> Markdown version of [/jobs/ext/2570461-senior-soc-analyst-tuesday-saturday](https://www.wearedevelopers.com/jobs/ext/2570461-senior-soc-analyst-tuesday-saturday). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior SOC Analyst- Tuesday- Saturday - **Company:** The Bank of New York Mellon Corporation - **Location:** Pittsburgh, PA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software Documentation, Cyber Security, Linux, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Knowledge Management, Network Security, Windows PowerShell, Security Information and Event Management, Data Logging, Scripting, Mitre Att&ck, QRadar, Malware, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Cybercrime, CIS Benchmarks, Purple Team (Cyber Security), Splunk, Servicenow - **Published:** August 4, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18128917?backUrl=%2Fcareer%2F18128917%2FSenior-Soc-Analyst-Tuesday-Saturday-Pennsylvania-Pittsburgh ## About the Role * 6-10; years of experience in a SOC, incident response, or threat detection role, including Tier 2/3 investigations. * Bachelor's degree in Information Security, Computer Science, or a related field - Advanced certifications such as CISSP or CISM are preferred * Advanced proficiency with SIEM (e.g., Splunk, QRadar, Sentinel), EDR (e.g., CrowdStrike, Microsoft Defender), and SOAR platforms. * Strong knowledge of network security, Windows/Linux, identity systems, and common cloud logging sources. * Hands-on experience with the MITRE ATT&CK framework, threat hunting, IOC/IOA development, and detection tuning. * Demonstrated ability to lead complex incidents, coordinate stakeholders, and communicate clearly under time pressure. * Scripting or automation experience (e.g., Python, PowerShell) for investigation enrichment and workflow improvements. * Familiarity with NIST CSF/800-61, CIS Controls, and common regulatory requirements impacting incident response. * Excellent documentation skills and an evidence-driven approach to investigations. Preferred Qualifications * Relevant certifications: GCIA, GCED, GCIH, GCFA, GNFA, CISSP, CCSP, or equivalent experience. * Experience with ticketing and case management systems (e.g., ServiceNow) and knowledge management practices. * Prior experience with threat intel platforms, sandboxing tools, and malware triage is a plus. ## Description We're seeking a future team member for the role of Senior SOC Analyst to join our Security Operations Center team. This role can be in Pittsburgh PA or Lake Mary FL. Schedule: Tuesday-Saturday., * Lead triage and investigation of security alerts, escalating and coordinating incident response as needed. * Perform root cause analysis, scope affected assets, and drive containment, eradication, and recovery. * Correlate events across SIEM, EDR, IDS/IPS, firewalls, cloud logs, and identity platforms to identify true positives and reduce false positives. * Develop, refine, and maintain SOC playbooks, runbooks, and detection logic aligned to the MITRE ATT&CK framework. * Mentor junior analysts and provide guidance on investigation techniques, documentation standards, and operational best practices. * Coordinate with Threat Intelligence to enrich investigations, track adversary TTPs, and proactively hunt for indicators of compromise. * Partner with Engineering teams to tune detections, improve log fidelity, and strengthen preventive controls. * Create clear, actionable incident reports and executive summaries; contribute to metrics and trend analysis. * Support purple team exercises and post-incident reviews to capture lessons learned and drive continuous improvement. * Ensure adherence to regulatory and security policies; maintain audit-ready documentation for investigations and incidents. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)