Senior SOC Lead: Threat Hunting & IR (Remote)

SPS Commerce

Minneapolis (MN)

Hybrid

USD 108,200 - 140,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

SPS Commerce is seeking a senior member of the Cyber Defense team to lead detection and response, guide the SOC, and manage escalations across SIEM, EDR, identity, and cloud telemetry. You will shepherd investigations, drive incident response, and proactively hunt threats to keep the SOC well‑prioritized and effective.

The ideal candidate has 5+ years in security operations with DFIR and SOC experience, strong communication skills, and a track record of improving detections and runbooks.

Qualifications

  • 5+ years in security operations, incident response, or threat detection with senior‑level DFIR/SOC depth.
  • Hands‑on investigation with a SIEM and an EDR platform; ability to pivot across identity, cloud, and network logs.
  • Solid evidence handling and forensic fundamentals for disk, memory, and log artifacts.
  • Familiarity with adversarial behavior and MITRE ATT&CK.
  • Know‑how of exposure management workflows: triage, prioritization, remediation tracking.
  • Clear written and verbal communication; able to brief engineers and executives effectively.
  • Internal SPS candidates: SOC/IR/engineering experience with at least 1 year at SPS.
  • Key Skills: DFIR, SIEM/EDR, threat hunting, MITRE ATT&CK, cloud monitoring, cross‑team comms, executive briefing.

Responsibilities

  • Lead alert triage and investigation across SIEM/EDR and cloud, correlating data from multiple sources to determine escalation needs.
  • Run incident response for high‑severity incidents: scoping, containment, stakeholder coordination, thorough documentation.
  • Hunt for threats using current intelligence and surface coverage gaps before incidents occur.
  • Incorporate AI and automation to accelerate investigations, summaries, and documentation; partner with engineering to operationalize.
  • Collaborate with exposure management, security engineering, and cloud security on investigations and detections.
  • Improve detections, runbooks, and tooling; provide coaching to analysts and feed enhancements to engineering.
  • Develop the SOC: review determinations and escalation quality; participate in on‑call rotation.
  • Perform other duties as assigned.

Skills

Digital forensics and incident
SIEM/EDR investigation
Threat hunting
MITRE ATT&CK
Cloud security monitoring
Cross-team communication
Executive briefing

Tools

CrowdStrike
SOAR platforms
NG-SIEM
AWS
Azure
GCP
EKS

Job description

SPS Commerce is seeking a senior member of the Cyber Defense team to lead detection and response, guide the SOC, and manage escalations across SIEM, EDR, identity, and cloud telemetry. You will shepherd investigations, drive incident response, and proactively hunt threats to keep the SOC well‑prioritized and effective.

The ideal candidate has 5+ years in security operations with DFIR and SOC experience, strong communication skills, and a track record of improving detections and runbooks.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst - Lead SOC & Threat Hunting Remote
Senior Security Analyst - Lead SOC & Threat Hunting Remote

SPS Commerce Inc • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000
Senior SOC Analyst: Lead Incident Response & Threat Hunting
Senior SOC Analyst: Lead Incident Response & Threat Hunting

Confidential • Houston (TX)

Hybrid
USD 110,000 - 150,000
Senior SOC Lead: Threat Hunting & Incident Response
Senior SOC Lead: Threat Hunting & Incident Response

Swift Software • California (MO)

On-site
USD 121,000 - 226,000
401(k) matching
Bonus opportunities
Medical/dental/vision
Senior SOC Analyst - Lead Incident Response & Threat Hunting
Senior SOC Analyst - Lead Incident Response & Threat Hunting

Confidential • United States

Hybrid
USD 120,000 - 180,000
Senior SOC & Incident Response Lead (Hybrid Remote)
Senior SOC & Incident Response Lead (Hybrid Remote)

Layer8security • Northern (KY)

Hybrid
USD 120,000 - 190,000
Medical insurance
Life insurance
Unlimited vacation
+2
Senior SOC Engineer - Detection, Threat Hunting & SIEM
Senior SOC Engineer - Detection, Threat Hunting & SIEM

IT Data Consulting, LLC • Reston (VA)

On-site
Senior SOC Analyst: Threat Hunting & Incident Response
Senior SOC Analyst: Threat Hunting & Incident Response

Logicalis GmbH • Beachwood (OH)

On-site
USD 78,000 - 100,000
Senior Security Operations Center (SOC) Engineer
Senior Security Operations Center (SOC) Engineer

IT Data Consulting, LLC • Reston (VA)

On-site
USD 110,000 - 140,000
Senior SOC Analyst - Threat Detection & Response (Hybrid)
Senior SOC Analyst - Threat Detection & Response (Hybrid)

FlexTrade • Village of Great Neck (NY)

Hybrid
USD 120,000 - 180,000
Hybrid work schedule
Professional development budget
Comprehensive benefits
Senior SOC Lead: Threat Hunting & Incident Response
Senior SOC Lead: Threat Hunting & Incident Response

Invictus International Consulting, LLC • Colorado Springs (CO)

On-site
USD 200,000 - 230,000