> Markdown version of [/jobs/ext/1247301-sr-security-operations-center-analyst](https://www.wearedevelopers.com/jobs/ext/1247301-sr-security-operations-center-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr Security Operations Center Analyst - **Company:** TQL - **Location:** Cincinnati, OH, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Microsoft Azure, Cloud Computing, Cyber Security, Linux, Identity and Access Management, Intrusion Detection and Prevention, Windows PowerShell, Phishing, Security Information and Event Management, Software Vulnerability Management, Scripting, Mitre Att&ck, Malware, Cyber Threat Analysis, Azure Security Center, Information Technology, Microsoft Sentinel, SentinelOne Expertise, Security Orchestration, Automation & Response - **Published:** July 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3f84b9786aa261be ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field preferred; equivalent experience and industry certifications will be considered. * 5+ years of experience in Security Operations, Incident Response, or a related cybersecurity role. * Experience investigating malware, phishing, ransomware, insider threats, and other cybersecurity incidents. * Strong experience with SIEM platforms, security analytics, and log management technologies. * Hands-on experience with Endpoint Detection and Response (EDR) platforms such as Microsoft Defender for Endpoint, CrowdStrike, or SentinelOne. * Experience securing and monitoring Microsoft Azure and Microsoft 365 environments. * Strong understanding of networking, Windows and Linux operating systems, Active Directory, identity security, and cloud infrastructure. * Experience with vulnerability management, threat intelligence, and modern incident response frameworks such as MITRE ATT&CK and NIST. * Experience with Microsoft Sentinel, SOAR platforms, PowerShell or Python scripting, and security automation is a plus. * Industry certifications such as Security+, CySA+, GCIH, GCIA, CISSP, Microsoft SC-200, or AZ-500 are preferred. * Strong analytical, troubleshooting, communication, and problem-solving skills with the ability to effectively communicate complex security issues to technical and non-technical audiences. ## Description As a Senior Security Operations Center (SOC) Analyst at TQL, you'll help protect one of the nation's largest freight brokerage technology environments by leading the detection, investigation, and response to cybersecurity threats. You'll partner with Infrastructure, Engineering, and Technology teams to strengthen TQL's security posture, improve detection capabilities, and respond to complex security incidents. This role is ideal for an experienced cybersecurity professional who enjoys solving complex problems, mentoring others, and continuously improving security operations. What you'll be doing: * Monitor, investigate, and respond to security alerts and incidents across cloud, endpoint, network, and identity environments. * Lead incident response activities, including investigation, containment, eradication, recovery, root cause analysis, and post-incident documentation. * Perform proactive threat hunting and leverage threat intelligence to identify emerging threats and improve detection capabilities. * Develop, tune, and maintain SIEM detection rules, security monitoring content, and incident response playbooks. * Monitor endpoint detection and response (EDR) tools to identify, investigate, and remediate malicious activity. * Partner with Infrastructure and Engineering teams to identify, prioritize, and remediate security vulnerabilities. * Serve as an escalation point for complex security investigations while mentoring junior SOC analysts and contributing to process improvements and security automation. * Communicate technical findings and security risks to both technical and business stakeholders and support security audits and compliance initiatives. ## Related Videos - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)