Resource Logistics Inc.
Staffing & Recruiting
See how your profile stacks up against this role.
We compared the job requirements to your profile to show where you're strong and where you fall short.
Job Title: SOC Senior Analyst
Location: REMOTE
Mode : Contract (6+ Months)
The SOC Senior Analyst / Incident Response Specialist is a senior-level cybersecurity expert responsible for advanced incident investigation, threat hunting, digital forensic analysis, and incident response leadership within Client’s managed Security Operations Center (SOC) – ClientR model. This role is pivotal in defending customer environments from evolving cyber threats, ensuring robust detection coverage, and mentoring the next generation of cyber defenders, thus directly contributing to the organization’s security posture and client trust.
Key Responsibilities
• Lead deep-dive investigations of escalated security incidents, reconstructing attack chains and correlating multi-source telemetry.
• Execute forensic triage of hosts, memory, disks, and logs, preserving evidence and providing comprehensive analysis for legal or regulatory needs.
• Design and conduct hypothesis-driven and intelligence-led threat hunts using frameworks such as MITRE Telecommunication&CK.
• Act as incident commander for high-severity events, coordinating containment, eradication, and recovery efforts with customer and internal teams.
• Develop and tune SIEM/EDR/XDR detections, authoring advanced use cases that improve detection efficacy and reduce false positives.
• Define, review, and validate SOAR (Security Orchestration, Automation, and Response) playbooks and automation workflows.
• Integrate threat intelligence into SOC operations, contextualizing incidents and managing the IOC lifecycle.
• Produce detailed root-cause analysis and lessons-learned reports, driving continuous improvement in detection and response processes.
• Audit L1/L2 analyst work, provide targeted coaching, and uphold quality assurance standards across the SOC.
• Mentor junior analysts, deliver knowledge transfer sessions, and contribute to internal training and capability building.
• Represent the SOC in customer governance and post-incident review forums, presenting incident trends and improvement actions.
• Participate in adversary emulation and purple-team exercises, translating findings into actionable detection and response enhancements.
Required Skills & Experience
• Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Engineering, or equivalent practical experience; Master’s preferred.
• 7–10+ years of hands-on experience in SOC/Cyber Defense operations, with at least 3–4 years at L2/L3, incident response, or threat hunting depth.
• Expertise across the incident lifecycle: detection, triage, investigation, containment, eradication, recovery, and post-incident review.
• Deep proficiency in SIEM technologies (e.g., Splunk, Microsoft Sentinel), EDR/XDR platforms (e.g., CrowdStrike, Microsoft Defender), and forensic tools (e.g., Volatility, KAPE, Autopsy).
• Advanced knowledge of Windows and Linux internals, identity security (AD, Entra ID), cloud security (Clienture, AWS, GCP), and network security telemetry.
• Experience designing and executing threat hunts mapped to MITRE Telecommunication&CK and related frameworks.
• Strong scripting and data querying skills (Python, PowerShell, KQL, SPL, Bash).
• Familiarity with security standards such as NIST 800-61, NIST CSF, ISO 27001, PCI-DSS, and HIPAA.
• Excellent written and verbal communication skills for executive briefings, documentation, and customer engagement.
• Availability for on-call rotation and ability to lead response during major incidents across time zones.
Preferred / Additional Requirements
• Preferred certifications: GIAC (GCIA, GCIH, GCFA, GCFE, GNFA, GCTI, GDAT), Microsoft SC-200 / SC-100, Splunk Certified Analyst, CrowdStrike CCFA/CCFR/CCFH, Offensive Security (OSCP/OSDA), CISSP, CISM, CCSP, EC-Council CHFI/CTIA, cloud security certifications (Client-500, AWS Security Specialty, GCP Professional).
• Experience with SOAR platforms (Cortex XSOAR or equivalent), ITSM tools (ServiceNow SecOps), and advanced threat intelligence platforms.
• Exposure to purple teaming, adversary emulation, and regulatory-driven incident response.
After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.
Marcus Rivera
Chief Revenue Officer

JustMarkets

Pando

Revolution Medicines

Kyriba

Datadog

Resource Logistics Inc.

Resource Logistics Inc.

Resource Logistics Inc.