Senior SOC Analyst
FlexTrade · Great Neck, NY · Yesterday
On-siteInformation TechnologyFull-time
About the role
The Team: We are looking for a technically sharp and driven Senior SOC Analyst to join our cybersecurity team. You will serve as a key individual contributor within the Security Operations Center, owning day-to-day detection, analysis, and response activities while contributing to vulnerability management and purple team exercises.
Responsibilities
- Security Monitoring & Incident Response
- Monitor, triage, and investigate security alerts across SIEM, EDR, NDR, and cloud platforms, escalating to the SOC Lead as appropriate.
- Respond to security incidents end-to-end: initial triage, containment, eradication, recovery, and post-incident documentation.
- Execute and help maintain incident response playbooks and runbooks, flagging gaps and recommending improvements.
- Conduct root cause analysis following incidents and contribute findings to post-incident reviews.
- Produce clear, accurate incident reports suitable for both technical and non-technical audiences.
- Participate in on-call rotation and be available to respond to high-severity incidents outside of business hours when required.
- Vulnerability Management
- Perform vulnerability scans and assessments using tools such as Tenable, Qualys, or Rapid7 on a scheduled and ad-hoc basis.
- Analyze and prioritize vulnerabilities using CVSS scores, threat intelligence, and asset criticality to guide remediation efforts.
- Track and follow up on remediation progress with IT and engineering teams, escalating stalled items as needed.
- Contribute to vulnerability reporting, capturing trends, patch compliance rates, and risk reduction metrics.
- Stay current on newly disclosed CVEs and exploit trends, advising on risk-based prioritization.
- Purple Teaming & Threat Detection
- Participate in purple team exercises alongside red team operators to validate detection and response capabilities.
- Map adversary techniques to the MITRE ATT&CK framework and use exercise findings to identify detection gaps.
- Write and tune SIEM detection rules, correlation queries, and alerts based on adversary TTPs and purple team outcomes.
- Conduct threat hunting exercises using hypothesis-driven and ATT&CK-aligned methodologies to surface undetected threats.
- Track emerging threat actor activity and incorporate relevant TTPs into detection logic and hunting campaigns.
- Security Operations & Collaboration
- Analyze logs from a variety of sources including endpoints, firewalls, proxies, cloud platforms, and identity systems.
- Enrich investigations with threat intelligence, enriching indicators of compromise (IOCs) and correlating activity across data sources.
- Collaborate with IT and engineering to support security control tuning, reducing false positives and improving signal quality.
- Maintain accurate and up-to-date SOC documentation including runbooks, knowledge base articles, and escalation procedures.
- Support compliance activities (e.g., SOC 2, ISO 27001, NIST CSF) by providing evidence and participating in audits as required.
- Mentor junior analysts by sharing knowledge and providing guidance on investigations and tool usage, without formal management responsibility.
Required Skills and Experience
- 5+ years of hands-on experience in a SOC, security operations, or incident response role.
- Strong proficiency with SIEM platforms such as Splunk, Microsoft Sentinel, or Sumo Logic.
- Hands-on experience with EDR solutions such as CrowdStrike Falcon, or Microsoft Defender.
- Hands-on experience configuring conditional access policies in Entra or another platform.
- Hands-on experience configuring DLP policies on Purview or another platform.
- Demonstrated experience triaging and responding to a significant volume of security alerts and incidents.
- Working knowledge of vulnerability management tools and processes, including scanning, prioritization, and remediation tracking.
- Solid understanding of network protocols and fundamentals: TCP/IP, DNS, HTTP/S, firewalls, and proxies.
- Experience analyzing logs across endpoints, networks, cloud environments, and SaaS platforms.
- Familiarity with the MITRE ATT&CK framework and applying it to investigations and detection engineering.
- Scripting experience for investigation and automation tasks (Python, PowerShell, or Bash).
- Strong analytical and problem-solving skills with high attention to detail.
- Excellent written and verbal communication skills; able to convey technical findings clearly to varied audiences.
Preferred Qualifications
- Experience participating in purple team, red team, or adversary emulation exercises.
- Background in threat hunting using hypothesis-driven or behavior-based methodologies.
- Exposure to SOAR platforms and security automation or workflow development.
- Experience with cloud security telemetry and threat models across AWS, Azure, or GCP.
- Familiarity with threat intelligence platforms or workflows (e.g., MISP, Recorded Future, OpenCTI).
- Knowledge of digital forensics tools and techniques (KAPE, Volatility, Velociraptor, etc.).
- Certifications: Required: CISSP – Certified Information Systems Security Professional Preferred: GIAC GCIH – GIAC Certified Incident Handler Preferred: GIAC GCIA – Intrusion Analyst Preferred: CEH – Certified Ethical Hacker Preferred: CompTIA CySA+ or Security+ Preferred: OSCP, GPEN, or similar offensive/detection-focused certification Preferred: Cloud security certifications: Microsoft SC-200, AWS Security Specialty, or equivalent
Why Join Us
- A hands-on practitioner role with real ownership over detection, response, and vulnerability operations.
- Hybrid schedule with consistent in-person collaboration and one remote day per week.
- Dedicated budget for professional development, training, and certification support.
- Competitive compensation and comprehensive benefits package.