Search

Security Operations Center Analyst

PublishedPublished: 6/14/2022
Real Estate

Job Description


\n

About the Company- Hybrid Role: Springfield Ma Area

\n


\n

As a Senior SOC Analyst, you will play a pivotal role in defending critical infrastructure.

\n


\n

About the Role

\n

As a Senior SOC Analyst, you will operate independently with minimal supervision to detect, analyze, and respond to complex security threats in a fast paced, mission critical SOC environment supporting electric grid operations, while leading response efforts for high severity and complex security incidents and serving as a project implementor for SOC‑related initiatives.

\n


\n

Responsibilities

\n

    \n
  • Operate independently with minimal supervision to detect, analyze, and respond to complex security threats in a fast paced, mission critical SOC environment supporting electric grid operations.
  • \n

  • Lead response efforts for high severity and complex security incidents, coordinating containment, eradication, and recovery across IT, OT, and engineering teams.
  • \n

  • Apply threat modeling techniques to anticipate adversary attack paths, inform detection strategy, and improve defensive coverage across critical infrastructure systems.
  • \n

  • Perform advanced threat detection and analysis using SIEM, EDR/XDR, network monitoring, and forensic tools.
  • \n

  • Conduct malware analysis, digital forensics, and root cause investigations following security events affecting critical systems.
  • \n

  • Develop, tune, and maintain detection rules, correlation logic, and automated response playbooks to continuously improve SOC effectiveness.
  • \n

  • Coordinate tabletop exercises, purple team activities, and grid focused security assessments.
  • \n

  • Mentor and train junior SOC analysts, providing guidance on investigation techniques, tools, and best practices.
  • \n

  • Serve as the project implementor for SOC‑related initiatives, partnering with the PMO to plan, coordinate, and execute corporate security projects impacting SOC operations.
  • \n

\n


\n

Required Skills

\n

    \n
  • SIEM platforms (Splunk, QRadar, ArcSight, Microsoft Sentinel, or similar)
  • \n

  • EDR/XDR solutions (CrowdStrike, Carbon Black, Microsoft Defender, SentinelOne, or similar)
  • \n

  • Network analysis tools (Wireshark, Zeek, tcpdump)
  • \n

  • Forensic tools and techniques (EnCase, FTK, Volatility, Autopsy)
  • \n

  • Attack frameworks such as MITRE ATT&CK and the Cyber Kill Chain
  • \n

  • Threat actor tactics, techniques, and procedures (TTPs)
  • \n

  • Threat intelligence frameworks and indicators of compromise (IOCs)
  • \n

  • Network protocols (TCP/IP, DNS, HTTP/S, SMTP, SMB)
  • \n

  • Firewalls, IDS/IPS, and proxy technologies
  • \n

  • Windows and Linux operating systems (administration and security hardening)
  • \n

  • Cloud environments (AWS, Azure, GCP) and cloud security principles
  • \n

  • Scripting languages (Python, PowerShell, Bash)
  • \n

  • Malware analysis techniques (static and dynamic analysis)
  • \n

  • Log analysis and event correlation
  • \n

  • Vulnerability management concepts
  • \n

\n


\n

Preferred Skills

\n

    \n
  • Relevant certifications such as GCIA, GCIH, GCFA, GREM, CISSP, CySA+, or equivalent
  • \n

  • Experience in critical infrastructure or energy sector environments
  • \n

  • Background in threat hunting or offensive security concepts
  • \n

  • Familiarity with NERC CIP compliance requirements
  • \n

  • Experience with SOAR platforms (Splunk SOAR, Palo Alto XSOAR, Swimlane)
  • \n

  • Knowledge of OT/ICS security concepts
  • \n

\n


Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...