Senior SOC Analyst (Direct Hire EAD OKAY)

Confidential

United States

Hybrid

USD 120,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Confidential is seeking an experienced Senior Security Operations Center (SOC) Analyst to join our Cybersecurity team. As a Tier 3 / Lead analyst, you will be the primary escalation point for high‑severity incidents, drive threat hunting, and continuously improve incident response capabilities.

You will collaborate with security engineering, IT operations, and leadership to detect, analyze, and mitigate advanced cyber threats, ensuring the resilience of our infrastructure and data.

Qualifications

  • 5+ years in cybersecurity with 3+ years in a dedicated SOC/IR environment.
  • Experience investigating security events across cloud environments (AWS, Azure, GCP) and on-prem networks.
  • Strong proficiency with SIEM/EDR/XDR and security tooling.
  • Experience drafting executive-level incident reports and lessons learned.

Responsibilities

  • Serve as Tier 3 escalation point for high-severity incidents and complex threats.
  • Lead end-to-end incident response, including containment, eradication, and RCA.
  • Draft detailed Incident Reports and Lessons Learned after major events.
  • Proactively hunt threats across endpoints, network, and cloud using MITRE ATT&CK.
  • Integrate CTI into monitoring and create IoCs and detection rules.

Skills

SOC leadership
Incident response
Threat detection
Endpoint security
Threat hunting
Python scripting
PowerShell
Bash scripting

Tools

Splunk
Sentinel
CrowdStrike
SentinelOne
Palo Alto Cortex
Wireshark
PCAP

Job description

Here is a comprehensive job description for a Senior SOC Analyst role. You can easily adapt the requirements, tools, and responsibilities to fit your company’s specific tech stack and team structure.

Job Summary

We are seeking an experienced and proactive Senior Security Operations Center (SOC) Analyst to join our Cybersecurity team. As a Tier 3 / Lead analyst, you will serve as the primary escalation point for complex security incidents, drive threat-hunting initiatives, and continuously improve our incident response capabilities.

You will work closely with security engineering, IT operations, and leadership to detect, analyze, and mitigate advanced cyber threats, ensuring the resilience of our infrastructure and data.

Key Responsibilities
  • Serve as the senior escalation point (Tier 3) for high-severity security incidents and complex threats detected by Tier 1 and Tier 2 analysts.
  • Lead end-to-end incident response processes, including containment, eradication, and post-incident root-cause analysis (RCA).
  • Draft detailed, executive-level Incident Reports and Lessons Learned documentation following major events.
  • Proactively search across endpoints, network traffic, and cloud environments to identify undetected advanced persistent threats (APTs) using the MITRE ATT&CK framework.
  • Integrate Cyber Threat Intelligence (CTI) into security monitoring to generate actionable Indicators of Compromise (IoCs) and custom detection rules.
Detection Engineering & Automation
  • Tune and optimize SIEM, SOAR, EDR/XDR, and NDR platforms to reduce false positives and improve alert fidelity.
  • Develop automated playbooks and workflows to streamline routine SOC tasks and speed up Mean Time to Respond (MTTR).
  • Mentor and train junior SOC analysts, providing guidance on incident analysis, tool usage, and industry best practices.
  • Participate in or lead on-call rotations for critical security escalations.
  • Assist in conducting incident response tabletop exercises to validate procedures.
Required Qualifications & Experience
Experience
  • 5+ years of direct experience in cybersecurity, with at least 3+ years in a dedicated SOC or Incident Response environment.
  • Strong experience investigating security events across cloud environments (AWS, Azure, or GCP) and on-premises enterprise networks.
Technical Skills
  • SIEM & EDR/XDR: Advanced proficiency with enterprise tools (e.g., Splunk, Sentinel, CrowdStrike, SentinelOne, Palo Alto Cortex).
  • Forensics & Analysis: Deep understanding of network traffic analysis (Wireshark, PCAP), memory forensics, host-based artifacts, and log analysis (Windows Event Logs, Syslog).
  • Scripting & Automation: Ability to write scripts in Python, PowerShell, or Bash to automate repetitive task workflows or parse complex datasets.
  • Frameworks: Expertise in applying security frameworks like MITRE ATT&CK, NIST SP 800-61, and NIST CSF.
Certifications (Preferred)
  • GIAC: GCIH, GCFA, GNFA, or GCDA
  • CompTIA: CySA+ or CASP+
  • OffSec: OSCP or OSDA
  • Other: CISSP, Azure/AWS Security Specialty
Soft Skills & Attributes
  • Critical Thinking: Ability to dissect complex security scenarios under pressure and make sound decisions swiftly.
  • Communication: Excellent written and verbal skills to articulate technical findings to non-technical business leaders and stakeholders.
  • Collaborative Mindset: A strong sense of ownership combined with a passion for mentoring and uplifting teammates.
  • Work Location: [On-site / Hybrid / Fully Remote]
  • Schedule: Full-time (Include details about on-call rotation or shift structure)
  • Compensation: Competitive salary + bonus + benefits package (401k matching, healthcare, professional development/certification stipend).
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

Hybrid
USD 110,000 - 150,000
Senior Security Operations Analyst
Senior Security Operations Analyst

Prosegur Security USA, Inc • Lowell (MA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Senior SOC Analyst
Senior SOC Analyst

KeenLogic • Merrifield (VA)

On-site
USD 120,000 - 160,000
Health/dental/vision benefits
PTO
401k
+1
SOC Manager with BS Degree
SOC Manager with BS Degree

Acumenz Consulting • United States

Remote
USD 120,000 - 150,000
SOC Analyst I
SOC Analyst I

SOClogix, Inc. • Catonsville (MD)

On-site
USD 55,000 - 75,000
Health insurance
Dental insurance
Vision insurance
+6
Security Operations Center Analyst
Security Operations Center Analyst

Oxford Global Resources • Virginia (MN)

On-site
USD 120,000 - 180,000
Soc Tier 3 Analyst
Soc Tier 3 Analyst

Global Alliant Inc • Crownsville (MD)

Hybrid
USD 130,000 - 190,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Security Operations Center Analyst
Security Operations Center Analyst

Diligente Technologies • San Jose (CA)

On-site
USD 80,000 - 100,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000