Senior SOC Analyst

DeepSeas LLC

Northern (KY)

Hybrid

USD 120,000 - 180,000

Full time

28 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

DeepSeas LLC is seeking a Senior SOC Analyst (L2) to drive high‑severity investigations and mentor L1/L2 analysts. You will lead threat hunting, forensics, and detection engineering efforts to deliver stronger detections and playbooks.

The role requires deep technical aptitude, strong communication, and an ability to work with clients in a remote environment across the United States. You will influence incident response across multiple client environments and collaborate with threat intel and

Qualifications

  • 5+ years in security operations, incident response, or threat detection, with senior experience.
  • Proven lead on high-severity incidents from triage to recovery.
  • Hands-on proficiency with SIEM/EDR/XDR and SOAR platforms, including detection content.
  • Knowledge of MITRE ATT&CK and incident response lifecycle (NIST SP 800-61).
  • Experience with host/memory/network forensics and malware analysis.
  • Scripting in Python/PowerShell/Bash to automate tasks.
  • Mentor or lead junior analysts.
  • Excellent written and verbal communication; able to brief execs.

Responsibilities

  • Lead L1/L2 analysts on security incidents and mentor the team.
  • Coordinate during high-severity incidents with stakeholders.
  • Develop, test, and refine incident response playbooks and procedures.
  • Conduct advanced threat hunting to detect sophisticated adversaries.
  • Collaborate with threat intel and vulnerability teams to stay current.
  • Provide root-cause analysis and post-incident reviews.
  • Develop and tune detection rules; use MITRE ATT&CK to categorize TTPs.
  • Produce metrics/reports on IR activities and trends for leadership.
  • Automate IR processes with scripts and memory/forensics tooling.

Skills

SIEM
EDR/XDR
SOAR platforms
Threat hunting
Incident response
Python scripting
PowerShell
Bash
MITRE ATT&CK
NIST SP 800-61

Education

Bachelor's degree in Cybersecurity or related field
GCIH
GCFA
GREM
GNFA
CISSP

Tools

KQL
SPL
YARA
Ghidra
IDA Pro
Volatility

Job description

Senior SOC Analyst

Department: Threat Management: Strategic Services

Employment Type: Full Time

Location: Remote - United States

Description

*This position is contingent on contract award*

Who is DeepSeas

With 30 years of experience in cyber defense, DeepSeas is trusted by nearly 1,000 clients around the world, including Fortune 100 enterprises and mid-market organizations, higher education institutions, municipality and local governments, and federal agencies. Known for its programmatic approach to continuously transforming cyber defense programs, DeepSeas is recognized by Gartner as a top 40 provider of MDR and ranked as a top 5 MDR leader in the 2024 Frost Radar: Global Managed Detection and Response (MDR) Market. In addition to its industry‑leading MDR service, DeepSeas offers a full suite of advisory, compliance, and testing services to support clients on their cybersecurity transformation journeys, with an approach to cyber defense that prioritizes technical expertise, tradecraft, and continuous innovation to deliver unparalleled results.

Position Summary

We're looking for (5) Senior SOC Analyst (L2) to drive the quality of outcomes in DeepSeas' client‑facing detection and response.

You're a seasoned incident responder who leads high‑severity investigations, mentors L1 and L2 analysts, and turns findings from threat hunting, malware analysis, and forensics into stronger detections and playbooks. This role requires a blend of strategic thinking, deep technical aptitude, awareness of the evolving threat landscape, and strong operational execution.

Key Responsibilities
  • Leads and mentors a team of L1 and L2 incident responders in handling security incidents.
  • Coordinates with internal and external stakeholders during high‑severity incidents.
  • Develops, refines, and tests incident response playbooks and procedures.
  • Conducts advanced threat‑hunting activities to detect sophisticated adversaries.
  • Collaborates with threat intelligence and vulnerability management teams to stay current on emerging threats and vulnerabilities.
  • Provides expert guidance in root cause analysis and post‑incident reviews.
  • Develops and fine‑tunes detection rules to enhance threat detection capabilities.
  • Uses frameworks such as MITRE ATT&CK to understand and categorize threat actor TTPs.
  • Drives continuous improvement initiatives within the SOC.
  • Generates metrics and reports on incident response activities and trends for leadership.
  • Conducts regular briefings to leadership on security incidents and trends.
  • Develops and maintains scripts to automate and enhance incident response processes.
  • Conducts in‑depth malware analysis to determine malware samples' functionality, origin, and impact.
  • Collaborates with threat intelligence teams to correlate malware findings with known threat actor campaigns.
  • Provides recommendations to enhance detection and prevention capabilities based on malware analysis findings.
  • Leads digital forensics investigations, including memory forensics, to uncover evidence and artifacts related to security incidents.
  • Oversees network forensics activities to analyze network traffic logs and detect malicious activities or patterns.
  • Serves as a subject matter expert on incident response, providing guidance and advice to DeepSeas and client leadership.
Experience, Education, and Skills Required

