Security Operations Center (SOC) Lead - L3

Toyota North America

Plano (TX)

On-site

USD 95,000 - 130,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Comprehensive health care and wellness
Team Member Vehicle Purchase Discount
Relocation assistance (if applicable)

Job summary

Toyota North America is seeking a skilled SOC Analyst III to join the Security Operations Center. You will lead advanced threat detection, investigate complex incidents, and mentor junior staff across endpoints, networks, cloud, and identity environments.

You will design and tune detection content, coordinate response efforts, and collaborate with IT, engineering, and business teams to strengthen security posture. Strong MITRE ATT&CK knowledge and SIEM/EDR experience required.

Qualifications

  • Bachelor’s degree in Cybersecurity, IT, CS or equivalent.
  • 5+ years in cybersecurity operations, IR, threat hunting, or related field.
  • Experience investigating advanced threats across endpoint, network, cloud, and identity.
  • Strong understanding of MITRE ATT&CK framework.
  • Experience with SIEM, EDR/XDR, threat intel, and log analysis.
  • Excellent analytical, troubleshooting, and problem-solving skills.
  • Excellent written and verbal communication.
  • Industry certifications such as CISSP, GCIH, GCFA, GCIA, CySA+.

Responsibilities

  • Lead threat detection and monitoring across multiple platforms.
  • Investigate and validate cybersecurity threats and suspicious activity.
  • Perform threat hunting to detect emerging threats.
  • Develop detection logic, use cases, and alert content.
  • Lead complex incident investigations across endpoint, network, cloud, and identity.
  • Perform root cause analysis and assess scope and impact.
  • Coordinate containment, eradication, and recovery with stakeholders.
  • Document findings and lessons learned.
  • Evaluate and tune monitoring technologies to reduce false positives.
  • Onboard new log sources and security tools.
  • Support automation initiatives to improve SOC efficiency.
  • Develop and maintain SOC playbooks and processes.
  • Provide mentorship to Tier 1/2 analysts.
  • Escalate complex investigations and collaborate with IT/business teams.
  • Prepare incident summaries, metrics, and leadership reports.

Skills

Incident Response
Threat Hunting
Detection Engineering
Security Monitoring
Malware Analysis
Security Automation
Risk Assessment
Technical Leadership
Process Improvement
Cross-Functional Collaboration

Education

Bachelor’s degree in Cybersecurity
Bachelor’s degree in Information Technology
Bachelor’s degree in Computer Science
Industry certifications (CISSP, GCIH, GCFA, GCIA, CySA+)

Tools

SIEM
EDR/XDR
Threat Intelligence
Log Analysis Platforms

Job description

Overview

Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like at Toyota. As one of the world’s most admired brands, Toyota is growing and leading the future of mobility through innovative, high-quality solutions designed to enhance lives and delight those we serve. We’re looking for talented team members who want to Dream. Do. Grow. with us.

Who we are

Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like at Toyota. As one of the world’s most admired brands, Toyota is growing and leading the future of mobility through innovative, high-quality solutions designed to enhance lives and delight those we serve. We’re looking for talented team members who want to Dream. Do. Grow. with us.

An important part of the Toyota family is Toyota Financial Services (TFS), the finance and insurance brand for Toyota and Lexus in North America. While TFS is a separate business entity, it is an essential part of this world-changing company- delivering on Toyota’s vision to move people beyond what’s possible. At TFS, you will help create best-in‑class customer experience in an innovative, collaborative environment.

Toyota does not offer support or sponsorship of job applicants for employment‑based visas or any other work authorization for this role now or in the future. You must have the right to work in the United States and not require Toyota support or sponsorship for immigration‑related employment (e.g., H‑1B, O‑1, E‑3, H‑1B1, TN, F‑1 OPT, F‑1 STEM OPT, F‑1 CPT, ‘job flexibility benefits’ [also known as I‑140 or Adjustment of Status portability], etc.) now or in the future. You should not apply for this role if you will require Toyota to assist with immigration support or sponsorship now or in the future.

Whowe’relooking for

The SOC Analyst III serves as a senior member of the Security Operations Center, responsible for advanced threat detection, investigation, incident response, and security monitoring activities. This role provides technical leadership for complex cybersecurity incidents, develops and optimizes detection content, and collaborates with cross‑functional teams to strengthen the organization’s security posture. The SOC Analyst III also mentors junior analysts, drives continuous improvement initiatives, and contributes to the development of security operations processes and procedures.

Whatyou’llbe doing
Threat Detection & Monitoring
  • Lead advanced monitoring and analysis of security events, alerts, and telemetry from multiple security platforms.

  • Identify, investigate, and validate potential cybersecurity threats and suspicious activities.

  • Perform threat hunting activities to proactively detect malicious behavior and emerging threats.

  • Develop and maintain detection logic, use cases, correlation rules, and alerting content to improve security visibility.

Incident Response & Investigation
  • Lead investigations of complex security incidents across endpoint, network, cloud, and identity environments.

  • Perform root cause analysis and determine the scope, impact, and severity of security events.

  • Coordinate containment, eradication, and recovery efforts with internal and external stakeholders.

  • Document incident findings, actions taken, and lessons learned.

Security Engineering & Optimization
  • Evaluate and tune security monitoring technologies to improve detection effectiveness and reduce false positives.

  • Assist with onboarding and integration of new log sources, security tools, and data feeds.

  • Support automation initiatives that enhance SOC efficiency and operational effectiveness.

  • Contribute to the development and maintenance of SOC processes, playbooks, and operational standards.

