Data First Jobs

Synergy Business Consulting, Inc.

Level 3 SOC Analyst – Senior Security Operations

Contract · In Office · Broward County, Florida (USA)

Posted Oct 6, 2026

Work Options
Seniority Level
Cloud Stack
Skills
Job Type
Position Group
  • Hybrid | Broward county FL | 24x7x365 SOC
  • We are seeking an experienced Level 3 SOC Analyst to serve as a senior technical authority within a 24x7x365 Security Operations Center.
  • This is a hands-on technical role, not a people-management position. The Level 3 Analyst will own complex investigations escalated by Level 1 and Level 2 analysts, conduct advanced threat hunting and forensic analysis, improve detection quality, and provide technical mentorship and escalation support to the SOC team.
  • The ideal candidate is an experienced security professional who can independently investigate sophisticated threats, make sound decisions during high-severity incidents, and clearly communicate findings to both technical teams and customers.
  • Key Responsibilities
  • Advanced Investigation & Threat Analysis
  • Own complex security investigations escalated from Level 1 and Level 2 analysts.
  • Determine incident scope, impact, root cause, and disposition.
  • Investigate advanced threats including:
  • Ransomware and pre-ransomware activity
  • Advanced persistent threats (APTs)
  • Business Email Compromise (BEC)
  • Identity-based attacks
  • Insider threats
  • Reconstruct attack timelines across endpoint, identity, network, email, and cloud telemetry.
  • Perform forensic analysis involving logs, host artifacts, identity activity, memory/disk artifacts, and network traffic.
  • Produce technically defensible findings suitable for customers and regulated environments.
  • Security Technology & Detection Stack
  • Work across enterprise security technologies including:
  • Huntress MDR/EDR/ITDR
  • Google Chronicle / Google SecOps
  • CrowdStrike
  • Microsoft Defender
  • Microsoft 365
  • Microsoft Entra ID
  • SIEM/SOAR technologies
  • Threat intelligence platforms
  • Endpoint and network telemetry
  • Comparable experience with platforms such as Microsoft Sentinel or Splunk is also highly relevant.
  • Incident Response
  • Serve as the senior technical escalation point during high-severity security incidents.
  • Coordinate response activities with SOC leadership, infrastructure/NOC teams, cybersecurity teams, and external partners.
  • Confirm true-positive incidents and identify indicators of compromise.
  • Coordinate containment activities with infrastructure teams.
  • Support major incident response and incident command.
  • Work against defined severity-based response requirements and MTTA, MTTD, and MTTR objectives.
  • Identify incidents that may trigger contractual or regulatory notification requirements and escalate appropriately.
  • Lead technical post-incident reviews and identify required detection or process improvements.
  • Threat Hunting & Proactive Defense
  • Conduct structured, hypothesis-driven threat hunts across customer environments.
  • Search for Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
  • Perform retrospective analysis against historical telemetry.
  • Use threat intelligence and MITRE ATT&CK to guide investigations.
  • Identify gaps in existing detection coverage.
  • Help improve overall threat-detection capabilities.
  • Detection Engineering & Tuning
  • Analyze detection rules, correlation logic, raw logs, and normalized security data.
  • Investigate false positives, detection gaps, parser failures, and missing telemetry.
  • Develop evidence-based recommendations for detection-rule improvements.
  • Work with SIEM/SOAR and detection-engineering teams on:
  • Detection tuning
  • Parser and schema mapping
  • Use-case development
  • Detection scoring
  • Log ingestion
  • Validate that detection changes continue to identify the threats they were designed to detect.
  • Identify repetitive investigation, enrichment, triage, and containment processes that can be automated.
  • Support the development of security automation and SOAR workflows.
  • Mentorship & Technical Leadership
  • Provide technical guidance and escalation support to Level 1 and Level 2 SOC Analysts.
  • Review investigations and case documentation for technical quality.
  • Help junior analysts develop stronger investigation and incident-response skills.
  • Develop and maintain:
  • Incident-response playbooks
  • Runbooks
  • Standard Operating Procedures (SOPs)
  • Support SOC onboarding, tabletop exercises, and incident-response simulations.
  • This position does not have direct reports. Technical mentorship is a core responsibility.
  • Customer Communication & Documentation
  • Independently produce professional incident reports covering:
  • Incident timeline
  • Root cause
  • Scope and impact
  • Actions taken
  • Recommended remediation
  • Clearly communicate complex security findings to technical and non-technical audiences.
  • Participate in customer incident calls when required.
  • Maintain accurate investigation documentation throughout the incident lifecycle.
  • Contribute technical security findings and trends to customer service reviews and quarterly business reviews.
  • Participate in formal SOC shift handoffs to ensure continuity of open investigations.
  • Required Experience
  • 5+ years of SOC, cybersecurity operations, incident response, or related security experience.
  • Demonstrated ownership of complex or escalated security investigations.
  • Hands-on experience with incident response, forensic analysis, and threat hunting.
  • Experience working with modern SIEM/SOAR and EDR/MDR platforms.
  • Strong understanding of endpoint, network, identity, and cloud security telemetry.
  • Experience investigating Microsoft 365 and Microsoft Entra ID environments.
  • Experience with at least one major cloud platform:
  • Azure
  • AWS
  • Google Cloud Platform
  • Strong working knowledge of MITRE ATT&CK.
  • Ability to independently investigate complex security incidents with limited supervision.
  • Experience mentoring or providing escalation support to junior SOC analysts.
  • Strong written and verbal English communication skills.
  • Experience within a multi-client MSSP, MSP, MDR, or managed-security environment is strongly preferred.
  • Technical Skills
  • Candidates should have strong experience in several of the following areas:
  • SIEM / SOAR
  • Google Chronicle / Google SecOps
  • Microsoft Sentinel
  • Splunk
  • Huntress
  • CrowdStrike Falcon
  • Microsoft Defender
  • EDR / MDR / XDR
  • Incident Response
  • Digital Forensics
  • Threat Hunting
  • Detection Engineering
  • Malware Analysis
  • Threat Intelligence
  • Microsoft 365
  • Entra ID
  • Azure / AWS / GCP
  • MITRE ATT&CK
  • Log and network analysis
  • Python and/or PowerShell
  • Security automation
  • ConnectWise Manage or similar PSA/ticketing platforms
  • Knowledge of security frameworks and regulatory requirements including NIST, CIS, ISO 27001, HIPAA, PCI-DSS, and GLBA is highly desirable.
  • Education
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field preferred.
  • Equivalent professional cybersecurity experience will also be considered.
  • Certificatio

Mention you found this on Data First Jobs — it helps us bring you more roles like this.

Level 3 SOC Analyst – Senior Security Operations

Synergy Business Consulting, Inc.

Like this role? Get carefully selected jobs like it, twice a week, straight to your inbox.

Free, no spam. Unsubscribe anytime.