Security Operations Center Analyst

Posted yesterday

colossus technologies groupSpringfield (MA)

SENIORITY

Senior

Apply

About the role

About the Company: Hybrid Role: Springfield Ma Area As a Senior SOC Analyst, you will play a pivotal role in defending critical infrastructure.
About the Role: As a Senior SOC Analyst, you will operate independently with minimal supervision to detect, analyze, and respond to complex security threats in a fast paced, mission critical SOC environment supporting electric grid operations, while leading response efforts for high severity and complex security incidents and serving as a project implementor for SOC‑related initiatives.
Responsibilities: Operate independently with minimal supervision to detect, analyze, and respond to complex security threats in a fast paced, mission critical SOC environment supporting electric grid operations. Lead response efforts for high severity and complex security incidents, coordinating containment, eradication, and recovery across IT, OT, and engineering teams. Apply threat modeling techniques to anticipate adversary attack paths, inform detection strategy, and improve defensive coverage across critical infrastructure systems. Perform advanced threat detection and analysis using SIEM, EDR/XDR, network monitoring, and forensic tools. Conduct malware analysis, digital forensics, and root cause investigations following security events affecting critical systems. Develop, tune, and maintain detection rules, correlation logic, and automated response playbooks to continuously improve SOC effectiveness. Coordinate tabletop exercises, purple team activities, and grid focused security assessments. Mentor and train junior SOC analysts, providing guidance on investigation techniques, tools, and best practices. Serve as the project implementor for SOC‑related initiatives, partnering with the PMO to plan, coordinate, and execute corporate security projects impacting SOC operations.
Required Skills:
  • SIEM platforms (Splunk, QRadar, ArcSight, Microsoft Sentinel, or similar)EDR/XDR solutions (CrowdStrike, Carbon Black, Microsoft Defender, SentinelOne, or similar)
  • Network analysis tools (Wireshark, Zeek, tcpdump)
  • Forensic tools and techniques (EnCase, FTK, Volatility, Autopsy)
  • Attack frameworks such as MITRE ATT&CK and the Cyber Kill ChainThreat actor tactics, techniques, and procedures (TTPs)
  • Threat intelligence frameworks and indicators of compromise (IOCs)
  • Network protocols (TCP/IP, DNS, HTTP/S, SMTP, SMB)
  • Firewalls, IDS/IPS, and proxy technologies
  • Windows and Linux operating systems (administration and security hardening)
  • Cloud environments (AWS, Azure, GCP) and cloud security principles
  • Scripting languages (Python, PowerShell, Bash)
  • Malware analysis techniques (static and dynamic analysis)
  • Log analysis and event correlation
  • Vulnerability management concepts
Preferred Skills:
  • Relevant certifications such as GCIA, GCIH, GCFA, GREM, CISSP, CySA+, or equivalent
  • Experience in critical infrastructure or energy sector environments
  • Background in threat hunting or offensive security concepts
  • Familiarity with NERC CIP compliance requirements
  • Experience with SOAR platforms (Splunk SOAR, Palo Alto XSOAR, Swimlane)
  • Knowledge of OT/ICS security concepts

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this