> Markdown version of [/jobs/ext/3409811-soc-incident-response](https://www.wearedevelopers.com/jobs/ext/3409811-soc-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC- Incident Response - **Company:** Noblesoft Technologies - **Location:** Jersey City, NJ, United States - **Experience:** Expert - **Salary:** $104,000.0 - $114,400.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Cyber Security, Data Infrastructure, Linux, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Anti-Phishing, Security Information and Event Management, Software Vulnerability Management, Forensic Toolkit, Scripting, Software Security, Mitre Att&ck, Malware, Cyber Threat Analysis, Cybercrime, Splunk, Security Orchestration, Automation & Response, Servicenow - **Published:** September 27, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0b39ce0b0d519ef3 ## About the Role * Strong understanding of incident response lifecycle, cyber kill chain, MITRE ATT&CK, NIST incident-handling practices, and evidence management. * Hands-on experience investigating Windows, Linux, Active Directory, Entra ID, AWS, Azure, network, endpoint, email, and application security incidents. * Experience with SIEM platforms such as Splunk, EDR/XDR platforms, network telemetry, cloud logs, identity logs, and forensic tools. * Ability to write advanced SPL or equivalent queries for investigation, correlation, and timeline construction. * Experience analyzing phishing, account compromise, malware, ransomware, insider threat, privilege misuse, data exfiltration, web attacks, and cloud compromises. * Knowledge of memory, disk, endpoint, network, and log forensics; familiarity with malware triage and sandbox analysis. * Experience using ServiceNow or similar case-management platforms for incident workflow, evidence, status, and SLA tracking. * Strong knowledge of regulatory, audit, legal-hold, and financial-services incident-reporting considerations. * Ability to automate analysis or enrichment using Python, PowerShell, APIs, SOAR, or scripting is preferred. ## Description 10+ years of experience in SOC services including incident response, digital investigation, SOC escalation, malware analysis, or security operations.. Need some senior candidates with Architect experience., * Serve as an L3 incident response specialist supporting security incidents, escalations, investigations, containment coordination, and post-incident improvement. * Work with Client SOC, infrastructure, application, IAM/PAM, cloud, network, legal, risk, and relevant third parties during security incidents. * Provide subject-matter expertise on complex or high-severity incidents while maintaining clear evidence, timelines, stakeholder updates, and recommendations. * Lead or support investigation of high-severity security incidents across endpoint, identity, network, cloud, email, application, and data environments. * Perform alert validation, scoping, timeline reconstruction, root-cause analysis, impact assessment, and evidence preservation. * Develop containment, eradication, and recovery recommendations; coordinate execution with technology owners rather than assuming infrastructure remediation ownership unless explicitly authorized. * Manage technical war-room activities, investigation workstreams, action tracking, and escalation to Customer incident command. * Prepare executive summaries, detailed investigation reports, lessons learned, and post-incident corrective-action recommendations. * Maintain incident response plans, playbooks, escalation matrices, communication templates, and evidence-handling procedures. * Coordinate with threat intelligence, threat hunting, detection engineering, vulnerability management, and external forensic providers. * Support tabletop exercises, readiness assessments, simulation exercises, and continuous improvement of incident-response processes. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)