L3 SOC Analyst / Incident Response Analyst

2 months ago
Full-time
Senior
Cybersecurity
ProArch

ProArch

At ProArch, we help our clients accelerate growth and mitigate risk with IT services, cybersecurity services, application development, cloud computing, and data analytics. ProArch was founded on the belief that a future where change is ‘business as usu...

Internet Software & Services
251-1K
Founded 2006

Description

  • Lead and support advanced security incident investigations across multiple customer environments.
  • Perform threat triage, IOC analysis, threat correlation, endpoint and identity investigations, email security investigations, and cloud security incident analysis.
  • Investigate and respond to account compromise, BEC, malware, ransomware, privilege escalation, lateral movement, phishing, and social engineering incidents.
  • Coordinate containment, remediation, and recovery activities with customer and internal teams.
  • Provide detailed investigation findings, timelines, impact assessments, and response recommendations.
  • Conduct proactive threat hunting and threat validation activities.
  • Support digital forensics and evidence collection activities when needed.
  • Design, develop, tune, and maintain detection rules, analytics rules, KQL queries, and correlation logic in Microsoft Sentinel and Microsoft Defender XDR.
  • Build and optimize SOC automation workflows using Sentinel playbooks, Logic Apps, SOAR platforms, and API-driven integrations.
  • Maintain investigation playbooks, SOPs, workflow documentation, operational runbooks, and detection documentation while collaborating with SOC, engineering, vendors, and customer stakeholders.

Requirements

  • Bachelor’s degree or graduation in Computer Science, Information Technology, Cybersecurity, or a related technical field is mandatory.
  • 6-9 years of overall cybersecurity experience.
  • Strong hands-on experience in incident response, threat investigation, SOC operations, detection engineering, and DFIR activities.
  • Prior Incident Response Analyst experience is highly preferred.
  • Experience working within MSSP environments is preferred.
  • Experience supporting or collaborating with US-based teams and vendors is preferred.
  • Proven hands-on experience with SOAR platforms in enterprise or MSSP environments.
  • Strong experience designing and implementing SOC automation workflows from scratch.
  • Hands-on experience with Microsoft Sentinel and Defender XDR SIEM operations is mandatory.
  • Strong hands-on experience with Microsoft security platforms including MDE, Defender XDR, MDI, MDO, MDCA, Microsoft Purview, Entra ID / Microsoft Identity Protection, and CrowdStrike Falcon.
  • Strong experience creating detection rules, analytics rules, KQL queries, and tuning detections.
  • Experience with SOC workflow design, SOAR engineering, API integrations, and workflow orchestration.
  • Understanding of MITRE ATT&CK, threat detection methodologies, threat hunting methodologies, and AI-driven attack techniques.
  • Preferred experience with PowerShell, Python, REST APIs, and Logic Apps.
  • KQL is mandatory.
  • Preferred certifications include Microsoft SC-200, SC-401, AZ-500, SC-900, SC-100, CISSP, and SOAR or security automation certifications.
  • Strong verbal and written communication skills and the ability to work across technical and non-technical teams.
  • Ability to work independently in a remote-first, multicultural, fast-paced MSSP environment.
  • Rotational shift availability for US business hours or after hours, with on-call escalation participation when required.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Continuity & Contingency Planning Specialist

Skyepoint Decisions 51-250 Internet Software & Services

SkyePoint Decisions is hiring a fully remote Continuity & Contingency Planning Specialist to support federal systems in maintaining mission-critical operations during disruptions and ensuring continuity documentation aligns with cybersecurity and compliance requirements.

Cybersecurity
6 minutes ago

Incident Response Analyst

Skyepoint Decisions 51-250 Internet Software & Services

SkyePoint Decisions is hiring a fully remote Incident Response Analyst to support federal cybersecurity operations by monitoring, investigating, and responding to security incidents across enterprise, cloud, network, and endpoint environments.

Cybersecurity Linux Palo Alto SIEM Splunk
6 minutes ago

OSINT Trainer and Investigator - Contractor - Burmese speaker - Myanmar

Centre for Information Resilience 11-50 Diversified Consumer Services

Centre for Information Resilience is hiring a remote contractor to support Myanmar Witness’s capacity-building, open-source investigations, and engagement with civil society partners on conflict-related human rights documentation in Myanmar.

21 minutes ago

Client Due Dilligence Analyst (DDQ)

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a DDQ Analyst to support its global sales process by managing client due diligence questionnaires and related compliance workflows for an enterprise SaaS platform.

Cybersecurity
23 hours, 21 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers