Tier 3 SOC Lead Analyst

Merlin International IncMclean, VA

About The Position

The Security Operations Center (SOC) is responsible for continuous monitoring, threat detection, and incident response across a multi-cloud environment supporting FedRAMP Moderate and High workloads. The team operates dual-stack SIEM architecture (Splunk and SentinelOne) serving customers across AWS, Azure, and GCP. We are expanding the team to deepen our operational capabilities and mature our security posture. We are looking for a Senior SOC Analyst to serve as the T3 Lead, providing shift leadership and technical direction for the operations team. In this role, you will own day-to-day operational decisions, mentor junior analysts, and drive framework alignment across compliance control families. You will work closely with the SOC Manager to coordinate cross-team efforts with Engineering, GRC, and Infrastructure.

Requirements

  • 5+ years of SOC experience with at least 2 years in a senior or lead analyst capacity
  • Deep familiarity with NIST 800-53, FedRAMP control families, and compliance evidence requirements
  • Hands-on experience with SIEM platforms such as Splunk and/or SentinelOne
  • Strong mentorship ability across triage, detection engineering, and incident response
  • Experience operating in multi-cloud environments (AWS, Azure, GCP)

Nice To Haves

  • Experience leading SOC teams through FedRAMP audit cycles
  • Familiarity with MITRE ATT&CK framework and detection coverage mapping
  • Background in detection-as-code practices and version-controlled rule management
  • Experience with SOAR platforms and automated incident response workflows
  • Prior work in a managed security services or multi-tenant SOC environment
  • Ability to operate in a fast-paced, growth-oriented environment
  • Strong collaboration across distributed teams

Responsibilities

  • Provide shift leadership and day-to-day operational direction for the SOC team
  • Lead compliance framework alignment including control evaluation, gap analysis, and NIST 800-53 traceability
  • Drive audit readiness through dry-run assessments, KPI validation, and evidence gap remediation
  • Mentor T1 and T2 analysts on detection methodology, triage procedures, and engineering best practices
  • Coordinate cross-functional dependencies with Engineering, GRC, and Infrastructure teams
  • Contribute to operational planning, transition readiness, and continuous improvement initiatives

Benefits

  • medical, dental, and vision insurance
  • FSA
  • EAP
  • 401(k) with employer match
  • unlimited PTO
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service