SOC 3 Analyst
About the role
The Security Senior Analyst role is responsible for managing services for Managed Security Service customers. The Security Specialist assesses, discovers, and directs remediation of security threats and vulnerabilities within client environments while working as part of a managed security team on various cyber security projects and tasks.
This role involves collaboration at all levels with Solution Architects, Development Operations, Engineers, SOC Analysts, clients, and other stakeholders to build and manage security architecture and systems that remain current in the rapidly evolving Managed Security Services industry.
As a senior technical SOC role, the holder is expected to provide Tier 3 analysis, advanced investigation, threat hunting, forensic support, and technical leadership for complex or critical incidents. The role also supports mentoring, service improvement, playbook evolution, and close collaboration with clients, internal teams, channel partners, and vendors.
Responsibilities
- Handles internal and client escalations by engaging with key stakeholders.
- Ensures adherence to published SOC policies and procedures.
- Acts as a subject matter expert across Managed Security Services, clearly articulating deliverables, limitations, and feasibility.
- Configures, tunes, and maintains SOC tools to improve detection capabilities and builds reusable visualizations/dashboards for security alert triage, threat hunting, and similar use cases.
- Develops Standard Operating Procedures (SOPs) and use cases for monitoring and handling different types of security events.
- Performs threat intelligence gathering to ensure detection methods are effective against current threats.
- Hunts for suspicious activity based on anomalous behavior.
- Handles events as part of the Security Incident Management Process.
- Works with internal and external partners to investigate and advise on security incidents and anomalies.
- Prepares detailed reports on findings, investigation status, progress, vulnerabilities, and risk factors.
- Serves as the senior technical escalation point and mentor for colleagues.
- Produces incident response playbooks to drive a consistent approach to handling common incidents and improve operational processes.
- Analyzes structured security log data through aggregated/correlated reports or visualizations.
- Identifies and implements opportunities for innovative and continuous improvement.
- Leads customer incident response investigations and containment of threats, advising on remediation.
- Participates in the Security Operations Centre on-call rotation.
- Maintains a working knowledge of applicable Federal, State, and Local laws and regulations, as well as Logicalis policies and procedures.
- Supports and conducts self in a manner consistent with customer service expectations.
Qualifications
To perform this job successfully, an individual should be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Requirements
- Bachelor’s Degree in a related field or equivalent combination of education and experience.
- Previous hands-on experience working in SOC environments is mandatory.
- Experience working within managed services, including SLAs, KPIs, operational reporting, customer escalations, and continuous service improvement.
- Strong experience in incident response, complex investigation, threat hunting, and advanced security analysis.
- Forensics experience is mandatory, including endpoint, network, or cloud investigation scenarios.
- Experience with forensic tooling and investigation techniques such as evidence collection, timeline analysis, artifact review, and root-cause analysis.
- Experience with SIEM platforms such as Microsoft Sentinel and/or Splunk.
- Knowledge of MITRE ATT&CK, detection engineering, EDR/XDR technologies, and incident response frameworks.
- Experience with Cisco XDR, Microsoft Defender is a strong plus.
- Experience with MISP, n8n, or SOAR platforms is a plus.
- Ability to act as a senior escalation point, lead technical investigations, and support customers during complex or critical incidents.
- Excellent written and oral communication skills, including executive-level incident reporting and clear remediation guidance.
- Strong analytical mindset, ability to work under pressure, and commitment to continual service improvement.
Skills
- Typically 5+ years of experience in cybersecurity, including significant experience in SOC, MSSP, or mature internal security operations environments.
- Hands-on experience analyzing security logs from SIEM, EDR/XDR, endpoint, identity, cloud, and network security sources.
- Experience with Microsoft Sentinel and/or Splunk is highly valued.
- Experience with Cisco XDR, MISP, n8n, and security automation/orchestration is highly valued.
- Experience with Azure and/or AWS security monitoring is valued.
- Awareness of security standards and frameworks such as ISO 27001, NIST, MITRE ATT&CK, and common vulnerability management practices.
Certifications
- Certifications from Microsoft, Splunk, and GIAC are highly valued, such as Microsoft SC-200, Microsoft SC-100, Splunk Core Certified Power User, Splunk Enterprise Certified Admin, GIAC GCIH, GCIA, GCFA, GNFA, GREM, or GCTI.
- Other relevant certifications such as CompTIA CySA+, CISSP, CISM, or equivalent are also valued.
Physical Demands
The physical demands described here are representative of those that should be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- While performing the duties of this job, the employee is constantly required to sit, talk, see, hear, and use hands and arms.
- The employee is frequently required to stand; move about, climb steps or balance; and stoop, kneel, crouch, or crawl.
- The employee may occasionally lift and/or move up to 10 pounds.
Pay
Compensation Range: $77,517 - $100,000/yr.