
Senior SOC Analyst
Posted Sep 8

Posted Sep 8
This is a fully remote position, open to applicants in United States, +1 more country.
• Oversee and prioritize security alerts across SIEM, EDR, and CSPM platforms.
• Analyze alerts to assess their scope, severity, and escalation needs.
• Utilize AI-enhanced tools for triage, enrichment, and investigation processes.
• Categorize, document, and monitor alerts throughout their lifecycle.
• Engage in or lead incident response efforts from detection to remediation.
• Gather evidence, perform forensic analysis, identify root causes, and liaise with stakeholders.
• Examine identity provider logs, cloud audit trails, network flow data, and various cloud-native sources.
• Implement incident-response runbooks across identity, endpoint, cloud, and email workflows.
• Generate incident summaries and post-incident reports.
• Design, implement, fine-tune, and validate detection rules for SIEM and EDR.
• Convert threat intelligence into actionable detection content while ensuring MITRE ATT&CK coverage.
• Contribute to the integration of AI and automation, including prompts, agent workflows, and LLM-based pipelines.
• Collaborate with engineering teams to enhance log ingestion, data quality, and tool integrations.
• Maintain operational notes and documentation for shift handoffs.
• Refine incident response runbooks, playbooks, and standard operating procedures.
• Be part of an after-hours on-call rotation.
• Monitor metrics such as MTTD, MTTR, MTTC, and false-positive rates.
• Engage in tabletop exercises, purple team activities, and post-incident reviews.
• A minimum of 2 years of experience in a SOC, security operations, or incident response position.
• Knowledge of MITRE ATT&CK, network protocols, and endpoint behavior.
• Experience with at least one SIEM platform, along with familiarity in writing search or detection queries.
• Familiarity with EDR platforms and cloud environments; IaaS experience is preferred.
• Proficiency in using AI systems such as LLM-based assistants, copilots, or AI-driven analysis tools in security workflows.
• Excellent written communication skills with the ability to document findings effectively for both technical and non-technical audiences.
• A culture of flexibility, trust, and continuous learning.
• Recognition for employee growth and contributions.
• A workplace culture focused on diversity and inclusion.
• Support and care for employees.
SyncEzy
Thrive
Capgemini
Get handpicked remote jobs straight to your inbox weekly.