Senior Security Operations Analyst - Onsite

Core Specialty Insurance Services, Inc.

Cincinnati (OH)

On-site

USD 95,000 - 135,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
Life insurance
Short and long-term disability
401(k) with company match
Employee Assistance Plan
Health Savings Account
Flexible Spending Account
Wellness program

Job summary

Core Specialty Insurance Services, Inc. is seeking a Senior SOC Analyst (Level 2/3) to join our Security Operations Center in Cincinnati. This onsite role leads investigations, mentors L1 analysts, and drives detection and response improvements in a 24/7 environment.

You will validate threats, develop SIEM rules, and design automation to accelerate incident response, while coordinating with IT and security teams for containment and remediation. Bachelor’s degree and 3+ years in SOC are required.

Qualifications

  • 3+ years of experience in SOC operations, cybersecurity, or incident response.
  • Bachelor's degree in Cybersecurity, Computer Science, IT, or equivalent practical experience.
  • Certifications such as GCIH, GCIA, CEH, CompTIA CySA+, or CISSP.

Responsibilities

  • Investigate escalated alerts and perform deep-dive forensic analysis using SIEM, EDR, and threat intel tools.
  • Lead containment and remediation efforts for escalated incidents across environments.
  • Develop and tune SIEM use cases, correlation rules, and EDR detection logic to improve SOC efficiency.
  • Design and implement automation workflows to enhance incident response and investigation efforts.
  • Leverage AI platforms to assist with automation of SOC processes.
  • Conduct proactive hunts leveraging behavioral analytics and intelligence feeds to identify threats.
  • Work with IT, network, and security teams to contain incidents and strengthen defenses.
  • Maintain and enhance SOC playbooks, runbooks, and SOPs.
  • Prepare detailed incident reports, root cause analyses, and preventive recommendations.
  • Train L1 analysts and foster continuous learning.
  • Assess new security technologies or measures to enhance SOC capabilities.
  • Maintain endpoint security baselines aligned with CIS benchmarks.
  • Support integration and operations of a new primary EDR/SIEM platform.
  • Test and deploy endpoint security changes in coordination with IT operations.
  • Act as a senior escalation point during security incidents.
  • Contribute to incident response playbooks and post-incident reviews.
  • Produce high-quality documentation: architecture diagrams, SOPs, runbooks, policy rationales, audit artifacts, timelines.

Skills

SIEM
EDR
Threat intel
SQL
KQL
MITRE ATT&CK
Cyber Kill Chain
Python
PowerShell
Cloud security monitoring

Education

Bachelor's degree in Cybersecurity, Computer Science, IT

Tools

Threat intelligence platforms
EDR platforms
SIEM platforms

Job description

- We are seeking a Senior SOC Analyst (Level 2/3) to join our Security Operations Center team onsite (Monday through Friday) within our Cincinnati office (this is NOT a hybrid or remote role). This role is pivotal in advanced threat detection, incident analysis, response coordination, and automation development. Acting as an escalation point for L1 analysts, you will lead investigations into complex security incidents, mentor junior team members, and drive improvements in detection and response capabilities within a fast-paced, 24/7 operational setting.

Key Accountabilities/Deliverables:
  • Investigate escalated alerts, validate threats, and perform deep-dive forensic analysis using SIEM, EDR, and threat intelligence tools.
  • Lead containment and remediation efforts for escalated incidents across multiple environments.
  • Develop and tune SIEM use cases, correlation rules, and EDR detection logic to improve SOC efficiency.
  • Design and implement automation workflows to enhance incidents response and investigation efforts.
  • Leverage AI platforms to assist with automation of SOC processes.
  • Conduct proactive hunts leveraging behavioral analytics and intelligence feeds to identify emerging threats.
  • Work closely with IT, network, and security engineering teams to contain incidents and strengthen defenses.
  • Maintain and enhance SOC playbooks, runbooks, and standard operating procedures (SOPs).
  • Assist with preparation of detailed incident reports, root cause analyses, and recommendations for preventive measures.
  • Train and guide L1 analysts, fostering a culture of continuous learning and operational excellence.
  • Assess and recommend new security technologies or security measures to enhance SOC capabilities.
  • Maintain endpoint security baselines aligned with CIS benchmarks.
  • Support integration and operations of a new primary EDR/SIEM platform.
  • Partner with IT operations to safely test and deploy endpoint security changes.
  • Act as a senior technical escalation point during security incidents.
  • Contribute to incident response playbooks and post-incident reviews.
  • Produce high-quality technical documentation, including: Security architecture diagrams SOPs and runbooks Policy rationale and audit artifacts Incident timelines
Technical Knowledge and Understanding:
  • Strong understanding of SIEM platforms, EDR tools, and network monitoring solutions; including the maintenance and tuning of security tools and alert logic, security settings, and IOC blocks.
  • Proven experience designing and implementing security automation workflows.
  • Strong SQL/KQL query capabilities.
  • Deep knowledge of attack lifecycle frameworks (MITRE ATT&CK, Cyber Kill Chain).
  • Proven ability to analyze network traffic, logs, and host-based artifacts.
  • Ability to work in a fast-paced 24x7 environment with rotational on-call coverage.
  • Excellent communication and documentation skills.
Experience:
  • (This is NOT a hybrid or remote role), onsite (Monday through Friday).
  • Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over work authorization sponsorship now or in the future for this position.
  • Bachelor's degree in Cybersecurity, Computer Science, IT, or equivalent practical experience.
  • 3+ years of experience in SOC operations, cybersecurity, or incident response.
  • Certifications such as GCIH, GCIA, CEH, CompTIA CySA+, or CISSP.
  • Experience with malware analysis or reverse engineering.
  • Experience with scripting (Python, PowerShell) for automation and SOC process improvement.
  • Familiarity with threat intelligence platforms and integration.
  • Experience in cloud security monitoring (AWS, Azure, GCP).

