Senior SOC Analyst (Direct Hire EAD OKAY)
confidentialDenver (CO)
Senior SOC Analyst (Direct Hire EAD OKAY)
Posted 2 days ago
confidentialDenver (CO)
SENIORITY
Senior
About the role
Here is a comprehensive job description for a Senior SOC Analyst role. You can easily adapt the requirements, tools, and responsibilities to fit your company’s specific tech stack and team structure. Job Title: Senior SOC Analyst (Tier 3 / Lead)
Job Summary:
We are seeking an experienced and proactive Senior Security Operations Center (SOC) Analyst to join our Cybersecurity team. As a Tier 3 / Lead analyst, you will serve as the primary escalation point for complex security incidents, drive threat-hunting initiatives, and continuously improve our incident response capabilities. You will work closely with security engineering, IT operations, and leadership to detect, analyze, and mitigate advanced cyber threats, ensuring the resilience of our infrastructure and data.
Key Responsibilities:
Incident Escalation & Response Serve as the senior escalation point (Tier 3) for high-severity security incidents and complex threats detected by Tier 1 and Tier 2 analysts. Lead end-to-end incident response processes, including containment, eradication, and post-incident root-cause analysis (RCA).Draft detailed, executive-level Incident Reports and Lessons Learned documentation following major events. Threat Hunting & Intelligence Proactively search across endpoints, network traffic, and cloud environments to identify undetected advanced persistent threats (APTs) using the MITRE ATT&CK framework. Integrate Cyber Threat Intelligence (CTI) into security monitoring to generate actionable Indicators of Compromise (IoCs) and custom detection rules. Detection Engineering & Automation Tune and optimize SIEM, SOAR, EDR/XDR, and NDR platforms to reduce false positives and improve alert fidelity. Develop automated playbooks and workflows to streamline routine SOC tasks and speed up Mean Time to Respond (MTTR).Mentorship & Leadership Mentor and train junior SOC analysts, providing guidance on incident analysis, tool usage, and industry best practices. Participate in or lead on-call rotations for critical security escalations. Assist in conducting incident response tabletop exercises to validate procedures.
Required Qualifications & Experience:
Experience 5+ years of direct experience in cybersecurity, with at least 3+ years in a dedicated SOC or Incident Response environment. Strong experience investigating security events across cloud environments (AWS, Azure, or GCP) and on-premises enterprise networks.
Technical Skills:
SIEM & EDR/XDR: Advanced proficiency with enterprise tools (e.g., Splunk, Sentinel, Crowd Strike, Sentinel One, Palo Alto Cortex).Forensics & Analysis: Deep understanding of network traffic analysis (Wireshark, PCAP), memory forensics, host-based artifacts, and log analysis (Windows Event Logs, Syslog).Scripting & Automation: Ability to write scripts in Python, Power Shell, or Bash to automate repetitive task workflows or parse complex datasets. Frameworks: Expertise in applying security frameworks like MITRE ATT&CK, NIST SP 800-61, and NIST CSF.
Certifications:
(Preferred)GIAC: GCIH, GCFA, GNFA, or GCDACompTIA: CySA+ or CASP+Off Sec: OSCP or OSDAOther: CISSP, Azure/AWS Security Specialty Soft Skills & Attributes Critical Thinking: Ability to dissect complex security scenarios under pressure and make sound decisions swiftly. Communication: Excellent written and verbal skills to articulate technical findings to non-technical business leaders and stakeholders. Collaborative Mindset: A strong sense of ownership combined with a passion for mentoring and uplifting teammates. Work Environment &
Benefits
Work Location: [On-site / Hybrid / Fully Remote]
Schedule: Full-time (Include details about on-call rotation or shift structure)
Compensation:
Competitive salary + bonus + benefits package (401k matching, healthcare, professional development/certification stipend).
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
