> Markdown version of [/jobs/ext/257793-senior-soc-analyst](https://www.wearedevelopers.com/jobs/ext/257793-senior-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior SOC Analyst - **Company:** POLYMARKET CLEARING LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $150,000.0 - $210,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing Security, Cyber Security, Computer Networks, Domain Name System (DNS), Hypertext Transfer Protocols (HTTP), Python (Programming Language), Blockchain, Phishing, Kusto Query Language, Security Information and Event Management, TCP/IP, Mitre Att&ck, Cyber Threat Analysis, Purple Team (Cyber Security), SentinelOne Expertise - **Published:** May 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1564a60a1931aeea ## About the Role Do you have experience in Threat intelligence?, * 2+ years of hands-on SOC, incident response, or security operations experience * Proficiency with a SIEM platform (Palo Alto XSIAM preferred) * Experience with EDR/XDR tooling (CrowdStrike, SentinelOne, or equivalent) * Demonstrated ability to triage alerts including phishing, malware, lateral movement, and credential-based attacks * Solid understanding of TCP/IP, DNS, HTTP/S, and common attack patterns * Ability to read and write basic scripts or queries (Python, Bash, KQL, or SPL) to support analysis * Availability for rotating shifts and participation in on-call rotation * (Plus) Experience managing escalations to or from an MSSP or third-party SOC * (Plus) Certifications such as CompTIA CySA+, GCIA, GCIH, or equivalent * (Plus) Familiarity with cloud security tooling in AWS, GCP, or Azure * (Plus) Knowledge of the blockchain, DeFi, or crypto-sector threat landscape * (Plus) Experience with MITRE ATT&CK-based threat hunting or purple team exercises ## Description Polymarket is looking for a SOC Analyst to join our internal security operations team. You'll be responsible for monitoring, triaging, and responding to security events across our environment - working alongside fellow in-house analysts and coordinating with our contracted 24/7 third-party SOC provider, serving as the escalation point for confirmed or ambiguous threats that require institutional context and hands-on response., * Monitor SIEM, EDR, NDR, and cloud security tooling for alerts, anomalies, and indicators of compromise; review and triage escalations from the third-party SOC provider * Conduct proactive threat hunting using intelligence feeds, MITRE ATT&CK TTPs, and hypothesis-driven queries * Lead containment, eradication, and recovery for confirmed incidents; coordinate with Engineering, Legal, and Leadership on high-severity events * Respond to on-call pages per the team rotation schedule; write clear incident reports covering timeline, impact, root cause, and corrective actions * Analyze malware samples, phishing campaigns, network traffic, and endpoint artifacts to determine scope and attacker TTPs * Identify detection gaps and propose new SIEM rules, correlation logic, and tuning improvements * Author and maintain SOC runbooks and playbooks used by both in-house and third-party teams; contribute to weekly/monthly reporting on incident trends and third-party SLA adherence ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)