Remote job
Sr SOC Analyst
Job details
About this role
Role overview
Join a Cyber Defense Operations team protecting both the corporate environment and a widely deployed privileged access management SaaS platform. The Senior SOC Analyst serves as a frontline responder who monitors, investigates, and resolves security events across enterprise and product infrastructure, working alongside threat hunters, incident responders, and detection engineers. The team is intentionally moving toward an AI-augmented operating model, expecting analysts to actively use AI tools and help shape how automation is woven into detection, triage, and response workflows.
Responsibilities
- Triage and investigate alerts across SIEM, EDR, and CSPM platforms, classifying severity, documenting findings, and tracking each case through its full lifecycle in ticketing and case management systems. - Lead or support incident response engagements end to end, including evidence collection, forensic analysis, root cause determination, and clear written summaries for technical and leadership audiences. - Execute established IR runbooks spanning identity, endpoint, cloud, and email investigations, drawing on identity provider logs, cloud audit trails, and network flow data. - Contribute to detection engineering by tuning SIEM and EDR rules, mapping coverage to MITRE ATT&CK, and translating threat intelligence from CVEs, CISA advisories, vendor bulletins, and open-source feeds into actionable detections. - Use AI-assisted triage and enrichment tools as part of daily operations and partner with engineering teams on log ingestion, data quality, and orchestration improvements. - Help design and test LLM-based or agent-driven pipelines that augment analyst workflows and reduce manual effort.
Requirements
- At least 2 years of experience in a SOC, security operations, or incident response role. - Working knowledge of MITRE ATT&CK, common network protocols, and endpoint behavior. - Hands-on experience with at least one SIEM platform and comfort writing search or detection queries. - Familiarity with EDR platforms and cloud environments, ideally IaaS. - Practical comfort using AI systems such as LLM-based assistants or copilots inside security workflows. - Strong written communication skills with the ability to document findings clearly for both technical and non-technical audiences.
Nice to have
- Prior experience leading complex incident response engagements from triage through remediation. - Familiarity with identity and access management platforms and cloud security posture management tooling. - Scripting and automation skills in Python, PowerShell, or an equivalent language applied to security workflows. - Experience with SOAR platforms or other orchestration tools for automated response and enrichment. - Exposure to AI agent architectures, LLM-based automation pipelines, or prompt engineering for security use cases. - Background building or contributing to threat intelligence programs or detection-as-code pipelines. - Understanding of the privileged access management landscape and the threat actors that target it. - Track record of evaluating and adopting emerging technologies inside a production security environment.