Security Analyst - Tier 3
Core
Senior Security Analyst leading complex, multi-stage investigations and serving as the quality gate for the SOC.
Role type
Senior individual-contributor Security Analyst (Tier 3)
Builds
Detection and response capabilities, investigation methodologies, and incident response outcomes
Domain
Cybersecurity, Cloud Security, Incident Response
Required skills
Complex incident investigation, Cloud security (containers, Kubernetes), EDR/SIEM query languages, Windows/Linux internals analysis, MITRE ATT&CK fluency, Python/SQL/KQL scripting, Technical leadership
Preferred skills
GCIH, GCFA, GNFA, GCFE, or OSCP certifications
Technologies
Python, SQL, KQL, EDR, SIEM, Kubernetes, Containers
Responsibilities
Lead complex, multi-stage investigations from scoping to root cause determination; Serve as senior escalation point and quality gate for SOC investigations; Support Incident Response team with deep telemetry analysis; Identify gaps in SOC methods and tooling to drive improvements; Mentor Tier 1 and Tier 2 analysts; Partner with Security Engineering and Threat Intelligence teams; Participate in tabletop exercises and post-incident reviews; Manage on-call rotation as senior point of contact
Seniority
Senior, hands-on IC