Lead - SOC Analyst (SIEM & SOAR)
ExternalFull-timeOn-site1d ago
AWSAzureCloud SecurityGCPIAMIncident Response
Prepare for this interview
EliteAI-generated questions, company research, and talking points tailored to this role
Responsibilities
- Administer, maintain, and optimize SIEM platforms (Splunk, Sentinel, QRadar, etc.).
- Design and implement SOAR playbooks to automate security operations and incident response.
- Onboard and manage log sources from enterprise infrastructure, applications, and cloud environments.
- Develop and tune detection rules, correlation searches, dashboards, and alerts.
- Support incident investigations, threat hunting, and response activities.
- Integrate SIEM/SOAR with EDR, IAM, cloud security, email security, and threat intelligence platforms.
- Collaborate with infrastructure, cloud, and security teams to improve monitoring coverage and security posture.
- Mentor SOC analysts and drive continuous improvement initiatives.
- 6-10 years of cybersecurity experience with SOC Engineering/Security Operations focus.
- Minimum 3+ years of hands-on SIEM administration experience.
- Minimum 2+ years of SOAR implementation and automation experience.
- Strong experience managing security monitoring for both:
- Enterprise environments (Windows, Linux, Active Directory, Network Security, Endpoint Security)
- Cloud environments (Azure, AWS, and/or GCP)
- Experience in onboarding and correlating logs from cloud-native security services and enterprise security tools.
- Strong understanding of incident response, threat hunting, and detection engineering.
- Experience with Python, PowerShell, APIs, and automation scripting.
- Good knowledge of MITRE ATT&CK framework and modern threat detection methodologies .
- Preferred Certifications
- Microsoft SC-200 / SC-100
- Splunk Certified Admin/Architect
- GCIH, GCED
- AWS or Azure Security certifications
Benefits
Vision insurance
Additional Information
Job Summary We are seeking a Lead SOC Engineer with strong expertise in SIEM administration, SOAR automation, and security monitoring across both enterprise and cloud environments. The role will focus on enhancing SOC capabilities, improving threat detection, automating response processes, and ensuring visibility across on-premises and cloud infrastructure.
Your Match
How well this role fits your profile.
Company Intel
What employees say
Worked at Freshworks? Share your experience