Senior SOC Analyst- Tuesday- Saturday

The Bank of New York Mellon

  • Pittsburgh, PA
  • 11 days ago

    Highlights

    Correlate events across SIEM, EDR, IDS/IPS, firewalls, cloud logs, and identity platforms to identify true positives and reduce false positives. Support purple team exercises and post-incident reviews to capture lessons learned and drive continuous improvement.

    Numbers & Facts

    LocationPittsburgh, PA

    Description

    JobID: 80293

    Category: Information Security

    JobSchedule: Full time

    Posted Date: 2026-08-28T18:30:37+00:00

    JobShift: Day

    Base Salary Min: 83000

    We're seeking a future team member for the role of Senior SOC Analyst to join our Security Operations Center team. This role can be in Pittsburgh PA or Lake Mary FL. Schedule: Tuesday-Saturday.

    Key Responsibilities

    • Lead triage and investigation of security alerts, escalating and coordinating incident response as needed.
    • Perform root cause analysis, scope affected assets, and drive containment, eradication, and recovery.
    • Correlate events across SIEM, EDR, IDS/IPS, firewalls, cloud logs, and identity platforms to identify true positives and reduce false positives.
    • Develop, refine, and maintain SOC playbooks, runbooks, and detection logic aligned to the MITRE ATT&CK framework.
    • Mentor junior analysts and provide guidance on investigation techniques, documentation standards, and operational best practices.
    • Coordinate with Threat Intelligence to enrich investigations, track adversary TTPs, and proactively hunt for indicators of compromise.
    • Partner with Engineering teams to tune detections, improve log fidelity, and strengthen preventive controls.
    • Create clear, actionable incident reports and executive summaries; contribute to metrics and trend analysis.
    • Support purple team exercises and post-incident reviews to capture lessons learned and drive continuous improvement.
    • Ensure adherence to regulatory and security policies; maintain audit-ready documentation for investigations and incidents.

    Qualifications

    • 6-10; years of experience in a SOC, incident response, or threat detection role, including Tier 2/3 investigations.
    • Bachelor's degree in Information Security, Computer Science, or a related field - Advanced certifications such as CISSP or CISM are preferred
    • Advanced proficiency with SIEM (e.g., Splunk, QRadar, Sentinel), EDR (e.g., CrowdStrike, Microsoft Defender), and SOAR platforms.
    • Strong knowledge of network security, Windows/Linux, identity systems, and common cloud logging sources.
    • Hands-on experience with the MITRE ATT&CK framework, threat hunting, IOC/IOA development, and detection tuning.
    • Demonstrated ability to lead complex incidents, coordinate stakeholders, and communicate clearly under time pressure.
    • Scripting or automation experience (e.g., Python, PowerShell) for investigation enrichment and workflow improvements.
    • Familiarity with NIST CSF/800-61, CIS Controls, and common regulatory requirements impacting incident response.
    • Excellent documentation skills and an evidence-driven approach to investigations.

    Preferred Qualifications

    • Relevant certifications: GCIA, GCED, GCIH, GCFA, GNFA, CISSP, CCSP, or equivalent experience.
    • Experience with ticketing and case management systems (e.g., ServiceNow) and knowledge management practices.
    • Prior experience with threat intel platforms, sandboxing tools, and malware triage is a plus.

    Work Schedule

    • This role is scheduled Tuesday-Saturday, 8:00 AM -4 PM Eastern Time to support operational coverage.
    • Occasional flexibility may be required during major incidents or planned exercises.

    Similar Jobs