The Senior SOC Analyst is an experienced team member responsible for monitoring, detecting, and responding to cybersecurity threats in a fast-paced environment. Using commercial and open-source tools, this role investigates alerts, reviews log data, and executes response actions. As a senior member, they handle escalations, mentor junior analysts, manage complex incidents, and identify automation opportunities across the SOAR environment. This role reports to the Manager/Director of Security Operations.
ESSENTIAL JOB DUTIES
-
Serve as SME for a team dedicated to 24x7x365 monitoring and response; manage escalations and on-call incidents.
-
Investigate incidents across endpoints, networks, cloud, databases, and identity systems.
-
Mentor junior SOC analysts; serve as escalation point and identify team strengths and growth areas.
-
Participate in tabletop exercises; review findings from vulnerability assessments and pen tests.
-
Create MITRE ATT&CK-aligned detections; refine playbooks, policies, and procedures.
-
Evaluate logging gaps; recommend tool configuration changes to minimize false positives.
-
Automate repetitive tasks in the SOAR environment using ML/AI to drive efficiency.
-
Report on SOC state to leadership; partner with security engineering, IR, and IT teams.
SKILLS & EXPERIENCE
-
5+ years in SOC monitoring, incident response, or related cybersecurity fields.
-
General understanding of ML/AI applications in security operations.
-
Scripting proficiency in Python, Bash, JavaScript, or PowerShell; skilled in KQL.
-
Advanced proficiency with Windows, macOS, and Linux operating systems.
-
Expertise in SOAR, SIEM, threat intelligence, EDR/XDR, and vulnerability management.
-
Strong judgment and quick decision-making in complex, high-pressure situations.
-
MITRE ATT&CK-aligned detection engineering experience.
-
Exceptional written and verbal communication across all organizational levels.
-
Familiarity with NIST CSF, CIS Controls, PCI DSS, SOX, HIPAA, GDPR, or CCPA.
EDUCATION & CERTIFICATIONS
-
Bachelor's degree preferred in Cybersecurity, Computer Science, Engineering, or a related field.
-
Preferred certifications: GCIH, SEC+, GDAT, GCED, Microsoft Certified SOC Associate, or CISSP.