Sr SOC Analyst
SIEMEDRCSPMPythonPowerShellMITRE ATT&CKThreat IntelligenceIncident ResponseAI-driven security analysis
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr SOC Analyst based in United States. As a Sr SOC Analyst, you will serve as a front-line defender protecting enterprise infrastructure and the security of customer-facing products in a high-stakes cybersecurity environment. You will monitor, investigate, and respond to sophisticated security events across corporate and product environments. Working alongside threat hunters, incident responders, and detection engineers, you will help strengthen defenses against advanced threat actors, ransomware, and supply chain attacks. The role combines security operations, incident response, detection engineering, threat intelligence, and automation. You will also play an important role in advancing an AI-augmented security operating model by integrating intelligent tools into daily workflows. This is an opportunity to take ownership, solve complex problems, and help build modern security capabilities rather than simply follow established processes. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr SOC Analyst based in United States. As a Sr SOC Analyst, you will serve as a front-line defender protecting enterprise infrastructure and the security of customer-facing products in a high-stakes cybersecurity environment. You will monitor, investigate, and respond to sophisticated security events across corporate and product environments. Working alongside threat hunters, incident responders, and detection engineers, you will help strengthen defenses against advanced threat actors, ransomware, and supply chain attacks. The role combines security operations, incident response, detection engineering, threat intelligence, and automation. You will also play an important role in advancing an AI-augmented security operating model by integrating intelligent tools into daily workflows. This is an opportunity to take ownership, solve complex problems, and help build modern security capabilities rather than simply follow established processes. Accountabilities: Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering corporate and product environments. Investigate security events to determine scope, severity, impact, and appropriate escalation, using AI-assisted enrichment and analysis where applicable. Participate in or lead incident response activities from initial detection through remediation, including evidence collection, forensic analysis, root-cause investigation, and stakeholder communication. Investigate identity, endpoint, cloud, email, and network activity using cloud audit trails, identity provider logs, network flow data, and other security telemetry. Execute and improve incident response runbooks, playbooks, and standard operating procedures while maintaining accurate case documentation and evidence-handling processes. Develop, tune, and validate SIEM and EDR detection rules, reducing false positives and closing security coverage gaps. Translate threat intelligence, CVE advisories, CISA alerts, vendor bulletins, and open-source intelligence into actionable detection content, particularly for privileged access and supply chain threats. Maintain and evolve detection coverage aligned with MITRE ATT&CK and collaborate with threat hunters on hypothesis-driven investigations. Use AI-driven tools, automation, and LLM-based capabilities to improve alert triage, enrichment, investigation, and operational efficiency. Contribute to the design and optimization of AI prompts, agent workflows, and automated security pipelines, while partnering with engineering teams on log ingestion, data quality, and integrations. Maintain shift handoffs and operational notes, participate in on-call rotations, and track metrics such as MTTD, MTTR, MTTC, and false-positive rates. Participate in tabletop exercises, purple team activities, post-incident reviews, and continuous improvement initiatives. Requirements: 2+ years of experience in a SOC, security operations, or incident response role. Strong understanding of common attack techniques, MITRE ATT&CK, network protocols, and endpoint behavior. Experience working with at least one SIEM platform and writing search or detection queries. Familiarity with EDR platforms and cloud environments, preferably IaaS. Comfortable using AI systems such as LLM-based assistants, copilots, or AI-driven security analysis tools as part of everyday workflows. Strong written communication skills, with the ability to document technical findings clearly and concisely for both technical and non-technical audiences. Experience leading or co-leading complex incident response engagements from triage through remediation is a plus. Familiarity with identity and access management platforms, CSPM tools, SOAR platforms, or security orchestration technologies is preferred. Scripting and automation experience using Python, PowerShell, or similar technologies is an advantage. Experience with AI agent architectures, LLM-based automation, or prompt engineering for security applications is valued. Background in threat intelligence programs, detection-as-code, or evaluating emerging technologies in production security environments is beneficial. Understanding of privileged access management and the threat actors targeting privileged access infrastructure is a plus. Benefits: Opportunity to work on high-impact cybersecurity challenges protecting both enterprise infrastructure and security-critical customer products. Collaborative environment alongside experienced threat hunters, incident responders, and detection engineers. Culture focused on flexibility, trust, continuous learning, and professional growth. Exposure to AI-driven security operations, automation, LLM-based workflows, and emerging cybersecurity technologies. Inclusive and diverse workplace focused on collaboration, belonging, and shared success. Participation in advanced security initiatives including threat hunting, purple teaming, tabletop exercises, and detection engineering. On-call participation and operational ownership within a modern cyber defense environment. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
Not disclosed
Location
United States
Job type
Full-time
Category
Security Engineering
Experience
2+ years
Posted
Today
Job Highlights
- 2+ years level role
- 100% Remote — open to candidates in United States
- Full-time position
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.