Minimum Qualifications

  • 5+ years of experience in security operations, incident response, or threat detection, including time operating at a senior (L3) level or leading investigations; or an equivalent combination of education and experience.
  • Proven experience leading high‑severity incident response from triage through containment, eradication, and recovery.
  • Strong hands‑on proficiency with SIEM, EDR/XDR, and SOAR platforms, including writing and tuning detection content (e.g., KQL, SPL, Sigma, YARA).
  • Working knowledge of MITRE ATT&CK and the incident response lifecycle (e.g., NIST SP 800-61).
  • Experience with host, memory, and network forensics, as well as static and dynamic malware analysis.
  • Scripting proficiency in Python, PowerShell, or Bash to automate investigation and response tasks.
  • Experience mentoring or leading junior analysts.
  • Excellent written and verbal communication skills, with the ability to brief both technical teams and executive or client audiences.
  • This position is open only to U.S. citizens who currently reside within the United States.

Preferred Qualifications

  • Advanced certifications such as GCIH, GCFA, GREM, GNFA, OSCP, or CISSP.
  • Experience in an MDR or MSSP environment supporting multiple clients.
  • Familiarity with reverse engineering and memory forensics tools (e.g., Ghidra, IDA Pro, x64dbg, Volatility).
  • Experience building or maturing a threat‑hunting or detection engineering program.
  • Bachelor's degree in Cybersecurity, Computer Science, or a related field.
Why DeepSeas?

At Deep Seas, we like to say that heart rates go down, careers take off, and security programs mature. Our values provide the ultimate guide for our daily behavior and decisions. Without these values, we aren’t Deep Seas. They preserve the essence of our organization, reflect the personalities of our Deeps (how we affectionately refer to our teammates), and enable us to exceed expectations. Our values are:

  • We are client obsessed.
  • We stand in solidarity with our teammates.
  • We prioritize personal health and well‑being.
  • We believe in the power of diversity.
  • We solve hard problems at the speed of cyber.

Information security is everyone's responsibility:

  • Understanding and following DeepSeas’s information security policies and procedures.
  • Remaining vigilant and reporting any suspicious activity or possible weaknesses in DeepSeas’s information security.
  • Actively participating in DeepSeas’s efforts to maintain and improve information security.
  • DeepSeas considers this position is as Moderate Risk with a potential to view/access/download restricted/private client/internal data.
  • This information must be treated with sensitivity and in the most secure manner.
  • HR reserves the right to perform random background/drug screens to ensure the safety of client/DeepSeas data
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SOC Analyst DeepSeas · Full-time · Remote — 3 hours ago
Senior SOC Analyst DeepSeas · Full-time · Remote — 3 hours ago

Emploive • Northern (KY)

Hybrid
USD 110,000 - 150,000
Senior SOC Lead: Incident Response & Threat Hunting
Senior SOC Lead: Incident Response & Threat Hunting

Emploive • Northern (KY)

Hybrid
USD 110,000 - 150,000
Senior SOC Analyst
Senior SOC Analyst

KeenLogic • Merrifield (VA)

On-site
USD 120,000 - 160,000
Health/dental/vision benefits
PTO
401k
+1
Incident Response Engineer 2
Incident Response Engineer 2

Sophos • United States

Remote
USD 85,000 - 120,000
Remote-first
Flexible schedule
Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

On-site
USD 110,000 - 150,000
Senior SOC Analyst (Direct Hire EAD OKAY)
Senior SOC Analyst (Direct Hire EAD OKAY)

Confidential • United States

On-site
USD 120,000 - 180,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

On-site
USD 97,600 - 109,800
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Senior Security Analyst
Senior Security Analyst

Yardi • Santa Barbara (CA)

On-site
USD 97,600 - 109,800
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Senior Threat Analyst 2 (Romania)
Senior Threat Analyst 2 (Romania)

Sophos • United States

Remote
USD 120,000 - 170,000