> Markdown version of [/jobs/ext/459226-lead-cyber-security-operations-center-csoc-analyst-usds](https://www.wearedevelopers.com/jobs/ext/459226-lead-cyber-security-operations-center-csoc-analyst-usds). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Cyber Security Operations Center (CSOC) Analyst - USDS - **Company:** Tiktok Inc. - **Location:** Sydney, FL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Software as a Service, Cyber Security, Digital Forensics, Perl (Programming Language), Python (Programming Language), Security Information and Event Management, SQL Databases, Scripting, Mitre Att&ck, Malware, Cyber Threat Analysis, Cybercrime - **Published:** June 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1b5986d42248effa ## About the Role Do you have experience in Threat intelligence?, Minimum Qualifications - 5+ years experience handling security-related incidents along with identifying and responding to advanced threats and threat actor TTPs - Excellent communication skills, ability to influence without authority while demonstrating leadership and collaboration skills, in particular in leading or contributing to global and multi-functional analyst SOC teams. - Demonstrated time management, problem-solving, effort prioritization and interpersonal skills as well as the ability to work well to solve problems and meet objectives - Excellent knowledge of industry-standard frameworks (e.g., MITRE ATT&CK) - Strong analytical/problem-solving skills and cross-functional expertise across multiple IT operational and security disciplines with the ability to communicate technical concepts to a broad range of technical and non-technical staff - Must possess a high degree of integrity, be trustworthy, and have the ability to lead and inspire change Preferred Qualifications - GCIA, GCIH, GREM or applicable experience in the Information Security field - One or more programming/scripting languages (e.g., Perl, Java, Python, etc.) / SQL - Experience writing and executing SQL queries - Experience in performing or overseeing static/dynamic malware analysis and performing digital forensics for incident response - High level of SIEM search and use case development/ detection experience - Strong Operating System Administration skills including conceptual knowledge of OS internals and experience with core service types along with strong experience in cloud hosted environments - including UNIX/Linux and Windows environments ## Description About the Team Our Cyber Security Operations Center (CSOC) team is the frontline of defense, responsible for protecting the organization from evolving cyber threats with precision, urgency, and purpose. We're a mission-driven team that thrives in a high-tempo environment-where curiosity, accountability, and continuous improvement are at the core of everything we do. We operate a 24/7 global detection and response program, leveraging cutting-edge tools, advanced threat intelligence, and automation to detect, investigate, and respond to threats at scale. But more than the tech, it's our people that make the difference. We're collaborative, detail-oriented, and deeply committed to safeguarding the business while enabling innovation. As part of our team, you'll not only work on meaningful challenges-you'll shape how Security Operations evolves. From driving detection engineering efforts to mentoring analysts and influencing process improvements, this is where tactical excellence meets strategic impact. Tasks and Responsibilities: - As a Lead SOC Analyst, you'll play a critical role at the intersection of frontline detection, incident response, and strategic defense engineering. This isn't a passive monitoring role-you'll be empowered to lead investigations, shape detection logic, and elevate the SOC's analytical and operational rigor. - Lead high-fidelity investigations from triage to root cause, coordinating incident response efforts across threat surfaces including endpoint, cloud, identity, and SaaS. - Mentor and develop SOC analysts, raising the technical bar through case reviews, scenario-based training, and real-time guidance during critical events. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)