> Markdown version of [/jobs/ext/2212846-senior-soc-analyst](https://www.wearedevelopers.com/jobs/ext/2212846-senior-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior SOC Analyst - **Company:** FlexTrade Systems, Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Bash Shell, Software as a Service, Cloud Computing Security, Cyber Security, Domain Name System (DNS), Forensics Tools (Digital Forensics Software), Hypertext Transfer Protocols (HTTP), Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Python (Programming Language), Log Analysis, Network Protocols, Windows PowerShell, Red Team (Cyber Security), Security Information and Event Management, TCP/IP, Software Vulnerability Management, Scripting, Google Cloud, Cloud Platform System, Mitre Att&ck, Cyber Threat Analysis, Firewalls (Computer Science), Cybercrime, Microsoft Sentinel, Sumo Logic (Software), Purple Team (Cyber Security), Splunk, Qualys, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** August 24, 2026 - **Apply:** https://www.dice.com/job-detail/66b54d7b-9709-4235-bbd3-15b58f367ea6 ## About the Role 5+ years of hands-on experience in a SOC, security operations, or incident response role. Strong proficiency with SIEM platforms such as Splunk, Microsoft Sentinel, or Sumo Logic. Hands-on experience with EDR solutions such as CrowdStrike Falcon, or Microsoft Defender. Hands-on experience configuring conditional access policies in Entra or another platform. Hands-on experience configuring DLP policies on Purview or another platform. Demonstrated experience triaging and responding to a significant volume of security alerts and incidents. Working knowledge of vulnerability management tools and processes, including scanning, prioritization, and remediation tracking. Solid understanding of network protocols and fundamentals: TCP/IP, DNS, HTTP/S, firewalls, and proxies. Experience analyzing logs across endpoints, networks, cloud environments, and SaaS platforms. Familiarity with the MITRE ATT&CK framework and applying it to investigations and detection engineering. Scripting experience for investigation and automation tasks (Python, PowerShell, or Bash). Strong analytical and problem-solving skills with high attention to detail. Excellent written and verbal communication skills; able to convey technical findings clearly to varied audiences. Preferred Qualifications Experience participating in purple team, red team, or adversary emulation exercises. Background in threat hunting using hypothesis-driven or behavior-based methodologies. Exposure to SOAR platforms and security automation or workflow development. Experience with cloud security telemetry and threat models across AWS, Azure, or Google Cloud Platform. Familiarity with threat intelligence platforms or workflows (e.g., MISP, Recorded Future, OpenCTI). Knowledge of digital forensics tools and techniques (KAPE, Volatility, Velociraptor, etc.). Certifications One or more of the following is required or strongly preferred: Required: CISSP - Certified Information Systems Security Professional Preferred: GIAC GCIH - GIAC Certified Incident Handler Preferred: GIAC GCIA - Intrusion Analyst Preferred: CEH - Certified Ethical Hacker Preferred: CompTIA CySA+ or Security+ Preferred: OSCP, GPEN, or similar offensive/detection-focused certification Preferred: Cloud security certifications: Microsoft SC-200, AWS Security Specialty, or equivalent ## Description We are looking for a technically sharp and driven Senior SOC Analyst to join our cybersecurity team. You will serve as a key individual contributor within the Security Operations Center, owning day-to-day detection, analysis, and response activities while contributing to vulnerability management and purple team exercises. This is a hands-on, practitioner role - you will spend most of your time in the work, not managing it. You will collaborate closely with peers, IT, and engineering teams to identify and contain threats, reduce attack surface, and continuously sharpen our defensive capabilities. The position is primarily on-site (4 days per week at our offices) with one remote day per week., Security Monitoring & Incident Response Monitor, triage, and investigate security alerts across SIEM, EDR, NDR, and cloud platforms, escalating to the SOC Lead as appropriate. Respond to security incidents end-to-end: initial triage, containment, eradication, recovery, and post-incident documentation. Execute and help maintain incident response playbooks and runbooks, flagging gaps and recommending improvements. Conduct root cause analysis following incidents and contribute findings to post-incident reviews. Produce clear, accurate incident reports suitable for both technical and non-technical audiences. Participate in on-call rotation and be available to respond to high-severity incidents outside of business hours when required. Vulnerability Management Perform vulnerability scans and assessments using tools such as Tenable, Qualys, or Rapid7 on a scheduled and ad-hoc basis. Analyze and prioritize vulnerabilities using CVSS scores, threat intelligence, and asset criticality to guide remediation efforts. Track and follow up on remediation progress with IT and engineering teams, escalating stalled items as needed. Contribute to vulnerability reporting, capturing trends, patch compliance rates, and risk reduction metrics. Stay current on newly disclosed CVEs and exploit trends, advising on risk-based prioritization. Purple Teaming & Threat Detection Participate in purple team exercises alongside red team operators to validate detection and response capabilities. Map adversary techniques to the MITRE ATT&CK framework and use exercise findings to identify detection gaps. Write and tune SIEM detection rules, correlation queries, and alerts based on adversary TTPs and purple team outcomes. Conduct threat hunting exercises using hypothesis-driven and ATT&CK-aligned methodologies to surface undetected threats. Track emerging threat actor activity and incorporate relevant TTPs into detection logic and hunting campaigns. Security Operations & Collaboration Analyze logs from a variety of sources including endpoints, firewalls, proxies, cloud platforms, and identity systems. Enrich investigations with threat intelligence, enriching indicators of compromise (IOCs) and correlating activity across data sources. Collaborate with IT and engineering to support security control tuning, reducing false positives and improving signal quality. Maintain accurate and up-to-date SOC documentation including runbooks, knowledge base articles, and escalation procedures. Support compliance activities (e.g., SOC 2, ISO 27001, NIST CSF) by providing evidence and participating in audits as required. Mentor junior analysts by sharing knowledge and providing guidance on investigations and tool usage, without formal management responsibility. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Debunking the Top 10 Myths about Web 3](https://www.wearedevelopers.com/videos/634-debunking-the-top-10-myths-about-web-3) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)