Search
Header navigation
SOC 3 Analyst

SOC 3 Analyst

PublishedPublished: Published today

Summary

The Security Senior Analyst role is responsible for managing services for Managed Security Service customers. The Security Specialist has the remit of assessing, discovering and directing remediation of security threats & vulnerabilities within client environments whilst working as part of a managed security team on various cyber security projects and tasks.

This role involves working at all levels with Solution Architects, Development Operations, Engineers, SOC Analysts, clients and other stakeholders in building and managing security architecture and systems which are kept up-to-date and relevant in the rapidly evolving Managed Security Services industry.

This is a senior technical SOC role and the role holder is expected to provide Tier 3 analysis, advanced investigation, threat hunting, forensic support and technical leadership for complex or critical incidents. The role also supports mentoring, service improvement, playbook evolution and close collaboration with clients, internal teams, channel partners and vendors.

Essential Duties and Responsibilities

  • Handles internal and client escalations by engaging with key stakeholders.

  • Follows & oversees that the team follows published SOC policies and procedures.

  • Acts as subject matter expert across Managed Security Service and be able to clearly articulate deliverables, limitations, feasibility, etc.

  • Demonstrates thorough experience of the configuration, tuning and maintenance of SOC tools to improve detection capability and building re-usable visualisations / dashboards for security alert triage, threat hunting and similar use cases, etc.

  • Develops Standard Operating Procedures (SOPs) and use cases for monitoring and handling different types of security events.

  • Performs Threat intelligence gathering to ensure that detection methods are effective against current threats.

  • Hunts for suspicious activity based on anomalous activity.

  • Handles events as part of the Security Incident Management Process.

  • Works with both internal and external partners to investigate and advise on security incidents and anomalies.

  • Prepares detailed reports, providing information on findings, status and progress of investigations, as well as vulnerability and risk factors.

  • Serves as the senior technical escalation point and mentor for colleagues.

  • Produces incident response playbooks to drive a consistent approach to handling common incidents and improve operational processes.

  • Analyzes structured security log data through the creation of aggregated / correlated reports or visualizations.

  • Identifies and implements opportunities for innovative and continuous improvement.

  • Leads on customer incident response investigations and containment of threats, advising on remediation.

  • Participates in the Security Operations Centre on-call rotation.

  • Demonstrates and actively promotes an understanding and commitment to the mission of Logicalis through performing behaviors consistent with the organization's values.

  • Maintains a working knowledge of applicable Federal, State, and Local laws and regulations as well as policies and procedures of Logicalis in order to ensure adherence in a manner that reflects honest, ethical and professional behaviors.

  • Supports and conducts self in a manner consistent with customer service expectations.

Supervisory Responsibilities

This job has no supervisory responsibilities.

Qualifications

To perform this job successfully, an individual should be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Education/Experience/Technical Requirements/Certifications

Equivalent combination accepted.

Education:

  • Bachelor’s Degree in a related field.

Experience / Technical Requirements

  • Previous hands-on experience working in SOC environments is mandatory.

  • Experience working within managed services, including SLAs, KPIs, operational reporting, customer escalations and continuous service improvement.

  • Strong experience in incident response, complex investigation, threat hunting and advanced security analysis.

  • Forensics experience is mandatory for this role, including endpoint, network or cloud investigation scenarios.

  • Experience with forensic tooling and investigation techniques such as evidence collection, timeline analysis, artefact review and root-cause analysis.

  • Experience with SIEM platforms such as Microsoft Sentinel and/or Splunk.

  • Knowledge of MITRE ATT&CK, detection engineering, EDR/XDR technologies and incident response frameworks.

  • Experience with Cisco XDR, Microsoft Defender is a strong plus.

  • Experience with MISP, n8n or SOAR platforms is a plus.

  • Ability to act as a senior escalation point, lead technical investigations and support customers during complex or critical incidents.

  • Excellent written and oral communication skills, including executive-level incident reporting and clear remediation guidance.

  • Strong analytical mindset, ability to work under pressure and commitment to continual service improvement.

Certifications

  • Certifications from Microsoft, Splunk and GIAC are highly valued, for example Microsoft SC-200, Microsoft SC-100, Splunk Core Certified Power User, Splunk Enterprise Certified Admin, GIAC GCIH, GCIA, GCFA, GNFA, GREM or GCTI. Other relevant certifications such as CompTIA CySA+, CISSP, CISM or equivalent are also valued.

Other Skills and Abilities

  • Typically 5+ years of experience in cybersecurity, including significant experience in SOC, MSSP or mature internal security operations environments.

  • Hands-on experience analyzing security logs from SIEM, EDR/XDR, endpoint, identity, cloud and network security sources.

  • Experience with Microsoft Sentinel and/or Splunk is highly valued.

  • Experience with Cisco XDR, MISP, n8n and security automation/orchestration is highly valued.

  • Experience with Azure and/or AWS security monitoring is valued.

  • Awareness of security standards and frameworks such as ISO 27001, NIST, MITRE ATT&CK and common vulnerability management practices.

Physical Demands

The physical demands described here are representative of those that should be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

While performing the duties of this Job, the employee is constantly required to sit, talk, see, hear, and use hands and arms. The employee is frequently required to stand; move about, climb steps or balance and stoop, kneel, crouch, or crawl. The employee may occasionally lift and/or move up to 10 pounds.

The above statements describe the general nature and level of work being performed by individuals assigned to this classification. This is not intended to be an exhaustive list of all responsibilities and duties required of personnel so classified.

Logicalis is an Equal Opportunity Employer. It is our policy to employ people who are qualified by reason of education, training, experience, and demonstrated performance. We value inclusion and belonging at our company. We do not discriminate on the basis of race, color, religion, national origin, sexual orientation, gender identity and gender expression, marital status, age, height, weight, disability, veteran status, or any other reason prohibited by applicable federal or state laws.

NOTE: It is Logicalis’ practice that when a client requires medical testing, the employee must accept that requirement as a condition of their assignment and either submit to the tests or show proof they’ve completed the test satisfactorily (i.e., TB Test negative).

Salary Compensation Range: $77,517 - $100,000/yr.



LogicalisUS Benefits Summary

Fields of study

  • Cybersecurity
  • Engineering

Required skills

  • Incident Management
  • Security Incident Management
  • Vulnerability Management
  • Security Architecture
  • Customer Service
  • Network Security
  • Security Monitoring
  • Threat Intelligence
  • Automation
  • AWS
  • Azure
  • Channel Partners
  • Communication Skills
  • Threat Hunting
  • Risk
  • Incident Response
  • Functions
  • ISO 27001
  • Operational Reporting
  • Reporting
  • Managed Services
  • Microsoft Sentinel
  • Sentinel
  • NIST
  • Splunk
  • Timeline

Image gallery

Video gallery

Consent to this service

YouTube Video

Consent to this service

YouTube Video

Consent to this service

YouTube Video
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...