Sr SOC Analyst

Jobgether

United States

On-site

USD 120,000 - 150,000

Full time

5 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Professional growth
AI-driven tools
Collaborative team
On-site workplace

Job summary

Jobgether in the United States seeks a Sr SOC Analyst to defend enterprise infrastructure and customer-facing products in a high-stakes cybersecurity environment. You will monitor, investigate, and respond to sophisticated security events across corporate and product environments, working with threat hunters, incident responders, and detection engineers.

Join a team advancing an AI-augmented security operating model by integrating intelligent tools into daily workflows, taking ownership, solving

Qualifications

  • 2+ years in a SOC, security operations, or incident response role.
  • Strong understanding of MITRE ATT&CK, attack techniques, network protocols, and endpoint behavior.
  • Experience with at least one SIEM and writing detection queries.
  • Familiarity with EDR platforms and cloud environments.

Responsibilities

  • Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering enterprise environments.
  • Investigate security events to determine scope, severity, impact, and escalation.
  • Lead incident response activities from initial detection through remediation, including evidence collection and stakeholder communication.
  • Analyze identity, endpoint, cloud, email, and network activity using logs and telemetry.
  • Develop, tune, and validate detection rules to reduce false positives and cover gaps.
  • Translate threat intelligence into actionable detection content for privileged access and supply chain threats.
  • Maintain MITRE ATT&CK-aligned detection coverage and collaborate with threat hunters.
  • Use AI-driven tools and automation to improve alert triage, enrichment, and investigation.

Job description

Our partner is looking for a Sr SOC Analyst based in United States. As a Sr SOC Analyst, you will serve as a front-line defender protecting enterprise infrastructure and the security of customer-facing products in a high-stakes cybersecurity environment. You will monitor, investigate, and respond to sophisticated security events across corporate and product environments. Working alongside threat hunters, incident responders, and detection engineers, you will help strengthen defenses against advanced threat actors, ransomware, and supply chain attacks. The role combines security operations, incident response, detection engineering, threat intelligence, and automation. You will also play an important role in advancing an AI-augmented security operating model by integrating intelligent tools into daily workflows. This is an opportunity to take ownership, solve complex problems, and help build modern security capabilities rather than simply follow established processes.

Accountabilities
  • Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering corporate and product environments.
  • Investigate security events to determine scope, severity, impact, and appropriate escalation, using AI-assisted enrichment and analysis where applicable.
  • Participate in or lead incident response activities from initial detection through remediation, including evidence collection, forensic analysis, root-cause investigation, and stakeholder communication.
  • Investigate identity, endpoint, cloud, email, and network activity using cloud audit trails, identity provider logs, network flow data, and other security telemetry.
  • Execute and improve incident response runbooks, playbooks, and standard operating procedures while maintaining accurate case documentation and evidence-handling processes.
  • Develop, tune, and validate SIEM and EDR detection rules, reducing false positives and closing security coverage gaps.
  • Translate threat intelligence, CVE advisories, CISA alerts, vendor bulletins, and open-source intelligence into actionable detection content, particularly for privileged access and supply chain threats.
  • Maintain and evolve detection coverage aligned with MITRE ATT&CK and collaborate with threat hunters on hypothesis-driven investigations.
  • Use AI-driven tools, automation, and LLM-based capabilities to improve alert triage, enrichment, investigation, and operational efficiency.
  • Contribute to the design and optimization of AI prompts, agent workflows, and automated security pipelines, while partnering with engineering teams on log ingestion, data quality, and integrations.
  • Maintain shift handoffs and operational notes, participate in on-call rotations, and track metrics such as MTTD, MTTR, MTTC, and false-positive rates.
  • Participate in tabletop exercises, purple team activities, post-incident reviews, and continuous improvement initiatives.
Requirements
  • 2+ years of experience in a SOC, security operations, or incident response role.
  • Strong understanding of common attack techniques, MITRE ATT&CK, network protocols, and endpoint behavior.
  • Experience working with at least one SIEM platform and writing search or detection queries.
  • Familiarity with EDR platforms and cloud environments, preferably IaaS.
  • Comfortable using AI systems such as LLM-based assistants, copilots, or AI-driven security analysis tools as part of everyday workflows.
  • Strong written communication skills, with the ability to document technical findings clearly and concisely for both technical and non-technical audiences.
  • Experience leading or co-leading complex incident response engagements from triage through remediation is a plus.
  • Familiarity with identity and access management platforms, CSPM tools, SOAR platforms, or security orchestration technologies is preferred.
  • Scripting and automation experience using Python, PowerShell, or similar technologies is an advantage.
  • Experience with AI agent architectures, LLM-based automation, or prompt engineering for security applications is valued.
  • Background in threat intelligence programs, detection-as-code, or evaluating emerging technologies in production security environments is beneficial.
  • Understanding of privileged access management and the threat actors targeting privileged access infrastructure is a plus.
Benefits
  • Opportunity to work on high-impact cybersecurity challenges protecting both enterprise infrastructure and security-critical customer products.
  • Collaborative environment alongside experienced threat hunters, incident responders, and detection engineers.
  • Culture focused on flexibility, trust, continuous learning, and professional growth.
  • Exposure to AI-driven security operations, automation, LLM-based workflows, and emerging cybersecurity technologies.
  • Inclusive and diverse workplace focused on collaboration, belonging, and shared success.
  • Participation in advanced security initiatives including threat hunting, purple teaming, tabletop exercises, and detection engineering.
  • On-call participation and operational ownership within a modern cyber defense environment.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Jobgether • United States

Hybrid
USD 125,000 - 190,000
Remote or hybrid work
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Security Operations Lead
Security Operations Lead

Segment (Twilio) • Foster City (CA)

On-site
USD 140,000 - 210,000
Health, Dental, Vision
401(k)
Paid time off
+2
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobgether • United States

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
+1
Security Operations Analyst
Security Operations Analyst

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Health benefits
401(k) and profit-sharing
Paid holidays
+1
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Principal Consultant – SOC Transformation and XSIAM Deployment
Principal Consultant – SOC Transformation and XSIAM Deployment

Palo Alto Networks • California (MO)

Remote
USD 163,000 - 184,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Senior Detection and Response Analyst
Senior Detection and Response Analyst

Prestige Staffing • Dallas (TX)

On-site
USD 120,000 - 180,000
Contract extension potential
Remote work
Career growth
+2
MSSP SOC Analyst
MSSP SOC Analyst

Districttechgroup • Washington

Remote
USD 75,000 - 115,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2