacksonville (FL)

On-site
USD 140,000 - 180,000
SOC Manager
SOC Manager

GMI - Global Market Innovators • Scottsdale (AZ)

On-site
USD 100,000 - 130,000
Competitive salary and benefits package
401(k) match
Stock Appreciation Rights
+2
Sr SOC Analyst
Sr SOC Analyst

ASM Global LLC. • United States

Hybrid
USD 100,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+2
SOC Manager (Hands-On) - Remote (USA)
SOC Manager (Hands-On) - Remote (USA)

Echelon Risk + Cyber • Washington

On-site
USD 110,000 - 140,000
Health, dental, and vision insurance
401(k) with employer contribution
Flexible vacation policy
+1
SOC Manager with BS Degree
SOC Manager with BS Degree

Acumenz Consulting • United States

Remote
USD 120,000 - 150,000
SOC Manager
SOC Manager

HW3 • Jacksonville (FL)

On-site
USD 120,000 - 180,000