Role description
As a Level 3 SOC Analyst, you will serve as a senior escalation point within the Security Operations Center (SOC), responsible for leading complex investigations, mentoring junior analysts, and driving continuous improvement in threat detection and response capabilities. You will work closely with cross-functional teams to ensure rapid containment and remediation of security incidents, while contributing to the development of advanced detection logic and playbooks.
Key Responsibilities
Lead the investigation, escalation, and resolution of high-impact security incidents.
Perform deep-dive analysis of system logs, SIEM s, and network traffic to identify sophisticated threats.
Architect and optimize SIEM solutions, ensuring effective data ingestion and correlation.
Conduct root cause analysis and post-incident reviews to identify gaps and recommend improvements.
Generate and present detailed incident reports and threat intelligence summaries to stakeholders.
Oversee the tuning of detection rules and reduction of false positives to enhance SOC efficiency.
Mentor and guide L1 and L2 analysts in incident handling, threat hunting, and use of security tools.
Develop and maintain advanced runbooks, playbooks, and response procedures.
Collaborate with IT and security teams to implement preventive and corrective measures.
Provide expert-level support in isolating and remediating complex security issues.
Act as a subject matter expert during red team/blue team exercises and tabletop simulations.
Stay current with emerging threats, vulnerabilities, and security technologies.
Experience & Qualifications Required
Minimum 7 years of relevant experience in cybersecurity, with at least 1 year as an L3 SOC Analyst.
Must have strong IR experience and Use cases development and a bit of experience in the OT space as our business is mining, from time to time the candidate will need to develop use cases that will be relevant to OT
Proven expertise in incident response, threat hunting, and forensic analysis.
Hands-on experience with SIEM platforms such as QRadar, ArcSight, RSA NetWitness, LogRhythm, or Splunk.
Strong understanding of MITRE ATT&CK framework, kill chain methodology, and threat intelligence platforms.
Must be certified with Microsoft on the tools that are used at the SOC preferably.
Experience in developing and maintaining security documentation, including playbooks and runbooks.
Ability to work collaboratively with customer IT and security teams in high-pressure environments.
Excellent communication skills and ability to present technical findings to non-technical stakeholders.
Skills
Issue Analysis, Log Analysis, OT Security, MITRE ATT&CK
About UST
UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.