Senior Cyber Security Architect

Jobtailor

Duluth (GA)

On-site

USD 90,000 - 120,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Jobtailor is seeking an experienced Senior SOC Analyst to monitor, analyze, and respond to security events across client environments. You will design and implement automation using SIEM/SOAR platforms, perform threat hunting, and guide incident response efforts.

The role requires 7+ years in IT/cybersecurity, a strong SOAR/Python background, and relevant certifications. You will mentor junior staff and contribute to remediation and knowledge base development, ensuring defense-in-depth across

Qualifications

  • 7+ years of experience in Information Technology, cybersecurity, or a related technical field.
  • 5+ years of experience in a Security Operations Center (SOC), cybersecurity operations, incident response, or a related security function.
  • 5+ years of experience working with SIEM or SOAR technologies.
  • 5+ years of experience developing or implementing security automation using Python, SOAR platforms, or similar technologies.
  • Bachelor’s degree in Computer Science, Computer Information Systems, Electronics, or a related field.
  • Experience with SIEM platforms and security logging solutions such as Swimlane, Sentinel, or Google SecOps.
  • Candidate must be a U.S. Person: a U.S. citizen, U.S. permanent resident, protected status holder under asylum or refugee status, or someone with the ability to obtain an export authorization.

Responsibilities

  • Monitor and respond to security incidents using SIEM/SOAR tools and coordinate resolutions.
  • Develop and test security automation playbooks and remediation procedures.
  • Lead root cause analysis and coordinate remediation across teams.
  • Mentor Level 1 SOC Analysts and develop knowledge base materials.
  • Stay current on security regulations, threats, and industry best practices.

Skills

Python Programming
Security Automation
Threat Hunting
Threat Modeling
Root Cause Analysis
Remediation Recommendations
Control Deployment
Forensic Investigations
Incident Response
Malware Analysis

Education

Bachelor's degree in Computer Science
ITIL Foundation
CompTIA Security+
GCIH
CCNA
GCFA
CEH

Tools

SCADA
HMI
PLC
RTU
Firewalls
IDS/IPS
Swimlane
Sentinel
Google SecOps

Job description

  • Monitor SIEM, trouble tickets, email notifications, in-person escalations, and logs from ICs infrastructure components including SCADA, HMI, PLC, RTU, and control servers
  • Monitor applications and network devices such as switches, firewalls, and IDS/IPS
  • Design, implement, and test SOAR processes and procedures
  • Develop SOAR playbooks and troubleshoot automation capabilities
  • Examine escalated tickets to determine true positives and false positives
  • Perform malware analysis, threat hunting, and threat modeling
  • Assist forensic investigations by providing reports and other information
  • Review and suggest improvements to control deployment processes and installation procedures
  • Develop and document remediation recommendations for business owners in an accessible manner
  • Recommend and direct tuning of signatures, rules, alerts, parsers, and custom scripts
  • Participate in root cause analysis and coordinate remediation
  • Apply defense-in-depth strategies to client environments
  • Create and disseminate security notifications for internal staff
  • Act as the L2 escalation layer in the SOC
  • Mentor Level 1 SOC Analysts
  • Create manuals, guides, and knowledge base entries
  • Stay current on security and privacy legislation, emerging threats, regulations, advisories, alerts, and vulnerabilities
  • Maintain knowledge of the company’s solution portfolio and technical offerings
Requirements
  • 7+ years of experience in Information Technology, cybersecurity, or a related technical field
  • 5+ years of experience working in a Security Operations Center (SOC), cybersecurity operations, incident response, or a related security function
  • 5+ years of experience working with Security Information and Event Management (SIEM) or Security Orchestration, Automation and Response (SOAR) technologies
  • 5+ years of experience developing or implementing security automation using Python, SOAR platforms, or similar technologies
  • Bachelor’s degree in Computer Science, Computer Information Systems, Electronics, or a related field
  • ITIL Foundation certification or a cybersecurity certification such as CompTIA Security+, GCIH, CCNA, GCFA, or CEH
  • Experience with SIEM platforms and security logging solutions such as Swimlane, Sentinel, or GOOGLE SECOPS
  • Candidate must be a U.S. Person: a U.S. citizen, U.S. permanent resident, protected status holder under asylum or refugee status, or someone with the ability to obtain an export authorization
Core Competencies

Demonstrates extensive experience in Security Operations Center (SOC) functions, including monitoring and responding to security incidents, developing and implementing security automation, and conducting threat analysis. Proficient in utilizing SIEM and SOAR technologies to enhance security operations and improve incident response capabilities.

Highest-signal resume keywords
  • SIEM Technologies
  • SOAR Development
  • Malware Analysis
  • Incident Response
  • Cybersecurity Certifications
Hard Skills
  • Python Programming
  • Security Automation
  • Threat Hunting
  • Threat Modeling
  • Root Cause Analysis
  • Control Deployment Processes
  • Remediation Recommendations
  • Security Logging Solutions
  • Defense-in-Depth Strategies
  • Forensic Investigations
Soft Skills
  • Mentoring
  • Communication
  • Collaboration
Certifications & Qualifications
  • ITIL Foundation
  • CompTIA Security+
  • GCIH
  • CCNA
  • GCFA
  • CEH
Industry Keywords
  • Cybersecurity
  • Security Operations Center
  • Incident Response
  • Security Information and Event Management
  • Security Orchestration Automation and Response
Tools & Technologies
  • SCADA
  • HMI
  • PLC
  • RTU
  • Firewalls
  • IDS/IPS
  • Swimlane
  • Sentinel
  • Google SecOps
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Advanced Cyber Security Architect
Senior Advanced Cyber Security Architect

Jobtailor • Duluth (GA)

On-site
USD 120,000 - 160,000
Security Operations Lead
Security Operations Lead

Jobtailor • Pennsylvania

On-site
USD 120,000 - 160,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Tier 2 Security Operations Center (SOC) Analyst
Tier 2 Security Operations Center (SOC) Analyst

Jobtailor • California (MO)

On-site
USD 95,000 - 125,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

Jobtailor • Town of Montana (WI)

On-site
USD 85,000 - 125,000
Lead, Incident Response – Global CSIRT
Lead, Incident Response – Global CSIRT

Jobtailor • United States

On-site
USD 150,000 - 190,000
Health insurance
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Detection and platform engineer
Detection and platform engineer

Tixy Services LLC • Town of Texas (WI), Fort Worth (TX)

Hybrid
USD 120,000 - 180,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000