SOC Senior Analyst

Resource Logistics, Inc.

SAN JOSE, CA(remote)

JOB DETAILS
SKILLS
Amazon Web Services (AWS), Analysis Skills, Automation, Autopsy, Bash Scripting, CCSP - Cisco Certified Security Professional, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Cellular Telecommunications & Internet Association (CTIA), Cloud Computing, Coaching, Communication Skills, Computer Forensics, Computer Science, Computer Security, Continuous Improvement, Documentation, EC-Council, GCFA - GIAC Certified Forensic Analyst, GCIA - GIAC Certified Intrusion Analyst, GCIH - GIAC Certified Incident Handler, GCP (Good Clinical Practices), GIAC - Global Information Assurance Certification, HIPAA (Health Insurance Portability and Accountability Act), Hunting, ISO (International Organization for Standardization), IT Service Management (ITSM), Incident Management, Incident Response, Information/Data Security (InfoSec), Internet Security, Inversion of Control (IoC), Knowledge Transfer, Leadership, Legal, Linux Operating System, Memory Hardware, Mentoring, Microsoft Product Family, Microsoft Windows System Internals/Programming, Network Security, On Call, Operations Management, PCI-DSS, Presentation/Verbal Skills, Process Improvement, Python Programming/Scripting Language, Quality Assurance, Quality Metrics, Regulations, Root Cause Analysis, Scripting (Scripting Languages), Security Attacks, Security Information and Event Management (SIEM), Security Monitoring, ServiceNow, Splunk, Telecommunications, Telemetry, U.S. National Institute of Standards and Technology (NIST), Use Cases, Windows PowerShell, Writing Skills
LOCATION
SAN JOSE, CA
POSTED
1 day ago

Job Title: SOC Senior Analyst

Location: REMOTE

Mode : Contract (6+ Months)

The SOC Senior Analyst / Incident Response Specialist is a senior-level cybersecurity expert responsible for advanced incident investigation, threat hunting, digital forensic analysis, and incident response leadership within Client s managed Security Operations Center (SOC) ClientR model. This role is pivotal in defending customer environments from evolving cyber threats, ensuring robust detection coverage, and mentoring the next generation of cyber defenders, thus directly contributing to the organization s security posture and client trust.

Key Responsibilities

" Lead deep-dive investigations of escalated security incidents, reconstructing attack chains and correlating multi-source telemetry.

" Execute forensic triage of hosts, memory, disks, and logs, preserving evidence and providing comprehensive analysis for legal or regulatory needs.

" Design and conduct hypothesis-driven and intelligence-led threat hunts using frameworks such as MITRE Telecommunication&CK.

" Act as incident commander for high-severity events, coordinating containment, eradication, and recovery efforts with customer and internal teams.

" Develop and tune SIEM/EDR/XDR detections, authoring advanced use cases that improve detection efficacy and reduce false positives.

" Define, review, and validate SOAR (Security Orchestration, Automation, and Response) playbooks and automation workflows.

" Integrate threat intelligence into SOC operations, contextualizing incidents and managing the IOC lifecycle.

" Produce detailed root-cause analysis and lessons-learned reports, driving continuous improvement in detection and response processes.

" Audit L1/L2 analyst work, provide targeted coaching, and uphold quality assurance standards across the SOC.

" Mentor junior analysts, deliver knowledge transfer sessions, and contribute to internal training and capability building.

" Represent the SOC in customer governance and post-incident review forums, presenting incident trends and improvement actions.

" Participate in adversary emulation and purple-team exercises, translating findings into actionable detection and response enhancements.

Required Skills & Experience

" Bachelor s degree in Computer Science, Information Security, Cybersecurity, Engineering, or equivalent practical experience; Master s preferred.

" 7 10+ years of hands-on experience in SOC/Cyber Defense operations, with at least 3 4 years at L2/L3, incident response, or threat hunting depth.

" Expertise across the incident lifecycle: detection, triage, investigation, containment, eradication, recovery, and post-incident review.

" Deep proficiency in SIEM technologies (e.g., Splunk, Microsoft Sentinel), EDR/XDR platforms (e.g., CrowdStrike, Microsoft Defender), and forensic tools (e.g., Volatility, KAPE, Autopsy).

" Advanced knowledge of Windows and Linux internals, identity security (AD, Entra ID), cloud security (Clienture, AWS, GCP), and network security telemetry.

" Experience designing and executing threat hunts mapped to MITRE Telecommunication&CK and related frameworks.

" Strong scripting and data querying skills (Python, PowerShell, KQL, SPL, Bash).

" Familiarity with security standards such as NIST 800-61, NIST CSF, ISO 27001, PCI-DSS, and HIPAA.

" Excellent written and verbal communication skills for executive briefings, documentation, and customer engagement.

" Availability for on-call rotation and ability to lead response during major incidents across time zones.

Preferred / Additional Requirements

" Preferred certifications: GIAC (GCIA, GCIH, GCFA, GCFE, GNFA, GCTI, GDAT), Microsoft SC-200 / SC-100, Splunk Certified Analyst, CrowdStrike CCFA/CCFR/CCFH, Offensive Security (OSCP/OSDA), CISSP, CISM, CCSP, EC-Council CHFI/CTIA, cloud security certifications (Client-500, AWS Security Specialty, GCP Professional).

" Experience with SOAR platforms (Cortex XSOAR or equivalent), ITSM tools (ServiceNow SecOps), and advanced threat intelligence platforms.

" Exposure to purple teaming, adversary emulation, and regulatory-driven incident response.

About the Company

R

Resource Logistics, Inc.

COMPANY SIZE
500 to 999 employees
INDUSTRY
Medical Devices and Supplies