Sr. Security Analyst - Security Operations Center (SOC)

LEN Lennar Corporation

Irving (TX)

On-site

USD 140,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) plan
Paid parental leave
Adoption assistance
Vacation and holidays

Job summary

Lennar is seeking a Senior SOC Analyst to lead advanced incident response efforts, coordinate with our MDR partner, and drive threat detection improvements across SIEM/EDR/cloud platforms. You will develop playbooks, perform threat hunts, and automate SOC processes to reduce response times.

Ideal candidates have 5–7 years in cybersecurity ops, strong certification background (Security+, CISSP, GCIA), and hands-on experience with Microsoft Sentinel and XDR tools.

Qualifications

  • 5–7 years in a cybersecurity operations role with Tier 2/3 experience.
  • Proven incident response triage, investigation and remediation.
  • Experience with SIEM/SOAR tools, including Microsoft Defender XDR and Cortex XDR.
  • Strong ability to author and tune detection content and produce actionable remediation.

Responsibilities

  • Lead investigations of complex high-severity security incidents from detection to containment.
  • Coordinate with internal teams and MDR partner; act as Tier 3 escalation point.
  • Develop and maintain incident response playbooks and runbooks.
  • Conduct threat hunting across endpoint, identity, network, and cloud telemetry.
  • Automate repetitive SOC processes using SOAR, Logic Apps, and playbooks.
  • Monitor logs across SIEM/EDR/cloud platforms and correlate data for threats.
  • Mentor Tier 1/2 analysts and generate executive-level SOC reports.

Skills

Incident response
Threat management
MDR partner coordination
SOAR automation
Threat hunting
KQL
Python
PowerShell
Microsoft Sentinel
XDR (Palo Alto Cortex/XDR)
ServiceNow
MITRE ATT&CK
Mentorship
Reporting

Education

CompTIA Security+
CISSP
GCIA

Tools

Torq
Microsoft Sentinel Automation Rules
Logic Apps
Azure AD/AWS logs

Job description

We are Lennar

We are Lennar Lennar is one of the nation's leading homebuilders, dedicated to making an impact and creating an extraordinary experience for their Homeowners, Communities, and Associates by building quality homes and providing exceptional customer service, giving back to the communities in which we work and live in, and fostering a culture of opportunity and growth for our Associates throughout their career. Lennar has been recognized as a Fortune 500 company and consistently ranked among the top homebuilders in the United States. Join a Company that Empowers You to Build Your Future We are seeking a highly skilled and experienced Senior SOC Analyst to join our cybersecurity team. This role is critical in leading advanced incident response efforts, managing escalations from cross functional teams and working closely with our MDR partner to ensure rapid detection, containment, and remediation of security threats. The ideal candidate will have deep technical expertise, strong analytical skills, and a proactive mindset toward incident response and continuous improvement. A career built on defending digital infrastructure. A career focused on proactive threat detection and response. A career that protects critical assets and enables secure business operations.

Your Responsibilities on the Team

Incident Response & Threat Management Lead investigations of complex, high severity security incidents from detection through containment, remediation, and recovery, coordinating across internal teams and the MDR partner. Act as the primary escalation point for Tier 3 alerts and incidents and perform root cause analysis with actionable remediation plans. Serve as the primary liaison to the MDR provider: validate and triage MDR alerts, ensure alignment on response protocols and escalation procedures, and provide tuning recommendations to improve detection fidelity. Develop and maintain incident response playbooks, runbooks, and workflows. Analyze threat actor tactics, techniques, and procedures (TTPs) and translate findings into improved defenses and detection content. Threat Hunting Conduct proactive, hypothesis-driven threat hunts across endpoint, identity, network, and cloud telemetry, leveraging threat intelligence and the MITRE ATT&CK framework to surface threats that evade automated detection. Operationalize hunt findings into durable detection logic and response procedures. Automation & Process Improvement Identify recurring, manual, or manual heavy SOC processes and design automation to reduce analyst effort and accelerate response. Build, test, and maintain automated playbooks and response workflows in a SOAR platform (e.g., Torq, Microsoft Sentinel Automation Rules and Logic Apps) for enrichment, triage, containment, and case management. Develop, tune, and operationalize detection and correlation rules through automated validation and deployment. Measure the impact of automation against SOC performance metrics (MTTD, MTTR, alert volume, false-positive rate) and iterate based on results. Partner with Detection Engineering and Security Engineering to integrate tooling, close telemetry gaps, and standardize repeatable response. Security Monitoring & Analysis Monitor and analyze logs and alerts across SIEM, EDR, identity, and cloud platforms. Correlate data across multiple sources to identify patterns, anomalies, and emerging threats. Maintain situational awareness of the external threat landscape and internal security posture. Mentorship & Reporting Mentor Tier 1 and Tier 2 analysts, lead knowledge-sharing, and uplevel team investigative tradecraft and tooling proficiency. Document incident timelines, findings, and lessons learned. Track, analyze, and drive improvement of core SOC performance metrics (MTTD, MTTR, detection coverage, false-positive rate), and use them to prioritize tuning and automation efforts. Generate executive-level and technical reports on SOC performance and incidents, and support compliance and audit efforts through accurate record-keeping and evidence handling.

