- Monitor SIEM, trouble tickets, email notifications, in-person escalations, and logs from IC infrastructure, applications, and network devices
- Design, implement, and test SOAR processes and procedures
- Develop SOAR playbooks and troubleshoot automation capabilities
- Examine escalated tickets to determine true positives or false positives
- Perform malware analysis, threat hunting, and threat modeling
- Assist forensic investigations by providing reports and other information
- Review and suggest improvements to control deployment processes and installation procedures
- Develop and document remediation recommendations for business owners in understandable language
- Recommend and direct tuning of signatures, rules, alerts, parsers, and custom scripts
- Participate in root cause analysis and help orchestrate remediation
- Apply defense-in-depth strategies to client environments
- Create and disseminate security notifications for internal staff
- Act as the Level 2 escalation layer in the SOC
- Mentor Level 1 SOC Analysts
- Create manuals, guides, and knowledge‑base entries
- Monitor current security and privacy legislation, emerging threats, regulations, advisories, alerts, and vulnerabilities
- Maintain knowledge of the company’s solution portfolio and technical offerings
Requirements
- 7+ years of experience in Information Technology, cybersecurity, or a related technical field
- 5+ years of experience working in a Security Operations Center (SOC), cybersecurity operations, incident response, or a related security function
- 5+ years of experience working with Security Information and Event Management (SIEM) or Security Orchestration, Automation and Response (SOAR) technologies
- 5+ years of experience developing or implementing security automation using Python, SOAR platforms, or similar technologies
- U.S. Person requirement: U.S. citizen, U.S. permanent resident, protected status in the U.S. under asylum or refugee status, or ability to obtain an export authorization
- Bachelor’s degree in Computer Science, Computer Information Systems, Electronics, or a related field (valued/preferred)
- ITIL Foundation certification or a cybersecurity certification such as CompTIA Security+, GCIH, CCNA, GCFA, or CEH (valued/preferred)
- Experience with SIEM platforms and security logging solutions such as Swimlane, Sentinel, or Google SecOps (valued/preferred)
Core Competencies
Demonstrates extensive experience in Security Operations Center (SOC) functions, including incident response, threat hunting, and security automation. Proficient in developing and implementing SOAR processes and playbooks, with a strong focus on security monitoring and compliance.
Highest-signal resume keywords
- Security Operations Center (SOC) Experience
- Security Information and Event Management (SIEM)
- Security Orchestration, Automation and Response (SOAR)
- Malware Analysis and Threat Hunting
- Python for Security Automation
Hard Skills
- Incident Response
- Threat Modeling
- Security Automation
- Malware Analysis
- Root Cause Analysis
- Control Deployment Processes
- Remediation Recommendations
- Security Notifications
- Defense-in-Depth Strategies
- Troubleshooting Automation Capabilities
Soft Skills
- Mentoring Level 1 SOC Analysts
- Effective Communication
- Collaboration
- Problem Solving
- Report Writing
Certifications & Qualifications
- ITIL Foundation
- CompTIA Security+
- GCIH
- CCNA
- GCFA
- CEH
Industry Keywords
- Cybersecurity
- Information Technology
- Security Operations
- Threat Intelligence
- Compliance Regulations
Tools & Technologies
- SIEM Platforms
- SOAR Technologies
- Swimlane
- Sentinel
- Google SecOps