Senior SOC Analyst

FlexTrade

Village of Great Neck (NY)

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid work schedule
Professional development budget
Comprehensive benefits

Job summary

FlexTrade Systems, a leading provider of multi-asset trading solutions, seeks a Senior SOC Analyst to own day-to-day detection, analysis, and response within our Security Operations Center. You will work across SIEM, EDR, and cloud platforms, collaborating with IT and engineering to harden defenses.

The role emphasizes hands-on execution, threat hunting, and purple team activities, with hybrid schedule (four days onsite, one remote day per week).

Qualifications

  • 5+ years in a SOC, security operations, or IR role.
  • Proficient with SIEMs such as Splunk, Microsoft Sentinel, or Sumo Logic.
  • Hands-on with EDRs like CrowdStrike Falcon or Defender.
  • Experience configuring conditional access policies (Entra).
  • Experience configuring DLP policies (Purview).
  • Strong understanding of MITRE ATT&CK and threat detection.

Responsibilities

  • Monitor and investigate security alerts across SIEM, EDR, NDR, and cloud platforms.
  • Lead end-to-end incident response including containment and recovery.
  • Develop and maintain incident response playbooks and runbooks.
  • Perform vulnerability assessments and prioritize remediation.
  • Map detections to MITRE ATT&CK and tune SIEM rules.
  • Conduct threat hunting and report findings to teams.
  • Collaborate with IT/engineering to reduce false positives.

Skills

SOC experience
SIEM (Splunk)
EDR (CrowdStrike)
Entra CA policies
DLP policies (Purview)
Threat detection
MITRE ATT&CK
Python scripting
Log analysis
Communication skills

Tools

Splunk
Microsoft Sentinel
Sumo Logic
CrowdStrike Falcon
Entra
Purview

Job description

FlexTrade Systems is a provider of customized multi-asset execution and order management trading solutions for buy- and sell-side financial institutions. Through deep client partnerships with some of the world's largest, most complex and demanding capital markets firms, we develop flexible tools, technology and innovation that deliver our clients a competitive edge. Our globally distributed engineering teams focus on adaptable technology and open architecture to develop highly sophisticated trading solutions that can automate and scale with your business strategies.

At FlexTrade, we hold our values close to heart, with pride and gratitude, as they guide us in everything that we do. We are dedicated to giving our clients a competitive edge, taking ownership of our responsibilities, being flexible to adapt to ever-changing environment and technology, bringing integrity to every interaction and we continue to improve, grow together and collaborate as one team. All of these while having Fun truly makes FlexTrade a wonderful place to work.

The Team:

We are looking for a technically sharp and driven Senior SOC Analyst to join our cybersecurity team. You will serve as a key individual contributor within the Security Operations Center, owning day-to-day detection, analysis, and response activities while contributing to vulnerability management and purple team exercises. This is a hands‑on, practitioner role — you will spend most of your time in the work, not managing it. You will collaborate closely with peers, IT, and engineering teams to identify and contain threats, reduce attack surface, and continuously sharpen our defensive capabilities. The position is primarily on‑site (4 days per week at our offices) with one remote day per week.

