Security Operations Center Analyst

StevenDouglas

Miami (FL)

Hybrid

USD 100,000 - 140,000

Full time

6 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work arrangement

Job summary

StevenDouglas is seeking a Senior SOC Analyst in Miami to lead investigations, coordinate with our MDR partner, and drive automation for faster threat detection and response.

The role focuses on proactive threat hunting, playbook development, and mentoring Tier 1/2 analysts in a hybrid in-office and remote setup. 3-month assignment with in-office 3 days per week.

Qualifications

  • Minimum 5-7 years in cybersecurity operations, with at least 3 years in Tier 2/3 SOC or escalation.
  • CompTIA Security+ or equivalent certification required.
  • Proven experience leading incident response triage, investigation, and remediation with MDR partners.
  • Deep knowledge of SIEM/SOAR tools (e.g., Microsoft Sentinel) and EDR solutions (Defender XDR, Cortex XDR).
  • Ability to author, tune detection content (e.g., KQL) and productionize it.
  • Experience with cloud telemetry (Azure/AWS) and automation in SOAR workflows.

Responsibilities

  • Lead investigations of high severity security incidents from detection through containment and recovery with MDR coordination.
  • Serve as primary escalation point for Tier 3 alerts; perform root cause analyses with remediation plans.
  • Act as liaison to MDR provider; validate alerts, tune detection, and refine response playbooks.
  • Develop and maintain incident response runbooks and workflows; mentor junior analysts.
  • Monitor logs across SIEM/EDR and cloud platforms; correlate data to identify patterns and threats.
  • Generate executive and technical SOC reports; support audits and evidence handling.
  • Drive automation to reduce manual steps and improve MTTD/MTTR; partner on tooling improvements.

Skills

Incident response
Threat hunting
Analytical thinking
Communication
Team leadership
MDR coordination

Tools

Microsoft Sentinel
Defender XDR
Palo Alto Cortex XDR
ServiceNow
SOAR platforms

Job description

Rate to suppliers: not to exceed between $86.33 - $97.00

Hybrid with 3 days a week in office and 2 days remote

Location: Miami, Florida

3-month assignment

Sr Security Operations Center (SOC) Analyst

We are seeking a highly skilled and experienced Senior SOC Analyst to join our cybersecurity team. This role is critical in leading advanced incident response efforts, managing escalations from cross functional teams and working closely with our MDR partner to ensure rapid detection, containment, and remediation of security threats. The ideal candidate will have deep technical expertise, strong analytical skills, and a proactive mindset toward incident response and continuous improvement.

