Independently monitor, triage, investigate, and respond to security alerts and incidents while coordinating containment, remediation, and escalation activities. The role is expected to handle most day-to-day SOC investigations, improve detection quality, contribute to threat hunting, maintain strong case documentation, and provide guidance to analysts when required. The role is responsible for advanced security monitoring, investigation, and incident response in a 24x7 SOC environment. It requires strong analytical thinking, evidence-based investigation, and the ability to correlate activity across endpoints, network, identity, email, cloud, applications, and enterprise security tools. The role contributes to SOC maturity by improving detection rules, use cases, escalation logic, playbooks, investigation guides, and response documentation. It also supports threat hunting, post-incident reviews, stakeholder communication, and remediation tracking to strengthen the organization’s overall detection and response posture. Core Objective Lead SOC investigations, incident response, containment, and remediation while improving detection coverage, response effectiveness, threat hunting outcomes, and SOC operational maturity. The SOC is responsible for continuously monitoring and improving the organization’s security posture by preventing, detecting, analyzing, and responding to cybersecurity incidents using security tools, threat intelligence, defined processes, and operational response capabilities.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed