> Markdown version of [/jobs/ext/1783312-security-operations-center-soc-analyst-l3](https://www.wearedevelopers.com/jobs/ext/1783312-security-operations-center-soc-analyst-l3). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Center (SOC) Analyst L3 - **Company:** Xerox - **Location:** Norwalk, CT, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Data Analysis, ARM Architecture, Cyber Security, Linux, Digital Forensics, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Machine Learning, Network Forensics, Security Information and Event Management, SQL Databases, Scripting, Cloud Platform System, Information Technology, Cybercrime - **Published:** July 7, 2026 - **Apply:** https://xerox.avature.net/en_US/careers/Login?jobId=51401 ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related technical discipline, or an equivalent combination of education and experience. * Four or more years of Security Operations Center (SOC) or Incident Response experience, including ownership of complex, multi-stage investigations. * Experience working within AI- or Machine Learning-enabled detection environments. * Expertise in digital forensics, threat hunting, SIEM, XDR, SOAR, and security incident response. * Advanced knowledge of Linux and Windows operating systems, scripting with Python, and SQL for data analysis and automation. * Experience with Cortex XSIAM or similar security platforms is preferred. * Strong analytical, problem-solving, communication, and decision-making skills, with the ability to explain technical concepts to both technical and non-technical audiences. * Industry certifications such as GCFA, GCIH, GNFA, GREM, or equivalent are considered an asset. ## Description Xerox is seeking a highly skilled and analytical Cybersecurity Operations Analyst III to join our Threat Detection & Response (TD&R) team. As the senior technical escalation point within the Security Operations Center (SOC), you will lead the investigation of the organization's most complex cybersecurity incidents, drive advanced threat hunting initiatives, and partner with Detection Engineering and Machine Learning teams to strengthen detection capabilities. This role is ideal for an experienced cybersecurity professional who thrives in a fast-paced environment, enjoys solving sophisticated security challenges, and is passionate about mentoring others while advancing security operations. Why Join This Team: * Protect Xerox by leading investigations into sophisticated cyber threats across a global enterprise. * Work with advanced cybersecurity technologies, including AI-enabled detection, SOAR automation, SIEM, XDR, and threat intelligence platforms. * Partner with Detection Engineering, Machine Learning, Incident Response, and IT teams to continuously improve security capabilities. * Influence the future of security operations through automation, threat hunting, and detection strategy. * Join an inclusive team committed to continuous learning, innovation, and technical excellence. What You Will Do: * Lead end-to-end investigations of complex, high-severity cybersecurity incidents across endpoints, networks, identity platforms, and cloud environments. * Perform advanced memory, endpoint, and network forensic analysis to determine root cause and attacker activity. * Conduct proactive, hypothesis-driven threat hunting using multiple telemetry sources and threat intelligence. * Validate AI-generated detections, identify systemic false-positive trends, and provide structured feedback to Detection Engineering and Machine Learning teams. * Design and enhance SOAR automations with appropriate validation, observability, rollback capabilities, and human oversight. * Develop scripts and automation using Python and SQL to improve investigative efficiency and operational workflows. * Make risk-based containment decisions and coordinate incident response activities with CSIRT, IT, and business stakeholders. * Mentor SOC Analysts and contribute to technical documentation, knowledge sharing, quality reviews, and analyst development programs. * Continuously improve detection logic, playbooks, and operational processes based on lessons learned from investigations and threat hunting activities. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)