- Hybrid | Broward county FL | 24x7x365 SOC
- We are seeking an experienced Level 3 SOC Analyst to serve as a senior technical authority within a 24x7x365 Security Operations Center.
- This is a hands-on technical role, not a people-management position. The Level 3 Analyst will own complex investigations escalated by Level 1 and Level 2 analysts, conduct advanced threat hunting and forensic analysis, improve detection quality, and provide technical mentorship and escalation support to the SOC team.
- The ideal candidate is an experienced security professional who can independently investigate sophisticated threats, make sound decisions during high-severity incidents, and clearly communicate findings to both technical teams and customers.
- Key Responsibilities
- Advanced Investigation & Threat Analysis
- Own complex security investigations escalated from Level 1 and Level 2 analysts.
- Determine incident scope, impact, root cause, and disposition.
- Investigate advanced threats including:
- Ransomware and pre-ransomware activity
- Advanced persistent threats (APTs)
- Business Email Compromise (BEC)
- Identity-based attacks
- Insider threats
- Reconstruct attack timelines across endpoint, identity, network, email, and cloud telemetry.
- Perform forensic analysis involving logs, host artifacts, identity activity, memory/disk artifacts, and network traffic.
- Produce technically defensible findings suitable for customers and regulated environments.
- Security Technology & Detection Stack
- Work across enterprise security technologies including:
- Huntress MDR/EDR/ITDR
- Google Chronicle / Google SecOps
- CrowdStrike
- Microsoft Defender
- Microsoft 365
- Microsoft Entra ID
- SIEM/SOAR technologies
- Threat intelligence platforms
- Endpoint and network telemetry
- Comparable experience with platforms such as Microsoft Sentinel or Splunk is also highly relevant.
- Incident Response
- Serve as the senior technical escalation point during high-severity security incidents.
- Coordinate response activities with SOC leadership, infrastructure/NOC teams, cybersecurity teams, and external partners.
- Confirm true-positive incidents and identify indicators of compromise.
- Coordinate containment activities with infrastructure teams.
- Support major incident response and incident command.
- Work against defined severity-based response requirements and MTTA, MTTD, and MTTR objectives.
- Identify incidents that may trigger contractual or regulatory notification requirements and escalate appropriately.
- Lead technical post-incident reviews and identify required detection or process improvements.
- Threat Hunting & Proactive Defense
- Conduct structured, hypothesis-driven threat hunts across customer environments.
- Search for Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
- Perform retrospective analysis against historical telemetry.
- Use threat intelligence and MITRE ATT&CK to guide investigations.
- Identify gaps in existing detection coverage.
- Help improve overall threat-detection capabilities.
- Detection Engineering & Tuning
- Analyze detection rules, correlation logic, raw logs, and normalized security data.
- Investigate false positives, detection gaps, parser failures, and missing telemetry.
- Develop evidence-based recommendations for detection-rule improvements.
- Work with SIEM/SOAR and detection-engineering teams on:
- Detection tuning
- Parser and schema mapping
- Use-case development
- Detection scoring
- Log ingestion
- Validate that detection changes continue to identify the threats they were designed to detect.
- Identify repetitive investigation, enrichment, triage, and containment processes that can be automated.
- Support the development of security automation and SOAR workflows.
- Mentorship & Technical Leadership
- Provide technical guidance and escalation support to Level 1 and Level 2 SOC Analysts.
- Review investigations and case documentation for technical quality.
- Help junior analysts develop stronger investigation and incident-response skills.
- Develop and maintain:
- Incident-response playbooks
- Runbooks
- Standard Operating Procedures (SOPs)
- Support SOC onboarding, tabletop exercises, and incident-response simulations.
- This position does not have direct reports. Technical mentorship is a core responsibility.
- Customer Communication & Documentation
- Independently produce professional incident reports covering:
- Incident timeline
- Root cause
- Scope and impact
- Actions taken
- Recommended remediation
- Clearly communicate complex security findings to technical and non-technical audiences.
- Participate in customer incident calls when required.
- Maintain accurate investigation documentation throughout the incident lifecycle.
- Contribute technical security findings and trends to customer service reviews and quarterly business reviews.
- Participate in formal SOC shift handoffs to ensure continuity of open investigations.
- Required Experience
- 5+ years of SOC, cybersecurity operations, incident response, or related security experience.
- Demonstrated ownership of complex or escalated security investigations.
- Hands-on experience with incident response, forensic analysis, and threat hunting.
- Experience working with modern SIEM/SOAR and EDR/MDR platforms.
- Strong understanding of endpoint, network, identity, and cloud security telemetry.
- Experience investigating Microsoft 365 and Microsoft Entra ID environments.
- Experience with at least one major cloud platform:
- Azure
- AWS
- Google Cloud Platform
- Strong working knowledge of MITRE ATT&CK.
- Ability to independently investigate complex security incidents with limited supervision.
- Experience mentoring or providing escalation support to junior SOC analysts.
- Strong written and verbal English communication skills.
- Experience within a multi-client MSSP, MSP, MDR, or managed-security environment is strongly preferred.
- Technical Skills
- Candidates should have strong experience in several of the following areas:
- SIEM / SOAR
- Google Chronicle / Google SecOps
- Microsoft Sentinel
- Splunk
- Huntress
- CrowdStrike Falcon
- Microsoft Defender
- EDR / MDR / XDR
- Incident Response
- Digital Forensics
- Threat Hunting
- Detection Engineering
- Malware Analysis
- Threat Intelligence
- Microsoft 365
- Entra ID
- Azure / AWS / GCP
- MITRE ATT&CK
- Log and network analysis
- Python and/or PowerShell
- Security automation
- ConnectWise Manage or similar PSA/ticketing platforms
- Knowledge of security frameworks and regulatory requirements including NIST, CIS, ISO 27001, HIPAA, PCI-DSS, and GLBA is highly desirable.
- Education
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field preferred.
- Equivalent professional cybersecurity experience will also be considered.
- Certificatio
Mention you found this on Data First Jobs — it helps us bring you more roles like this.
Level 3 SOC Analyst – Senior Security Operations
Synergy Business Consulting, Inc.
Similar Analytics Jobs
View all Analytics jobs→Merck
Senior Intelligence Analyst
New
RemoteUSA
University of Rochester
Lead Org Change Analyst
New
RemoteUSA$86,900 - $130,300
Quantum Health
Lead Business Intelligence Analyst
New
RemoteUSA
SMB Team
FP&A Analyst
New
USA
PayPal
Sr Analyst, Strategic Sourcing
New
Austin, Texas (USA)
Quantum Life
Data Insights Analyst (Entry / Junior)
New
New York, New York (USA)
Like this role? Get carefully selected jobs like it, twice a week, straight to your inbox.
Free, no spam. Unsubscribe anytime.