Responsibilities:
Security Monitoring & Incident Response
  • Monitor, triage, and investigate security alerts across SIEM, EDR, NDR, and cloud platforms, escalating to the SOC Lead as appropriate.
  • Respond to security incidents end‑to‑end: initial triage, containment, eradication, recovery, and post‑incident documentation.
  • Execute and help maintain incident response playbooks and runbooks, flagging gaps and recommending improvements.
  • Conduct root cause analysis following incidents and contribute findings to post‑incident reviews.
  • Produce clear, accurate incident reports suitable for both technical and non‑technical audiences.
  • Participate in on‑call rotation and be available to respond to high‑severity incidents outside of business hours when required.
Vulnerability Management
  • Perform vulnerability scans and assessments using tools such as Tenable, Qualys, or Rapid7 on a scheduled and ad‑hoc basis.
  • Analyze and prioritize vulnerabilities using CVSS scores, threat intelligence, and asset criticality to guide remediation efforts.
  • Track and follow up on remediation progress with IT and engineering teams, escalating stalled items as needed.
  • Contribute to vulnerability reporting, capturing trends, patch compliance rates, and risk reduction metrics.
  • Stay current on newly disclosed CVEs and exploit trends, advising on risk‑based prioritization.
Purple Teaming & Threat Detection
  • Participate in purple team exercises alongside red team operators to validate detection and response capabilities.
  • Map adversary techniques to the MITRE ATT&CK framework and use exercise findings to identify detection gaps.
  • Write and tune SIEM detection rules, correlation queries, and alerts based on adversary TTPs and purple team outcomes.
  • Conduct threat hunting exercises using hypothesis‑driven and ATT&CK‑aligned methodologies to surface undetected threats.
  • Track emerging threat actor activity and incorporate relevant TTPs into detection logic and hunting campaigns.
Security Operations & Collaboration
  • Analyze logs from a variety of sources including endpoints, firewalls, proxies, cloud platforms, and identity systems.
  • Enrich investigations with threat intelligence, enriching indicators of compromise (IOCs) and correlating activity across data sources.
  • Collaborate with IT and engineering to support security control tuning, reducing false positives and improving signal quality.
  • Maintain accurate and up‑to‑date SOC documentation including runbooks, knowledge base articles, and escalation procedures.
  • Support compliance activities (e.g., SOC 2, ISO 27001, NIST CSF) by providing evidence and participating in audits as required.
  • Mentor junior analysts by sharing knowledge and providing guidance on investigations and tool usage, without formal management responsibility.
Required Skills and Experience:
  • 5+ years of hands‑on experience in a SOC, security operations, or incident response role.
  • Strong proficiency with SIEM platforms such as Splunk, Microsoft Sentinel, or Sumo Logic.
  • Hands‑on experience with EDR solutions such as CrowdStrike Falcon, or Microsoft Defender.
  • Hands‑on experience configuring conditional access policies in Entra or another platform.
  • Hands‑on experience configuring DLP policies on Purview or another platform.
  • Demonstrated experience triaging and responding to a significant volume of security alerts and incidents.
  • Working knowledge of vulnerability management tools and processes, including scanning, prioritization, and remediation tracking.
  • Solid understanding of network protocols and fundamentals: TCP/IP, DNS, HTTP/S, firewalls, and proxies.
  • Experience analyzing logs across endpoints, networks, cloud environments, and SaaS platforms.
  • Familiarity with the MITRE ATT&CK framework and applying it to investigations and detection engineering.
  • Scripting experience for investigation and automation tasks (Python, PowerShell, or Bash).
  • Strong analytical and problem‑solving skills with high attention to detail.
  • Excellent written and verbal communication skills; able to convey technical findings clearly to varied audiences.
Preferred Qualifications
  • Experience participating in purple team, red team, or adversary emulation exercises.
  • Background in threat hunting using hypothesis‑driven or behavior‑based methodologies.
  • Exposure to SOAR platforms and security automation or workflow development.
  • Experience with cloud security telemetry and threat models across AWS, Azure, or GCP.
  • Familiarity with threat intelligence platforms or workflows (e.g., MISP, Recorded Future, OpenCTI).
  • Knowledge of digital forensics tools and techniques (KAPE, Volatility, Velociraptor, etc.).
Certifications
  • Required: CISSP – Certified Information Systems Security Professional
  • Preferred: GIAC GCIH – GIAC Certified Incident Handler
  • Preferred: GIAC GCIA – Intrusion Analyst
  • Preferred: CEH – Certified Ethical Hacker
  • Preferred: CompTIA CySA+ or Security+
  • Preferred: OSCP, GPEN, or similar offensive/detection‑focused certification
  • Preferred: Cloud security certifications: Microsoft SC‑200, AWS Security Specialty, or equivalent
Why Join Us
  • A hands‑on practitioner role with real ownership over detection, response, and vulnerability operations.
  • Hybrid schedule with consistent in‑person collaboration and one remote day per week.
  • Dedicated budget for professional development, training, and certification support.
  • Competitive compensation and comprehensive benefits package.

FlexTrade Systems, Inc. does not accept unsolicited resumes from search firm recruiters. Fees will not be paid in the event a candidate submitted by a recruiter without an authorized agreement for a particular SOW (Statement of Work) in place is hired: such resumes are deemed the sole property of FlexTrade Systems, Inc.

FlexTrade Systems, Inc. is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or any other status protected by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SOC Analyst
Senior SOC Analyst

FlexTrade • Milwaukee (WI)

On-site
USD 110,000 - 140,000
Senior SOC Analyst - Threat Detection & Response (Hybrid)
Senior SOC Analyst - Threat Detection & Response (Hybrid)

FlexTrade • Village of Great Neck (NY)

Hybrid
USD 120,000 - 180,000
Hybrid work schedule
Professional development budget
Comprehensive benefits
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Senior SOC Analyst | Hybrid, Hands-On Incident Response
Senior SOC Analyst | Hybrid, Hands-On Incident Response

FlexTrade • Milwaukee (WI)

Hybrid
USD 110,000 - 140,000
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

On-site
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

On-site
USD 110,000 - 150,000
Cyber Security Analyst
Cyber Security Analyst

Clinisoltech • Huntsville (AL)

Hybrid
USD 80,000 - 90,000
Engineer, Security
Engineer, Security

11:11 Systems • United States

On-site
USD 120,000 - 160,000
Security Operations Center (SOC) Analyst / Engineer
Security Operations Center (SOC) Analyst / Engineer

Zoho • United States

On-site
USD 110,000 - 160,000
Senior SOC Analyst (Direct Hire EAD OKAY)
Senior SOC Analyst (Direct Hire EAD OKAY)

Confidential • United States

On-site
USD 120,000 - 180,000