Senior SOC Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior SOC Analyst (Cybersecurity): Leading advanced threat detection and incident response within a Security Operations Center with an accent on SIEM optimization and proactive threat hunting. Focus on analyzing complex security incidents, mentoring analysts, and developing detection rules using Microsoft Sentinel.
Location: Marlborough, MA. Training period requires onsite in office 5 days a week; hybrid option available thereafter.
Company
provides advanced cyber, data operations, and intelligence mission support services for defense and commercial markets.
What you will do
- Monitor security alerts and perform advanced threat hunting using SIEM, IDS/IPS, and EDR tools.
- Lead incident response efforts for high-severity events, including containment, eradication, and recovery.
- Research emerging threats and develop/tune detection rules to reduce false positives.
- Mentor junior and mid-level analysts and provide guidance on complex escalations.
- Create technical reports and executive summaries to communicate findings to stakeholders.
Requirements
- 5+ years of experience in cybersecurity or a SOC environment.
- 3+ years of hands-on experience with SIEM platforms, specifically Microsoft Sentinel.
- Proficiency in log analysis, network protocols, and security event correlation.
- Experience with scripting languages such as Python, PowerShell, or Bash.
- Strong understanding of Windows, Linux, and cloud environments.
- Familiarity with threat frameworks like MITRE ATT&CK and Cyber Kill Chain.
Nice to have
- Certifications such as CISSP, GSEC, GCIH, GCTI, or CEH.
- Experience with cloud security (AWS, Azure, GCP).
- Knowledge of SOAR platforms and security automation tools.
Culture & Benefits
- Collaborative teamwork environment with a focus on innovation and collective expertise.
- Opportunity to work with talented individuals on demanding intelligence mission support.
- Equal Opportunity/Affirmative Action employer.
- Includes an on-call rotation for surge support or active incident investigation.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →