Senior Security Analyst – Security Operations Center

Jobtailor

Town of Florida (NY)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in New York seeks an experienced cybersecurity operations professional to lead investigations of high severity incidents from detection to containment and recovery. You will act as the primary escalation point for Tier 3 alerts and coordinate with the MDR provider to triage and respond quickly.

This role requires hands-on expertise with SIEM/SOAR tools, EDR solutions, threat hunting, and developing playbooks and automation in a SOAR platform.

Qualifications

  • Minimum 5-7 years in a cybersecurity operations role.
  • At least 3 years in Tier 2/3 SOC or escalation capacity.
  • CompTIA Security+ or equivalent.
  • Proven experience leading incident response triage, investigation, and remediation.
  • Deep knowledge of SIEM/SOAR platforms (e.g., Microsoft Sentinel).
  • Experience with EDR solutions (e.g., Defender XDR, Cortex XDR).
  • Experience with ServiceNow ticketing.
  • Ability to author and tune detection content (KQL).
  • Experience analyzing cloud security telemetry.
  • Hands-on with automated playbooks and SOAR workflows.
  • Strong understanding of network security, OS, and malware analysis.
  • Familiarity with MITRE ATT&CK and threat intelligence.
  • Excellent communication and collaboration skills.
  • Preferred CISSP, GCIA, GCIH, GCFA, CySA+, eJPT/PJPT, CEH, SC-200.
  • Scripting skills (Python, PowerShell).
  • Experience supporting an EDR platform migration.

Responsibilities

  • Lead investigations of complex, high severity security incidents from detection through containment, remediation, and recovery
  • Act as the primary escalation point for Tier 3 alerts and incidents
  • Perform root cause analysis with actionable remediation plans
  • Serve as the primary liaison to the MDR provider
  • Validate and triage MDR alerts
  • Ensure alignment on response protocols and escalation procedures
  • Provide tuning recommendations to improve detection fidelity
  • Develop and maintain incident response playbooks, runbooks, and workflows
  • Analyze threat actor TTPs and translate findings into improved defenses and detection content
  • Conduct proactive threat hunts across endpoint, identity, network, and cloud telemetry
  • Leverage threat intelligence and MITRE ATT&CK to surface threats
  • Identify recurring manual SOC processes
  • Design automation to reduce analyst effort and accelerate response
  • Build, test, and maintain automated playbooks and response workflows in a SOAR platform
  • Monitor and analyze logs across SIEM, EDR, identity, and cloud platforms
  • Correlate data to identify patterns, anomalies, and emerging threats
  • Mentor Tier 1 and Tier 2 analysts
  • Document incident timelines, findings, and lessons learned
  • Generate executive-level and technical reports on SOC performance and incidents

Skills

Incident response
Threat hunting
SOC escalation
MITRE ATT&CK knowledge
KQL querying
Python scripting
PowerShell scripting
Analytical thinking
Communication
Mentoring

Education

CompTIA Security+

Tools

Microsoft Sentinel
Microsoft Defender XDR
Palo Alto Cortex XDR
ServiceNow
SOAR platforms
KQL

Job description

Responsibilities
  • Lead investigations of complex, high severity security incidents from detection through containment, remediation, and recovery
  • Act as the primary escalation point for Tier 3 alerts and incidents
  • Perform root cause analysis with actionable remediation plans
  • Serve as the primary liaison to the MDR provider
  • Validate and triage MDR alerts
  • Ensure alignment on response protocols and escalation procedures
  • Provide tuning recommendations to improve detection fidelity
  • Develop and maintain incident response playbooks, runbooks, and workflows
  • Analyze threat actor tactics, techniques, and procedures (TTPs) and translate findings into improved defenses and detection content
  • Conduct proactive, hypothesis-driven threat hunts across endpoint, identity, network, and cloud telemetry
  • Leverage threat intelligence and the MITRE ATT&CK framework to surface threats that evade automated detection
  • Identify recurring, manual, or manual heavy SOC processes
  • Design automation to reduce analyst effort and accelerate response
  • Build, test, and maintain automated playbooks and response workflows in a SOAR platform
  • Monitor and analyze logs and alerts across SIEM, EDR, identity, and cloud platforms
  • Correlate data across multiple sources to identify patterns, anomalies, and emerging threats
  • Mentor Tier 1 and Tier 2 analysts
  • Document incident timelines, findings, and lessons learned
  • Generate executive-level and technical reports on SOC performance and incidents
Requirements
  • Minimum 5-7 years of experience in a cybersecurity operations role
  • At least 3 years in a Tier 2/Tier 3 SOC or escalation capacity
  • CompTIA Security+ or equivalent
  • Proven experience leading incident response triage, investigation, and remediation
  • In-depth knowledge of security tools and technologies, including SIEM/SOAR platforms (e.g., Microsoft Sentinel)
  • Endpoint detection and response solutions (e.g., Microsoft Defender XDR, Palo Alto Cortex XDR)
  • Ticketing systems (e.g., ServiceNow)
  • Demonstrated ability to author and tune detection content (e.g., KQL in Sentinel/Defender)
  • Experience analyzing cloud security telemetry
  • Hands‑on experience building or maintaining automated playbooks and response workflows in a SOAR platform
  • Strong understanding of network security concepts, operating systems, and malware analysis techniques
  • Familiarity with the MITRE ATT&CK framework and threat intelligence platforms
  • Excellent analytical, problem‑solving, and communication skills
  • Preferred Certifications such as CISSP, GCIA, GCIH, GCFA, CySA+, eJPT/PJPT, CEH, SC‑200
  • Scripting and automation skills (Python, PowerShell)
  • Experience supporting an EDR platform migration
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Vice President, Senior SOC Analyst
Vice President, Senior SOC Analyst

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Senior Security Analyst, Cyber Defense
Senior Security Analyst, Cyber Defense

Jobtailor • Minneapolis (MN)

On-site
USD 110,000 - 140,000
Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

Hybrid
USD 110,000 - 150,000
Cybersecurity Analyst, Security Operations Center (SOC) Analyst
Cybersecurity Analyst, Security Operations Center (SOC) Analyst

Digital Global Connectors • McLean (VA)

Hybrid
USD 70,000 - 110,000
Senior SOC Analyst (Direct Hire EAD OKAY)
Senior SOC Analyst (Direct Hire EAD OKAY)

Confidential • United States

Hybrid
USD 120,000 - 180,000
Senior Security Analyst
Senior Security Analyst

Yardi • Santa Barbara (CA)

On-site
USD 97,000 - 110,000
Security Operations Center Analyst
Security Operations Center Analyst

Diligente Technologies • San Jose (CA)

On-site
USD 80,000 - 100,000
Remote SOC Analyst
Remote SOC Analyst

Globalchannelmanagement • Atlanta (GA)

Remote
USD 80,000 - 100,000