Sr. Security Analyst - Security Operations Center (SOC)

Lennar

Miami (FL)

Hybrid

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401(k) with company match
Education Assistance Program
Paid parental leave
Home-purchase discounts

Job summary

Lennar is seeking a Senior SOC Analyst in Miami, Florida, to lead incident response efforts, manage escalations, and work with security partners to detect and remediate threats effectively.

The role requires 5-7 years of cybersecurity experience with expertise in incident triage and response. Comprehensive benefits include robust health plans, 401(k) matching, and generous vacation policies.

Qualifications

  • 5-7 years in a cybersecurity operations role, with 3 years in Tier 2/Tier 3 SOC.
  • Hands-on experience with automated playbooks and response workflows.
  • Strong understanding of network security concepts.

Responsibilities

  • Lead investigations of high severity security incidents with a focus on rapid response.
  • Mentor junior analysts and enhance team capabilities.
  • Document incidents and generate detailed performance reports.

Skills

Cybersecurity operations experience
Incident response and triage
Security tools knowledge
Analytical skills

Education

CompTIA Security+ or equivalent certification

Tools

SIEM/SOAR platforms
Endpoint detection and response solutions
Ticketing systems

Job description

Senior SOC Analyst

Lennar is a leading homebuilder dedicated to building quality homes and providing exceptional customer service.

The Senior SOC Analyst plays a critical role in leading advanced incident response efforts, managing escalations, and working closely with our MDR partner to ensure rapid detection, containment, and remediation of security threats.

Responsibilities
Incident Response & Threat Management
  • Lead investigations of complex, high severity security incidents from detection through containment, remediation, and recovery, coordinating across internal teams and the MDR partner.
  • Act as the primary escalation point for Tier 3 alerts and incidents and perform root cause analysis with actionable remediation plans.
  • Serve as the primary liaison to the MDR provider: validate and triage MDR alerts, ensure alignment on response protocols and escalation procedures, and provide tuning recommendations to improve detection fidelity.
  • Develop and maintain incident response playbooks, runbooks, and workflows.
  • Analyze threat actor tactics, techniques, and procedures (TTPs) and translate findings into improved defenses and detection content.
Threat Hunting
  • Conduct proactive, hypothesis-driven threat hunts across endpoint, identity, network, and cloud telemetry, leveraging threat intelligence and the MITRE ATT&CK framework to surface threats that evade automated detection.
  • Operationalize hunt findings into durable detection logic and response procedures.
Automation & Process Improvement
  • Identify recurring, manual, or heavily manual SOC processes and design automation to reduce analyst effort and accelerate response.
  • Build, test, and maintain automated playbooks and response workflows in a SOAR platform (e.g., Torq, Microsoft Sentinel Automation Rules, Logic Apps) for enrichment, triage, containment, and case management.
  • Develop, tune, and operationalize detection and correlation rules through automated validation and deployment.
  • Measure the impact of automation against SOC performance metrics (MTTD, MTTR, alert volume, false-positive rate) and iterate based on results.
  • Partner with Detection Engineering and Security Engineering to integrate tooling, close telemetry gaps, and standardize repeatable response.
Security Monitoring & Analysis
  • Monitor and analyze logs and alerts across SIEM, EDR, identity, and cloud platforms.
  • Correlate data across multiple sources to identify patterns, anomalies, and emerging threats.
  • Maintain situational awareness of the external threat landscape and internal security posture.
Mentorship & Reporting
  • Mentor Tier 1 and Tier 2 analysts, lead knowledge-sharing, and uplevel team investigative tradecraft and tooling proficiency.
  • Document incident timelines, findings, and lessons learned.
  • Track, analyze, and drive improvement of core SOC performance metrics (MTTD, MTTR, detection coverage, false-positive rate), and use them to prioritize tuning and automation efforts.
  • Generate executive-level and technical reports on SOC performance and incidents, supporting compliance and audit efforts through accurate record-keeping and evidence handling.
Requirements
  • Minimum 5-7 years of experience in a cybersecurity operations role, with at least 3 years in a Tier 2/Tier 3 SOC or escalation capacity.
  • CompTIA Security+ or equivalent certification.
  • Proven experience leading incident response triage, investigation, and remediation, including working directly with MDR partners.
  • In-depth knowledge of security tools and technologies, including SIEM/SOAR platforms (e.g., Microsoft Sentinel), endpoint detection and response solutions (e.g., Microsoft Defender XDR, Palo Alto Cortex XDR), and ticketing systems (e.g., ServiceNow).
  • Demonstrated ability to author and tune detection content (e.g., KQL in Sentinel/Defender) and operationalize it into production.
  • Experience analyzing cloud security telemetry (e.g., Azure/Entra sign-in logs, AWS CloudTrail).
  • Hands-on experience building or maintaining automated playbooks and response workflows in a SOAR platform.
  • Strong understanding of network security concepts, operating systems, and malware analysis techniques.
  • Familiarity with the MITRE ATT&CK framework and threat intelligence platforms.
  • Excellent analytical, problem-solving, and communication skills, with the ability to work under pressure and manage multiple priorities.
Preferred Qualifications
  • Certifications such as CISSP, GCIA, GCIH, GCFA, CySA+, eJPT/PJPT, CEH, SC-200.
  • Scripting and automation skills (Python, PowerShell) for tooling, enrichment, and analysis.
  • Experience supporting an EDR platform migration (e.g., Cortex XDR to Microsoft Defender XDR).
  • Experience with or strong interest in AI-assisted triage and agentic SOC tooling to augment analyst workflows.
  • Broader cloud security experience across AWS, Azure, and OCI.
  • Experience with Microsoft Sentinel, Proofpoint, and Palo Alto Cortex XDR.
Work Environment
  • Mandatory 4 days onsite; 1 day remote.
  • On-call rotation may be required for critical incident response.
  • Collaborative team environment with opportunities for growth and specialization.
Benefits