Requirements

Minimum 5-7 years of experience in a cybersecurity operations role, with at least 3 years in a Tier 2/Tier 3 SOC or escalation capacity. CompTIA Security+ or equivalent. Proven experience leading incident response triage, investigation, and remediation, including working directly with MDR partners. In-depth knowledge of security tools and technologies, including SIEM/SOAR platforms (e.g., Microsoft Sentinel), endpoint detection and response solutions (e.g., Microsoft Defender XDR, Palo Alto Cortex XDR), and ticketing systems (e.g., ServiceNow). Demonstrated ability to author and tune detection content (e.g., KQL in Sentinel/Defender) and operationalize it into production. Experience analyzing cloud security telemetry (e.g., Azure/Entra sign-in logs, AWS CloudTrail). Hands‑on experience building or maintaining automated playbooks and response workflows in a SOAR platform. Strong understanding of network security concepts, operating systems, and malware analysis techniques. Familiarity with the MITRE ATT&CK framework and threat intelligence platforms. Excellent analytical, problem‑solving, and communication skills, with the ability to work under pressure and manage multiple priorities. Preferred Certifications such as CISSP, GCIA, GCIH, GCFA, CySA+, eJPT/PJPT, CEH, SC-200. Scripting and automation skills (Python, PowerShell) for tooling, enrichment, and analysis. Experience supporting an EDR platform migration (e.g., Cortex XDR to Microsoft Defender XDR). Experience with or strong interest in AI‑assisted triage and agentic SOC tooling to augment analyst workflows. Broader cloud security experience across AWS, Azure, and OCI. Experience with Microsoft Sentinel, Proofpoint, and Palo Alto Cortex XDR.

Work Environment

Mandatory 4-days onsite; 1‑day remote. On‑call rotation may be required for critical incident response. Collaborative team environment with opportunities for growth and specialization.

This description outlines the basic responsibilities and requirements for the position noted. This is not a comprehensive listing of all job duties of the Associates. Duties, responsibilities and activities may change at any time with or without notice. Lennar is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws.

Life at Lennar

At Lennar, we are committed to fostering a supportive and enriching environment for our Associates, offering a comprehensive array of benefits designed to enhance their well‑being and professional growth. Our Associates have access to robust health insurance plans, including Medical, Dental, and Vision coverage, ensuring their health needs are well taken care of. Our 401(k) Retirement Plan, complete with a $1 for $1 Company Match up to 5%, helps secure their financial future, while Paid Parental Leave and an Associate Assistance Plan provide essential support during life's critical moments. To further support our Associates, we provide an Education Assistance Program and up to $30,000 in Adoption Assistance, underscoring our commitment to their diverse needs and aspirations. From the moment of hire, they can enjoy up to three weeks of vacation annually, alongside generous Holiday, Sick Leave, and Personal Day policies. Additionally, we offer a New Hire Referral Bonus Program, significant Home Purchase Discounts, and unique opportunities such as the Everyone’s Included Day. At Lennar, we believe in investing in our Associates, empowering them to thrive both personally and professionally. Lennar Associates will have access to these benefits as outlined by Lennar’s policies and applicable plan terms. Visit Lennartotalrewards.com to view our suite of benefits.

We’re Always Looking Ahead

Want to work in an innovative environment that empowers you to explore your passions? At Lennar, we promote asking questions and working together to solve complex problems. It’s how we’ve become a leader in the homebuilding industry and why our Associates love working here. If you’re interested in helping people find their future homes and, in doing so, build a better future for themselves, then Lennar is the place for you.

Work Where Everyone’s Included

We’re committed to building and sustaining an inclusive culture where everyone has a seat at the table, and we’re all on a first-name basis. This inclusive culture influences our hiring practices, the communities we serve and how we build better career experiences for all our Associates. It’s why we created our Everyone’s Included Advisory Council, and we’d love for you to be a part of our shared journey.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Analyst II
Security Analyst II

LEN Lennar Corporation • Miami (FL)

On-site
USD 100,000 - 140,000
Health insurance
401(k) plan
Adoption assistance
+1
Sr. Security Analyst - Security Operations Center (SOC)
Sr. Security Analyst - Security Operations Center (SOC)

Lennar USA • Miami (FL), Northern (KY)

Hybrid
USD 120,000 - 160,000
Home Purchase Discounts
Education Assistance
Paid Parental Leave
Sr. Security Analyst - Security Operations Center (SOC)
Sr. Security Analyst - Security Operations Center (SOC)

Lennar USA • Irving (TX)

Hybrid
USD 120,000 - 180,000
Health insurance
401k plan
Paid time off
+4
LTG - Security Engineer II
LTG - Security Engineer II

LTL Lennar Homes of TX L&C LTD • Irving (TX)

On-site
USD 90,000 - 120,000
Health insurance
401(k) retirement plan
Paid parental leave
+5
LTG - Systems Analyst I, IT Special Operations
LTG - Systems Analyst I, IT Special Operations

LAM Lennar Associates Mgmt LLC • Irvine (CA)

Remote
USD 47,000 - 63,000
Security Analyst II
Security Analyst II

Lennar USA • Miami (FL)

On-site
USD 90,000 - 120,000
Health insurance
401(k) retirement plan
Paid parental leave
+3
Sr Manager, Governance, Risk and Compliance
Sr Manager, Governance, Risk and Compliance

LAM Lennar Associates Mgmt LLC • Irving (TX)

On-site
USD 150,000 - 210,000
Health insurance
401(k) matching
Paid parental leave
+3
LTG - Security Engineer II
LTG - Security Engineer II

Lennar • Irving (TX)

On-site
USD 90,000 - 130,000
Health insurance
401(k) with company match
Paid parental leave
+2
Lead Software Engineer
Lead Software Engineer

LAM Lennar Associates Mgmt LLC • Town of Florida (NY)

On-site
USD 140,000 - 180,000
Sr Software Engineer
Sr Software Engineer

LAM Lennar Associates Mgmt LLC • Irving (TX)

On-site
USD 120,000 - 170,000
Health insurance
401(k) retirement plan with company 5%
Paid parental leave
+1