Senior SOC Analyst
Job Description
REQUIREMENTS
- 6+ years in a SOC, threat hunting, or DFIR role, with real incident ownership, not just alert queue work
- GCFA, GCIH, GCIA, or equivalent DFIR/detection engineering credential strongly preferred
- Real depth in at least three of: EDR internals and endpoint telemetry, cloud security monitoring (AWS/GCP), network forensics, malware analysis, SIEM and detection-as-code, identity threat hunting
- Comfortable writing your own detection logic and tooling in Python or a proper query language, not copy-pasting from a vendor blog
- You think like an attacker when you write a detection, because that’s the only way to catch one
- You know the difference between reducing noise and creating a blind spot, and you’ve caught that mistake before it cost someone
- You can write a report that gets fixed, not filed
RESPONSIBILITES
- Hunt proactively across infrastructure, cloud, identity, and endpoint, working from hypotheses, not just waiting on alerts
- Build, tune, and maintain detections mapped to real attacker TTPs (MITRE ATT&CK), not whatever ships default from the vendor
- Own incidents end to end: triage, containment, root cause, and a report that leads to an actual fix
- Push back on any tuning decision, exclusion, or “known good” assumption that trades visibility for noise reduction, and catch it before it ships
- Partner with Red Team on purple-team exercises, turning every finding into a detection
- Extend detection and monitoring coverage into our AI agent stack: prompt injection, tool misuse, credential exposure in agent workflows
- Do enough malware analysis and reverse engineering to actually understand what you’re looking at, not just what a sandbox report says
- Mentor junior analysts and raise the bar on what “triaged” actually means
Are you interested in this position?
Apply by clicking on the “Apply Now” button below!
#CrossChannelJobs #JobSearch
#CareerOpportunities #HiringNow
#Employment #JobOpenings
#JobSeekers