Leadership & Collaboration
  • Provide technical mentorship and guidance to Tier 1 and Tier 2 analysts.

  • Serve as an escalation point for complex investigations and security incidents.

  • Collaborate with IT, infrastructure, cloud, engineering, and business teams to address security risks.

  • Participate in security exercises, tabletop events, and post-incident reviews.

Reporting & Continuous Improvement
  • Prepare incident summaries, metrics, and operational reports for leadership and stakeholders.

  • Analyze trends and recommend improvements to detection, response, and security operations capabilities.

  • Stay current on emerging threats, attack techniques, and industry best practices.

Core Competencies
  • Incident Response

  • Threat Hunting

  • Detection Engineering

  • Security Monitoring

  • Malware Analysis

  • Security Automation

  • Risk Assessment

  • Technical Leadership

  • Process Improvement

  • Cross‑Functional Collaboration

What you bring
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or equivalent experience.

  • 5+ years of experience in cybersecurity operations, incident response, threat hunting, or a related field.

  • Experience investigating advanced threats across endpoint, network, cloud, and identity technologies.

  • Strong understanding of attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK.

  • Experience with SIEM, EDR/XDR, threat intelligence, and log analysis platforms.

  • Strong analytical, troubleshooting, and problem‑solving skills.

  • Excellent written and verbal communication skills

  • Industry certifications such as CISSP, GCIH, GCFA, GCIA, CySA+, or equivalent.

Added bonusif you have
  • Experience with cloud security technologies and security monitoring in hybrid environments.

  • Experience developing detection content, threat‑hunting methodologies, and automation workflows.

  • Familiarity with scripting or automation languages such as PowerShell, Python, or similar technologies.

  • Experience supporting regulatory, compliance, or security framework requirements.

Whatwe’llbring

During your interview process, our team can fill you in on all the details of our industry‑leading benefits and career development opportunities. A few highlights include:

  • A work environment built on teamwork, flexibility, and respect

  • Professional growth and development programs to help advance your career, as well as tuition reimbursement

  • Team Member Vehicle Purchase Discount

  • Toyota Team Member Lease Vehicle Program (if applicable)

  • Comprehensive health care and wellness plans for your entire family

  • Toyota 401(k) Savings Plan featuring a company match, as well as an annual retirement contribution from Toyota regardless of whether you contribute (if applicable)

  • Paid holidays and paid time off

  • Referral services related to prenatal services, adoption, childcare, schools and more

  • Tax Advantaged Accounts (Health Savings Account, Health Care FSA, Dependent Care FSA)

  • Relocation assistance (if applicable)

Belonging at Toyota

Our success begins and ends with our people. We embrace all perspectives and value unique human experiences. Respect for all is our North Star.

Applicants for our positions are considered without regard to race, ethnicity, national origin, sex, sexual orientation, gender identity or expression, age, disability, religion, military or veteran status, or any other characteristics protected by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Center (SOC) Lead - L3
Security Operations Center (SOC) Lead - L3

Toyota Deutschland GmbH • Plano (TX)

On-site
USD 90,000 - 130,000
Vehicle purchase discount
Relocation assistance
Health care plans
+1
Security Operations Center (SOC) Lead - L3
Security Operations Center (SOC) Lead - L3

TCC Toyota Motor Credit Corporation Company • Plano (TX)

On-site
USD 90,000 - 140,000
Team Member Vehicle Purchase Discount
Team Member Lease Vehicle Program
Health care and wellness plans
Threat and Exposure Analyst, Senior
Threat and Exposure Analyst, Senior

Toyota North America • Plano (TX)

On-site
USD 120,000 - 160,000
Team Member Vehicle Purchase Discount
Comprehensive health care and wellness
Toyota 401(k) with company match
Threat and Exposure Analyst, Senior
Threat and Exposure Analyst, Senior

Toyota Deutschland GmbH • Plano (TX)

On-site
USD 110,000 - 150,000
Team Member Vehicle Purchase Discount
Relocation assistance
Comprehensive health care
Cyber Threat Emulation Operator, Senior
Cyber Threat Emulation Operator, Senior

Toyota North America • Plano (TX)

On-site
USD 140,000 - 200,000
Health care and wellness plans
Toyota 401(k) with company match
Paid holidays and PTO
+2
Threat and Exposure Analyst, Senior
Threat and Exposure Analyst, Senior

TCC Toyota Motor Credit Corporation Company • Plano (TX)

On-site
USD 120,000 - 150,000
Health care and wellness plans
Relocation assistance
Tuition reimbursement
Cyber Threat Emulation Operator, Senior
Cyber Threat Emulation Operator, Senior

Toyota Deutschland GmbH • Plano (TX)

On-site
USD 150,000 - 230,000
Team Member Vehicle Purchase Discount
Comprehensive health care and wellness
401(k) with company match
+1
Business Information Security Officer (BISO), Senior
Business Information Security Officer (BISO), Senior

Toyota Deutschland GmbH • Plano (TX)

On-site
USD 140,000 - 210,000
Health care plans
Relocation assistance
Tuition reimbursement
+1
Cyber Threat Emulation Operator, Senior
Cyber Threat Emulation Operator, Senior

TCC Toyota Motor Credit Corporation Company • Plano (TX)

On-site
USD 140,000 - 180,000
Vehicle purchase discount
Lease vehicle program
Health care and wellness plans
+1
Offensive Security Automation Engineer - Senior
Offensive Security Automation Engineer - Senior

Toyota North America • Plano (TX)

On-site
USD 140,000 - 200,000
Tuition reimbursement
Vehicle purchase discount
Lease vehicle program
+3