#LI-Onsite - At Core Specialty, you will receive a competitive salary and opportunities for professional development and advancement.

We offer medical, dental, vision, and life insurances; short and long-term disability; a Company-match of 100% of a 6% contribution 401(k) plan; an Employee Assistance Plan; Health Savings Account, Flexible Spending Account, Health Reimbursement Account, and a wellness program

Core Specialty offers a diversified range of property and casualty insurance products for small to mid-sized businesses.

From underwriting offices spanning the U.S., the Company focuses on niche markets, local distribution, and superior underwriting knowledge, offering traditional as well as innovative insurance solutions to meet the needs of its customers and brokers.

For further information about Core Specialty, please visit www.corespecialtyinsurance.com.

In compliance with the Transparency in Coverage rule, issued in 2020 by US Departments of Health, Human Services, Labor and Treasury our health plan's machine-readable files (MRFs) can be accessed via www.Cigna.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Operations Analyst - Onsite
Senior Security Operations Analyst - Onsite

Core specialty • Cincinnati (OH)

On-site
USD 105,000 - 145,000
Health insurance
Dental insurance
Vision insurance
+7
EUC Site Analyst - onsite end user support
EUC Site Analyst - onsite end user support

Kalepa • Cincinnati (OH)

On-site
USD 65,000 - 90,000
Medical insurance
Dental insurance
Vision insurance
+7
EUC Site Analyst - onsite end user support
EUC Site Analyst - onsite end user support

Core Specialty Insurance Services, Inc. • Cincinnati (OH)

On-site
USD 60,000 - 85,000
Competitive salary
Medical/dental/vision insurance
Company 401(k) with match
+2
Senior Talent Acquisition Partner
Senior Talent Acquisition Partner

Kalepa • Cincinnati (OH), Northern (KY)

Hybrid
USD 100,000 - 160,000
Medical, dental, vision, and life ins.
Short- and long-term disability
Company 401(k) match
+2
Senior Talent Acquisition Partner
Senior Talent Acquisition Partner

Core Specialty Insurance Services, Inc. • Cincinnati (OH)

Hybrid
USD 90,000 - 120,000
Medical Insurance
Dental Insurance
Vision Insurance
+8
Senior Talent Acquisition Partner
Senior Talent Acquisition Partner

Core Specialty • Cincinnati (OH), Northern (KY)

Hybrid
USD 110,000 - 140,000
Medical, dental, vision, and life ins.
Short and long-term disability
401(k) with company match
+3
Senior Data Engineer
Senior Data Engineer

Core Specialty Insurance Services, Inc. • Dallas (TX)

Hybrid
USD 130,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+4
Senior Data Engineer
Senior Data Engineer

Core Specialty Insurance Services, Inc. • Cincinnati (OH)

Hybrid
USD 140,000 - 180,000
Medical, dental, vision, and life ins
Disability insurance
401(k) with company match
+2
Site Reliability Engineer - Platform
Site Reliability Engineer - Platform

Core Specialty • Cincinnati (OH), Northern (KY)

Hybrid
USD 120,000 - 170,000
Medical, dental, vision insurance
Life insurance
Disability insurance
+7
Site Reliability Engineer - Platform
Site Reliability Engineer - Platform

Kalepa • Cincinnati (OH), Northern (KY)

Hybrid
USD 120,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+5