Enter a job title or keyword

Sr. Analyst, SOC


Job Location:

Chicago, IL - USA

Monthly Salary: Not provided by the employer
Posted: 24 September 2026 (10 hours ago)
Application Deadline: 22 December 2026
Vacancies: 1 Vacancy

Job Summary

Title: Sr. Analyst SOC
End Date:
# of Openings: 1
Position Type: Contract to Hire
Locations: Louisville
Additional Details:

6monthsCTH
Visa Independent Candidates Only
100%Remote


Description:

Summary:

We are seeking a Senior Security Analyst to strengthen and mature Security Operations (SOC) detection and response capabilities across enterprise cloud and third-party environments. This role is accountable for advanced alert triage investigation and incident analysis. The Senior Security Analyst partners closely with the incident response team IT and engineering teams to improve signal quality close detection gaps and strengthen operational readiness. The ideal candidate is a senior individual contributor with strong investigation skills excellent judgment under pressure and the ability to translate attacker behavior and telemetry into actionable response and detection improvements.

Responsibilities:
  • Performing threat-informed analysis of alerts and events validating severity scope and business impact
  • Applying threat intelligence and adversary tradecraft to prioritize contextualize and enrich investigations
  • Identifying patterns of attacker behavior and emerging threats; translating findings into detection and response improvements
  • Conducting advanced alert triage investigation and escalation across endpoint network identity SaaS and cloud telemetry
  • Investigating identity access and configuration-related alerts (e.g. anomalous sign-ins privilege changes suspicious OAuth/app consent policy changes)
  • Supporting incident investigation and response activities including containment recommendations and responder handoffs
  • Collecting preserving and analyzing evidence; producing clear documentation suitable for incident reviews and potential legal/compliance needs
  • Tuning detections and improving signal quality by reducing false positives improving fidelity and expanding meaningful coverage
  • Analyzing detection gaps and control weaknesses surfaced through investigations; partnering with control owners to drive remediation
  • Validating detection effectiveness through testing simulation and structured attack emulation; documenting outcomes and follow-ups
  • Contributing to post-incident reviews lessons learned and playbook/runbook updates
  • Driving continuous improvement of SOC processes metrics and operational readiness; mentoring other analysts as needed
Requirements:
  • 6 years in security operations incident response or threat detection with demonstrated ownership of complex investigations
  • Strong experience triaging and investigating alerts across SIEM EDR/XDR identity platforms and cloud/SaaS environments
  • Proficiency with investigation workflows: hypothesis-driven analysis scoping timeline creation and clear escalation/handoff
  • Hands-on ability to query and analyze telemetry and turn findings into actionable outcomes
  • Practical knowledge of attacker techniques and common enterprise attack paths (identity compromise lateral movement persistence exfiltration)
  • Experience applying threat intelligence (IOCs/TTPs) to investigations and to improve detection content
  • Strong written and verbal communication skills including producing incident documentation appropriate for technical and leadership audiences
  • Ability to influence and collaborate across teams (IT cloud infrastructure engineering) and mentor junior members
Required Skills:
  • Detection and hunting experience
  • Cloud security operations experience in GCP including investigation of cloud control plane and SaaS audit logs
  • Hands-on incident response experience (on-call/rotations) including coordination containment support and recovery validation
  • Scripting/automation skills to enrich investigations and improve SOC efficiency
Preferred Skills:
  • Leading complex investigations from initial alert through containment recommendations escalation and handoff
  • Correlating endpoint network identity cloud and SaaS telemetry to validate attacker behavior and determine scope
  • Enriching cases with threat intelligence and internal context to prioritize response and reduce time-to-decision
  • Tuning detections and building investigation queries to improve fidelity and reduce repeat noise
  • Partnering with MSSP and internal incident response team members IT and engineering teams to close gaps discovered during investigations
  • Running targeted threat hunts and validation exercises to confirm detection coverage and document results
  • Updating playbooks/runbooks and coaching other analysts on investigation quality documentation and escalation standards
Benefits:

This role offers hands-on security operations work focused on advanced investigations incident analysis and continuous improvement of detection and response across the environment.


Required Skills:

SOCIncident Response