Start Date
Immediate
Expiry Date
25 Oct, 25
Salary
0.0
Posted On
26 Jul, 25
Experience
4 year(s) or above
Remote Job
Yes
Telecommute
Yes
Sponsor Visa
No
Skills
Security Analysis, Incident Response, Siem, Investigation, Containment, Switches, Automation, Bash, Firewalls, Performance Reviews, Syslog, Python, Training Delivery, Scripting, Correlation
Industry
Information Technology/IT
REQUIRED QUALIFICATIONS AND EXPERIENCE
TECHNICAL KNOWLEDGE
ESSENTIAL ROLES & RESPONSIBILITIES
As a Senior SOC Analyst (Team Leader), you apply your advanced security operations expertise to lead a team of SOC Analysts while performing advanced investigations and, when required, first-line triage to maintain queue health and SLA compliance. You are responsible for high-quality service delivery through detailed analysis, evidence-led response actions, and operational leadership. In addition to handling escalated alerts, you provide line management, oversee ticket quality, contribute to training and onboarding, and drive continual improvement. You work core business hours with participation in the on-call rota, ensuring consistent service support for customers and operational continuity across teams.
KEY RESPONSIBILITIES
ESSENTIAL DUTIES
Advanced Investigation and Escalated Response
o Perform in-depth investigations using correlated data from all available tooling.
o Reconstruct attack chains and identify root causes using MITRE ATT&CK.
o Recommend and coordinate response actions to mitigate impact during active incidents.
IOC and Threat Analysis
o Investigate indicators of compromise using commercial and open-source threat intelligence.
o Validate alerts and determine their relevance to customer environments, providing context on adversary behaviour and recommending follow-up actions when threats are confirmed.
Threat Hunting
o Lead and participate in threat hunts using hypothesis-driven approaches mapped to TTPs and MITRE ATT&CK.
o Leverage telemetry and queries in tooling to identify suspicious indicators not surfaced through existing detection logic.
o Document hunting activities, findings, and detection coverage gaps to support tuning and continual detection improvement.
Team Oversight
o Provide feedback and coaching on triage techniques, escalation decisions, and ticket quality.
o Monitor performance, manage formal HR processes, and support professional development through regular one-to-ones and quarterly appraisals.
o Provide concise on-call handovers and status reporting to maintain continuity between core and shift teams, escalating risks or operational issues as needed.
Documentation and Reporting
o Ensure clear, evidence-based documentation of incidents and investigations, including rationale for response actions and IOC validation.
o Perform case-closure quality assurance to confirm investigation completeness and capture lessons learned.
o Support knowledge-base development and post-incident reporting activities, ensuring reusable insights are recorded to improve future incident handling and analyst onboarding.