About the Company- Hybrid Role: Springfield Ma Area
As a Senior SOC Analyst, you will play a pivotal role in defending critical infrastructure.
About the Role
As a Senior SOC Analyst, you will operate independently with minimal supervision to detect, analyze, and respond to complex security threats in a fast paced, mission critical SOC environment supporting electric grid operations, while leading response efforts for high severity and complex security incidents and serving as a project implementor for SOC‑related initiatives.
Responsibilities
- Operate independently with minimal supervision to detect, analyze, and respond to complex security threats in a fast paced, mission critical SOC environment supporting electric grid operations.
- Lead response efforts for high severity and complex security incidents, coordinating containment, eradication, and recovery across IT, OT, and engineering teams.
- Apply threat modeling techniques to anticipate adversary attack paths, inform detection strategy, and improve defensive coverage across critical infrastructure systems.
- Perform advanced threat detection and analysis using SIEM, EDR/XDR, network monitoring, and forensic tools.
- Conduct malware analysis, digital forensics, and root cause investigations following security events affecting critical systems.
- Develop, tune, and maintain detection rules, correlation logic, and automated response playbooks to continuously improve SOC effectiveness.
- Coordinate tabletop exercises, purple team activities, and grid focused security assessments.
- Mentor and train junior SOC analysts, providing guidance on investigation techniques, tools, and best practices.
- Serve as the project implementor for SOC‑related initiatives, partnering with the PMO to plan, coordinate, and execute corporate security projects impacting SOC operations.
Required Skills
- SIEM platforms (Splunk, QRadar, ArcSight, Microsoft Sentinel, or similar)
- EDR/XDR solutions (CrowdStrike, Carbon Black, Microsoft Defender, SentinelOne, or similar)
- Network analysis tools (Wireshark, Zeek, tcpdump)
- Forensic tools and techniques (EnCase, FTK, Volatility, Autopsy)
- Attack frameworks such as MITRE ATT&CK and the Cyber Kill Chain
- Threat actor tactics, techniques, and procedures (TTPs)
- Threat intelligence frameworks and indicators of compromise (IOCs)
- Firewalls, IDS/IPS, and proxy technologies
- Windows and Linux operating systems (administration and security hardening)
- Cloud environments (AWS, Azure, GCP) and cloud security principles
- Scripting languages (Python, PowerShell, Bash)
- Malware analysis techniques (static and dynamic analysis)
- Log analysis and event correlation
- Vulnerability management concepts
Preferred Skills
- Relevant certifications such as GCIA, GCIH, GCFA, GREM, CISSP, CySA+, or equivalent
- Experience in critical infrastructure or energy sector environments
- Background in threat hunting or offensive security concepts
- Familiarity with NERC CIP compliance requirements
- Experience with SOAR platforms (Splunk SOAR, Palo Alto XSOAR, Swimlane)