> Markdown version of [/jobs/ext/254094-senior-soc-analyst](https://www.wearedevelopers.com/jobs/ext/254094-senior-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior SOC Analyst - **Company:** N-able - **Location:** Morrisville, NC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Intrusion Detection Systems, Security Information and Event Management, Cloud Platform System - **Published:** May 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fb74d0ff28ed00ca ## About the Role Do you have experience in Technical Proficiency?, Do you have a Bachelor's degree?, * 4-6 years of experience in SOC, Managed Detection Response, or equivalent cybersecurity role. * Proven experience handling escalations and complex investigations. * Bachelor's degree in Cybersecurity, IT, or related field (or equivalent experience). * Advanced knowledge of SOC operations, incident support, and analysis techniques. * Ability to mentor and support less experienced analysts. * Excellent communication skills for both technical and non-technical audiences. * High proficiency with SIEM, IDS/IPS, EDR, and related tools. * Analytical and detail-oriented with a passion for solving problems. * Strong mentor and team player. * Calm and dependable under high-pressure situations. * Ethical, professional, and dedicated to customer security. * Ability to work on a 24/7 shifting model. The standard shift is 3pm-11pm EST, either Tuesday-Saturday or Sunday-Thursday. ## Description The Senior SOC Analyst is an experienced cybersecurity professional responsible for handling complex and high-priority security inquiries, incidents, and service requests. Acting as a technical expert and mentor to Analysts, the Senior SOC Analyst plays a crucial role in ensuring swift and accurate resolutions, guiding technical topics, and serving as a critical escalation point. Please note that this role is on-site, therefore working in the Morrisville Collaboration Hub 3+ times per week is required. The standard shift is 3pm-11pm EST, either Tuesday-Saturday or Sunday-Thursday. What You'll Do: * Lead IH engagements from containment through eradication and recovery planning. * Provide technical and procedural guidance to customers during active incidents. * Conduct root-cause analysis and determine long-term remediation steps. * Perform deep-dive analysis of attacker TTPs, persistence mechanisms, and lateral movement. * Review forensic artifacts from endpoints, networks, and cloud environments. * Correlate indicators of compromise to broader attack campaigns and threat actors. * Act as a primary point of contact for customers during incident engagements. * Deliver technical findings and recommendations to both technical and executive stakeholders. * Provide remediation roadmaps tailored to customer environments. * Partner with operational MDR team analysts to transition containment into IH workflows. * Collaborate with operational MDR Teams for intelligence gathering and validation. * Contribute to IH playbook development and improvement. * Provide mentorship and peer review for junior analysts. * Share lessons learned with SOC leadership to improve service delivery. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [Cloud Vendor Lock-In - Is it just a new version of the Database Abstraction Layers?](https://www.wearedevelopers.com/videos/1185-cloud-vendor-lock-in-is-it-just-a-new-version-of-the-database-abstraction-layers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)