via Dice
$60K - 120K a year
Perform advanced alert triage, investigation, and incident analysis to improve SOC detection and response capabilities.
Requires 6+ years in security operations with strong investigation skills, cloud security experience, and ability to mentor junior analysts.
Title: Sr. Analyst, SOC End Date: # of Openings: 1 Position Type: Contract to Hire Locations: Louisville, Additional Details: 6 months CTH 100% Remote Description: Summary: We are seeking a Senior Security Analyst to strengthen and mature Security Operations (SOC) detection and response capabilities across enterprise, cloud, and third-party environments. This role is accountable for advanced alert triage, investigation, and incident analysis. The Senior Security Analyst partners closely with the incident response team, IT, and engineering teams to improve signal quality, close detection gaps, and strengthen operational readiness. The ideal candidate is a senior individual contributor with strong investigation skills, excellent judgment under pressure, and the ability to translate attacker behavior and telemetry into actionable response and detection improvements. Responsibilities: • Performing threat-informed analysis of alerts and events, validating severity, scope, and business impact • Applying threat intelligence and adversary tradecraft to prioritize, contextualize, and enrich investigations • Identifying patterns of attacker behavior and emerging threats; translating findings into detection and response improvements • Conducting advanced alert triage, investigation, and escalation across endpoint, network, identity, SaaS, and cloud telemetry • Investigating identity, access, and configuration-related alerts (e.g., anomalous sign-ins, privilege changes, suspicious OAuth/app consent, policy changes) • Supporting incident investigation and response activities, including containment recommendations and responder handoffs • Collecting, preserving, and analyzing evidence; producing clear documentation suitable for incident reviews and potential legal/compliance needs • Tuning detections and improving signal quality by reducing false positives, improving fidelity, and expanding meaningful coverage • Analyzing detection gaps and control weaknesses surfaced through investigations; partnering with control owners to drive remediation • Validating detection effectiveness through testing, simulation, and structured attack emulation; documenting outcomes and follow-ups • Contributing to post-incident reviews, lessons learned, and playbook/runbook updates • Driving continuous improvement of SOC processes, metrics, and operational readiness; mentoring other analysts as needed Requirements: • 6 years in security operations, incident response, or threat detection, with demonstrated ownership of complex investigations • Strong experience triaging and investigating alerts across SIEM, EDR/XDR, identity platforms, and cloud/SaaS environments • Proficiency with investigation workflows: hypothesis-driven analysis, scoping, timeline creation, and clear escalation/handoff • Hands-on ability to query and analyze telemetry and turn findings into actionable outcomes • Practical knowledge of attacker techniques and common enterprise attack paths (identity compromise, lateral movement, persistence, exfiltration) • Experience applying threat intelligence (IOCs/TTPs) to investigations and to improve detection content • Strong written and verbal communication skills, including producing incident documentation appropriate for technical and leadership audiences • Ability to influence and collaborate across teams (IT, cloud, infrastructure, engineering) and mentor junior members Required Skills: • Detection and hunting experience • Cloud security operations experience in Google Cloud Platform, including investigation of cloud control plane and SaaS audit logs • Hands-on incident response experience (on-call/rotations), including coordination, containment support, and recovery validation • Scripting/automation skills to enrich investigations and improve SOC efficiency Preferred Skills: • Leading complex investigations from initial alert through containment recommendations, escalation, and handoff • Correlating endpoint, network, identity, cloud, and SaaS telemetry to validate attacker behavior and determine scope • Enriching cases with threat intelligence and internal context to prioritize response and reduce time-to-decision • Tuning detections and building investigation queries to improve fidelity and reduce repeat noise • Partnering with MSSP and internal incident response team members, IT, and engineering teams to close gaps discovered during investigations • Running targeted threat hunts and validation exercises to confirm detection coverage and document results • Updating playbooks/runbooks and coaching other analysts on investigation quality, documentation, and escalation standards Benefits: This role offers hands-on security operations work focused on advanced investigations, incident analysis, and continuous improvement of detection and response across the environment.
This job posting was last updated on 9/28/2026