Leads advanced monitoring, complex investigations, and day-to-day oversight of SOC analysts. Ensure high quality security operations for ATS and customer environments.
Primary Responsibilities
- Serve as escalation point for complex alerts and incidents.
- Lead incident response activities including containment and remediation.
- Conduct threat hunting and advanced analysis across SIEM, EDR, and cloud telemetry.
- Review analyst investigations for accuracy and provide coaching.
- Maintain and improve SOC runbooks, playbooks, and automation workflows.
Technical Skills
- Advanced SIEM, EDR, and threat analysis expertise.
- Strong understanding of intrusion methods, malware behavior, and cloud log telemetry.
- Ability to lead SOC investigations and interpret complex evidence.
- Experience performing threat hunts and tuning detections.
Soft Skills
- Strong leadership and mentorship abilities.
- Calm under pressure with solid attention to detail.
- Clear written and verbal communication.
- Customer focused mindset.
Minimum Requirements
- 3+ years of SOC or incident response experience.
- Experience leading investigations and coaching analysts.
- Relevant certifications such as GCIH, GCIA, CySA+ or similar.
Preferred Requirements
- Experience in an MSSP or multi-tenant SOC environment.
- SOAR automation and detection tuning experience.
- Knowledge of NIST, CIS, CMMC, and SOC 2 frameworks.
- SIEM: Wazuh (Operating in both Commercial and GCC High)