  • A career focused on proactive threat detection and response.
  • A career that protects critical assets and enables secure business operations.
Your Responsibilities on the Team
  • Lead investigations of complex, high severity security incidents from detection through containment, remediation, and recovery, coordinating across internal teams and the MDR partner.
  • Act as the primary escalation point for Tier 3 alerts and incidents and perform root cause analysis with actionable remediation plans.
  • Serve as the primary liaison to the MDR provider: validate and triage MDR alerts, ensure alignment on response protocols and escalation procedures, and provide tuning recommendations to improve detection fidelity.
  • Develop and maintain incident response playbooks, runbooks, and workflows.
  • Analyze threat actor tactics, techniques, and procedures (TTPs) and translate findings into improved defenses and detection content.
Threat Hunting
  • Conduct proactive, hypothesis-driven threat hunts across endpoint, identity, network, and cloud telemetry, leveraging threat intelligence and the MITRE ATT&CK framework to surface threats that evade automated detection.
  • Operationalize hunt findings into durable detection logic and response procedures.
Automation & Process Improvement
  • Identify recurring, manual, or manual heavy SOC processes and design automation to reduce analyst effort and accelerate response.
  • Build, test, and maintain automated playbooks and response workflows in a SOAR platform (e.g., Torq, Microsoft Sentinel Automation Rules and Logic Apps) for enrichment, triage, containment, and case management.
  • Develop, tune, and operationalize detection and correlation rules through automated validation and deployment.
  • Measure the impact of automation against SOC performance metrics (MTTD, MTTR, alert volume, false-positive rate) and iterate based on results.
  • Partner with Detection Engineering and Security Engineering to integrate tooling, close telemetry gaps, and standardize repeatable response.
Security Monitoring & Analysis
  • Monitor and analyze logs and alerts across SIEM, EDR, identity, and cloud platforms.
  • Correlate data across multiple sources to identify patterns, anomalies, and emerging threats.
  • Maintain situational awareness of the external threat landscape and internal security posture.
  • Mentor Tier 1 and Tier 2 analysts, lead knowledge-sharing, and uplevel team investigative tradecraft and tooling proficiency.
  • Document incident timelines, findings, and lessons learned.
  • Track, analyze, and drive improvement of core SOC performance metrics (MTTD, MTTR, detection coverage, false-positive rate), and use them to prioritize tuning and automation efforts.
  • Generate executive-level and technical reports on SOC performance and incidents, and support compliance and audit efforts through accurate record-keeping and evidence handling.
Requirements
  • Minimum 5-7 years of experience in a cybersecurity operations role, with at least 3 years in a Tier 2/Tier 3 SOC or escalation capacity.
  • CompTIA Security+ or equivalent.
  • Proven experience leading incident response triage, investigation, and remediation, including working directly with MDR partners.
  • In-depth knowledge of security tools and technologies, including SIEM/SOAR platforms (e.g., Microsoft Sentinel), endpoint detection and response solutions (e.g., Microsoft Defender XDR, Palo Alto Cortex XDR), and ticketing systems (e.g., ServiceNow).
  • Demonstrated ability to author and tune detection content (e.g., KQL in Sentinel/Defender) and operationalize it into production.
  • Experience analyzing cloud security telemetry (e.g., Azure/Entra sign-in logs, AWS CloudTrail).
  • Hands‑on experience building or maintaining automated playbooks and response workflows in a SOAR platform.
  • Strong understanding of network security concepts, operating systems, and malware analysis techniques.
  • Familiarity with the MITRE ATT&CK framework and threat intelligence platforms.
  • Excellent analytical, problem‑solving, and communication skills, with the ability to work under pressure and manage multiple priorities.
Preferred
  • Certifications such as CISSP, GCIA, GCIH, GCFA, CySA+, eJPT/PJPT, CEH, SC-200.
  • Scripting and automation skills (Python, PowerShell) for tooling, enrichment, and analysis.
  • Experience supporting an EDR platform migration (e.g., Cortex XDR to Microsoft Defender XDR).
  • Experience with or strong interest in AI-assisted triage and agentic SOC tooling to augment analyst workflows.
  • Broader cloud security experience across AWS, Azure, and OCI.
  • Experience with Microsoft Sentinel, Proofpoint, and Palo Alto Cortex XDR.
  • Mandatory 4-days onsite; 1-days remote.
  • On-call rotation may be required for critical incident response.
  • Collaborative team environment with opportunities for growth and specialization.

This description outlines the basic responsibilities and requirements for the position noted. This is not a comprehensive listing of all job duties of the Associates. Duties, responsibilities and activities may change at any time with or without notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Operations Analyst
Senior Security Operations Analyst

Prosegur Security USA, Inc • Lowell (MA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Senior SOC Analyst (Direct Hire EAD OKAY)
Senior SOC Analyst (Direct Hire EAD OKAY)

Confidential • United States

Hybrid
USD 120,000 - 180,000
Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

Hybrid
USD 110,000 - 150,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Senior SOC Analyst- Tuesday- Saturday
Senior SOC Analyst- Tuesday- Saturday

BNY Mellon • Pittsburgh

On-site
USD 110,000 - 150,000
Senior SOC Analyst- Tuesday- Saturday
Senior SOC Analyst- Tuesday- Saturday

BNY Mellon • Town of Florida (NY)

On-site
USD 110,000 - 160,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Security Operations Center Analyst
Security Operations Center Analyst

Charter Solutions • Minneapolis (MN), Saint Paul (MN)

Hybrid
USD 70,000 - 100,000
Network Security Analyst
Network Security Analyst

ArnAmy, Inc. • Austin (TX)

On-site
USD 85,000 - 120,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000