Security Operations Center Analyst
Listed on 2025-12-27
-
IT/Tech
Cybersecurity, Security Manager
Splunk SOC Analyst 1, 2 and 3 (on-call, as needed for shift coverage)
Location:
US-based, remote.
- Weekdays (M-F):
- 1st shift 8 am-4 pm
- 2nd shift 4 pm-12 am
- 3rd shift 12 am-8 am
- Weekends (Saturday/Sunday—starts Friday at midnight):
- 5th shift: 12 pm-12 am (hands over to 3rd shift Sunday night/Monday morning)
The SA3 is the final level of internal escalation for incident response on the MDR Operations team. As a Security Analyst Level 3 in the Tek Stream Managed Detection and Response (MDR) environment, they act as a liaison between security operations and engineering to advance our practice and drive us towards growth. There is a particular emphasis on the ability to identify Indicators of Compromise (IOC) and correctly recommend remediation;
productively, efficiently, and with a high degree of accuracy. This core skillset is extended to include the guidance of SA2 and SA1 incident response. Related is the ability to leverage the technologies that are central to the Tek Stream MDR solution.
- Lead the response to escalated security incidents, providing advanced analysis and mitigation strategies.
- Mentor and guide SA2 and SA1 in incident response procedures and techniques.
- Conduct in-depth analysis of security incidents to understand the root cause and impact.
- Collaborate with cross-functional teams to coordinate and execute incident containment and eradication.
- Communicate threats and recommended remediation with customer Points of Contact (POC).
- Develop and maintain incident response playbooks to ensure consistency in handling incidents.
- Assist in the continuous improvement of security monitoring and detection capabilities.
- Participate in on‑call rotations to provide 24/7 incident response support.
- Conduct post‑incident reviews to identify lessons learned and areas for improvement.
- Stay abreast of the latest cybersecurity threats, vulnerabilities, and industry best practices.
- Work closely with customers and internal teams to provide expert guidance on security‑related matters.
- Associate
- Contract
- Information Technology
- IT Services and IT Consulting
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).