Enable job alerts via email!

SOC Level 3 Analyst & Incident Response Lead

BETSOL

Denver (CO)

Hybrid

USD 135,000 - 185,000

Full time

7 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

BETSOL is looking for a highly skilled Tier 3 SOC Analyst to lead critical incident response activities in a hybrid position. This role focuses on managing major security incidents, conducting thorough forensic investigations, and guiding junior analysts while enhancing the organization’s overall incident response capabilities. Candidates should possess extensive experience in a Security Operations Center, be adept at leading incident responses, and have strong forensic analysis skills. Competitive salary and comprehensive benefits package offered.

Benefits

Comprehensive health insurance
Competitive salaries
401K plan
Volunteer programs
Scholarship opportunities
Fitness center
Café and recreational facilities

Qualifications

  • 5+ years of experience in a Security Operations Center or Incident Response role.
  • Strong forensic analysis skills and hands-on experience in vulnerability management.
  • Advanced proficiency in SIEM platforms and cloud security tools.

Responsibilities

  • Act as the final escalation point for complex security alerts.
  • Lead end-to-end incident response lifecycle.
  • Educate and mentor Tier 1 and Tier 2 SOC analysts.

Skills

Forensic analysis
Digital investigations
Threat intelligence correlation
Scripting
Cloud security
Leadership
Communication skills

Education

5+ years in Security Operations/Incident Response
GIAC Certified Forensic Analyst (GCFA) or GIAC Certified Incident Handler (GCIH)
CISSP, OSCP, GCIA, or equivalent

Tools

Azure Sentinel
Defender for Endpoint
Forensic toolsets

Job description

Get AI-powered advice on this job and more exclusive features.

Company Description

BETSOL is a cloud-first digital transformation and data management company offering products and IT services to enterprises in over 40 countries. BETSOL team holds several engineering patents, is recognized with industry awards, and BETSOL maintains a net promoter score that is 2x the industry average.

Company Description

BETSOL is a cloud-first digital transformation and data management company offering products and IT services to enterprises in over 40 countries. BETSOL team holds several engineering patents, is recognized with industry awards, and BETSOL maintains a net promoter score that is 2x the industry average.

BETSOL’s open source backup and recovery product line, Zmanda (Zmanda.com), delivers up to 50% savings in total cost of ownership (TCO) and best-in-class performance.

BETSOL Global IT Services (BETSOL.com) builds and supports end-to-end enterprise solutions, reducing time-to-market for its customers.

BETSOL offices are set against the vibrant backdrops of Broomfield, Colorado and Bangalore, India.

We take pride in being an employee-centric organization, offering comprehensive health insurance, competitive salaries, 401K, volunteer programs, and scholarship opportunities. Office amenities include a fitness center, cafe, and recreational facilities.

Job Description

We are seeking a highly skilled and experienced Tier 3 SOC Analyst who will also function as the Incident Response Lead. This is a hybrid technical-leadership position focused on managing critical security events, conducting forensic investigations, and continuously enhancing the incident response program. As a senior member of the SOC, you will be the escalation point for complex and high-impact security incidents, support forensic analysis, lead root cause investigations, and contribute to detection engineering efforts.

Qualifications

Key Responsibilities

Tier 3 SOC Analyst Duties

  • Act as the final escalation point for complex security alerts and incidents identified through Azure Sentinel and other security monitoring tools.
  • Conduct in-depth digital forensic investigations across endpoints, networks, and cloud infrastructure (Azure, M365, Microsoft Dynamics, etc.).
  • Perform malware analysis, reverse engineering, and memory/disk analysis to support incident triage and response.
  • Provide expert-level guidance to Tier 1 and Tier 2 SOC analysts; coach and mentor to raise team capabilities.
  • Correlate threat intelligence with incident data to understand adversary behavior and campaign objectives.
  • Collaborate with SIEM engineers to tune, develop, and optimize detection use cases, particularly for emerging threats.
  • Maintain documentation of playbooks, threat scenarios, and incident patterns.

Incident Response Lead Duties

  • Lead and coordinate the end-to-end incident response lifecycle, from detection through containment, eradication, and recovery.
  • Own and maintain IR documentation including incident tracking, timelines, RCA, and after-action reports.
  • Liaise with the CSIRT team and relevant business stakeholders during critical incidents.
  • Lead post-incident reviews and facilitate lessons learned workshops, contributing to policy, procedure, and control improvements.
  • Drive continuous process improvement across SOC and IR operations, ensuring integration with change and problem management.
  • Ensure executive-level incident reporting and briefings are prepared and delivered as needed.

Required

  • 5+ years of experience in a Security Operations Center or Incident Response role.
  • Proven experience leading major incident response efforts (e.g., ransomware, APT, data breaches).
  • Strong forensic analysis skills (disk, memory, log, and network forensics).
  • Advanced proficiency in SIEM platforms (preferably Microsoft Sentinel), EDR tools (Defender for Endpoint), and forensic toolsets.
  • Hands-on experience with vulnerability management and cloud security tools such as Wiz, Tenable, or Qualys.
  • Understanding of attacker TTPs mapped to MITRE ATT&CK and threat hunting methodologies.
  • Hands-on experience with scripting and automation (e.g., PowerShell, Python) to streamline investigations and response.
  • Knowledge of security controls, network protocols, operating systems, and cloud environments (Azure).
  • Strong communication skills and ability to present technical findings to non-technical stakeholders.

Additional Information

Desirable Certifications

  • GIAC Certified Forensic Analyst (GCFA) or GIAC Certified Incident Handler (GCIH)
  • CISSP, oscp, GCIA, or equivalent
  • Microsoft certifications: SC-200, SC-300, AZ-500

Key Competencies

  • Calm and decisive under pressure
  • Analytical and detail-oriented
  • Strong leadership and collaboration skills
  • Proactive approach to process optimization and threat mitigation
  • Passion for continuous learning and capability development

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Industries
    IT Services and IT Consulting

Referrals increase your chances of interviewing at BETSOL by 2x

Get notified about new Security Operations Center Analyst jobs in Denver, CO.

Sr Cybersecurity Specialist, third-party/vendor risk management
Staff Security Operations Engineer, Incident Response Lead
Staff Security Operations Engineer, Incident Response Lead
SMB Account Executive, Cyber Security & Data Privacy - Denver, CO
Staff Security Operations Engineer (Observability & Automation)
Senior Product Security Engineer, Security Platform

Denver, CO $135,000.00-$185,000.00 2 weeks ago

Staff Security Operations Engineer (Observability & Automation)

Denver, CO $117,750.00-$232,000.00 2 weeks ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

IT Systems Engineer III

Ophelia

null null

Remote

Remote

USD 140,000 - 150,000

Full time

Today
Be an early applicant

Information Security Engineer

Maxar Technologies

null null

Remote

Remote

USD 98,000 - 189,000

Full time

29 days ago

Sr. Technical Writer

Rocket Lab

Denver null

On-site

On-site

USD 125,000 - 170,000

Full time

15 days ago

Senior Network Engineer

ZipRecruiter

Marlborough null

Remote

Remote

USD 120,000 - 140,000

Full time

30 days ago

Senior SailPoint Developer (Remote)

Claritev

McLean null

Remote

Remote

USD 115,000 - 155,000

Full time

30+ days ago

Information Security Engineer

Davita Inc.

Northglenn null

On-site

On-site

USD 98,000 - 164,000

Full time

22 days ago