Назад
Company hidden
2 дня назад

Lead SOC Analyst (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead SOC Analyst (Cybersecurity): Leading daily SOC operations while performing threat detection, investigation, and incident response with an accent on MDR coordination, detection engineering, and SOC process development. Focus on advanced threat hunting, tuning SIEM/XDR/MDR detection rules, coordinating cross-functional incident response, and improving SOC maturity through playbooks, metrics, and operational documentation.

Location: On-site full-time in Grand Rapids, Michigan, United States

Company

hirify.global is an organization operating an internal Security Operations Center with an external managed detection and response provider.

What you will do

  • Lead daily SOC operations and serve as the senior escalation point for security incidents.
  • Perform advanced threat hunting, incident investigation, root cause analysis, containment, and remediation.
  • Coordinate incident response across IT, infrastructure, application, and business teams.
  • Manage operational coordination with the MDR provider, including alert triage, escalations, service reviews, and detection quality.
  • Develop and maintain SOC SOPs, playbooks, runbooks, documentation, metrics, and KPIs.
  • Improve detection engineering by tuning SIEM, XDR, and MDR rules and expanding logging and telemetry coverage.

Requirements

  • Bachelor’s degree in computer science, information security, or equivalent experience.
  • 7+ years of experience in SOC, incident response, or cybersecurity operations.
  • Experience leading incident investigations, managing escalations, threat hunting, detection tuning, and log analysis.
  • Strong understanding of SIEM, XDR, EDR, and SOAR platforms.
  • Experience developing SOC processes, playbooks, runbooks, and operational documentation.
  • Strong leadership, mentoring, analytical, decision-making, and communication skills.

Nice to have

  • Experience with Splunk, Microsoft Sentinel, Defender XDR, or similar platforms.
  • Experience working with an MDR provider or in a hybrid internal-plus-MDR SOC model.
  • Familiarity with NIST or CMMC compliance frameworks.
  • CISSP, GCIA, GCIH, or equivalent certification.

Culture & Benefits

  • Player/coach role combining hands-on cybersecurity operations with technical leadership.
  • Opportunity to mentor analysts and support hiring, onboarding, and skill development.
  • Focus on continuous improvement, audit readiness, compliance, and organizational security posture.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →