> Markdown version of [/jobs/ext/3093534-senior-security-operations-center-soc-analyst](https://www.wearedevelopers.com/jobs/ext/3093534-senior-security-operations-center-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Operations Center (SOC) Analyst - **Company:** ISO New England - **Location:** Holyoke, MA, United States - **Experience:** Expert - **Salary:** $115,000.0 - $142,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Microsoft Azure, Bash Shell, Network Analysis, Cloud Computing Security, Linux, Digital Forensics, Domain Name System (DNS), Hypertext Transfer Protocols (HTTP), Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Log Analysis, Simple Mail Transfer Protocols, Network Monitoring, Network Protocols, Windows PowerShell, Program Analysis, ArcSight SIEM Tool, Security Information and Event Management, TCP/IP, Wireshark, Software Vulnerability Management, Forensic Toolkit, Scripting, Google Cloud, Cloud Platform System, Mitre Att&ck, QRadar, Malware, Cyber Threat Analysis, Firewalls (Computer Science), Cybercrime, Microsoft Sentinel, Cortex XSOAR Platform, Purple Team (Cyber Security), ArcSight Event Correlation, Encase, Splunk, SentinelOne Expertise - **Published:** September 26, 2026 - **Apply:** https://www.careerjet.com/job/us20d510b0a81afca132004fd6927f9325/eaa ## About the Role * Self-starter mindset with strong ownership, accountability, and professional judgment. * Proven ability to remain calm and decisive under pressure in incidents impacting critical infrastructure. * Strong analytical, problem solving, and critical thinking skills. * Excellent written and verbal communication, with the ability to explain complex issues clearly. * Commitment to continuous learning and staying current with evolving threats and technologies. Critical Infrastructure SOC Competencies: * Composure under pressure: Ability to remain calm, focused, and methodical during high-severity incidents where decisions directly impact grid reliability and public safety * Mission-driven mindset: Deep understanding of the responsibility that comes with defending critical infrastructure essential to national security and public welfare * Rapid triage and prioritization: Ability to quickly assess multiple simultaneous alerts and threats, making rapid decisions on priority and resource allocation * Situational awareness: Continuous awareness of the operational environment, threat landscape, and potential cascading impacts of security events on critical systems * Team coordination: Skill in working seamlessly with cross-functional teams including IT, OT, engineering, and leadership during incident response * Clear communication under stress: Ability to convey technical information accurately and concisely to diverse stakeholders while managing active incidents, * Relevant certifications such as GCIA, GCIH, GCFA, GREM, CISSP, CySA+, or equivalent * Experience in critical infrastructure or energy sector environments * Background in threat hunting or offensive security concepts * Familiarity with NERC CIP compliance requirements * Experience with SOAR platforms (Splunk SOAR, Palo Alto XSOAR, Swimlane) * Knowledge of OT/ICS security concepts This employer will not sponsor applicants for work visas for this position (ex: H-1B, F-1/CPT/OPT, O-1, E-3, TN, J, etc.). ## Description * Operate independently with minimal supervision to detect, analyze, and respond to complex security threats in a fast paced, mission critical SOC environment supporting electric grid operations. * Lead response efforts for high severity and complex security incidents, coordinating containment, eradication, and recovery across IT, OT, and engineering teams. * Apply threat modeling techniques to anticipate adversary attack paths, inform detection strategy, and improve defensive coverage across critical infrastructure systems. * Perform advanced threat detection and analysis using SIEM, EDR/XDR, network monitoring, and forensic tools. * Conduct malware analysis, digital forensics, and root cause investigations following security events affecting critical systems. * Develop, tune, and maintain detection rules, correlation logic, and automated response playbooks to continuously improve SOC effectiveness. * Coordinate tabletop exercises, purple team activities, and grid focused security assessments. * Mentor and train junior SOC analysts, providing guidance on investigation techniques, tools, and best practices. * Serve as the project implementor for SOC-related initiatives, partnering with the PMO to plan, coordinate, and execute corporate security projects impacting SOC operations. What we are looking for * SIEM platforms (Splunk, QRadar, ArcSight, Microsoft Sentinel, or similar) * EDR/XDR solutions (CrowdStrike, Carbon Black, Microsoft Defender, SentinelOne, or similar) * Network analysis tools (Wireshark, Zeek, tcpdump) * Forensic tools and techniques (EnCase, FTK, Volatility, Autopsy) * Attack frameworks such as MITRE ATT&CK and the Cyber Kill Chain * Threat actor tactics, techniques, and procedures (TTPs) * Threat intelligence frameworks and indicators of compromise (IOCs) * Network protocols (TCP/IP, DNS, HTTP/S, SMTP, SMB) * Firewalls, IDS/IPS, and proxy technologies * Windows and Linux operating systems (administration and security hardening) * Cloud environments (AWS, Azure, GCP) and cloud security principles * Scripting languages (Python, PowerShell, Bash) * Malware analysis techniques (static and dynamic analysis) * Log analysis and event correlation * Vulnerability management concepts ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)