Robust health insurance plans, including medical, dental, and vision coverage.

401(k) retirement plan with a 1:1 company match up to 5%.

Paid parental leave and an Associate Assistance Plan.

Education Assistance Program and up to $30,000 in Adoption Assistance.

Up to three weeks of vacation annually, plus generous holiday, sick leave, and personal day policies.

New-hire referral bonus program and significant home-purchase discounts.

Dedicated "Everyone's Included Day" and other supportive initiatives.

Equal Employment Opportunity

Lennar is an equal-opportunity employer and complies with all applicable federal, state, and local fair employment practices laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Analyst
Lead Security Analyst

Lennar • Irving (TX)

On-site
USD 120,000 - 160,000
Health insurance
401(k) match
Paid parental leave
+6
Security Program Manager
Security Program Manager

Lennar • Irving (TX)

On-site
USD 140,000 - 190,000
Security Program Manager
Security Program Manager

Lennar USA • Miami (FL)

On-site
USD 120,000 - 180,000
Health insurance
401(k) match
Paid parental leave
+1
Security Program Manager
Security Program Manager

Lennar USA • Irving (TX)

On-site
USD 120,000 - 150,000
Health insurance
401(k) match
Paid parental leave
+4
Lead Security Analyst
Lead Security Analyst

Jobtailor • Town of Florida (NY)

On-site
USD 180,000 - 240,000
Security Operations Lead
Security Operations Lead

Segment (Twilio) • Foster City (CA)

On-site
USD 140,000 - 210,000
Health, Dental, Vision
401(k)
Paid time off
+2
Security Operations Center (SOC) Analyst (Remote)
Security Operations Center (SOC) Analyst (Remote)

Trace3 • Louisville (KY)

On-site
USD 70,000 - 90,000
Comprehensive medical, dental and vision plans
401(k) Retirement Plan with Employer Match
Competitive Compensation
+4
Security Operations Center (SOC) Analyst (Remote)
Security Operations Center (SOC) Analyst (Remote)

Trace3 • Fargo (ND)

On-site
USD 70,000 - 90,000
Comprehensive medical, dental and vision plans
401(k) Retirement Plan with Employer Match
Training and development programs
+1
Senior Security Analyst
Senior Security Analyst

Tata Consultancy Services • Houston (TX)

On-site
USD 110,000 - 130,000
Discretionary Annual Incentive
Medical Coverage: Health, Dental & Vis
401K Plan
+2
Security Operations Center (SOC) Analyst (Remote)
Security Operations Center (SOC) Analyst (Remote)

Trace3 • Kansas City (KS)

On-site
USD 70,000 - 90,000
Comprehensive medical, dental and vision plans
401(k) Retirement Plan with Employer Match
Competitive Compensation
+2