Lead SOC Analyst
Listed on 2026-07-17
-
IT/Tech
Cybersecurity
About Us
We’re the world’s leading provider of secure financial messaging services, headquartered in Belgium. We are the way the world moves value – across borders, through cities and overseas. No other organisation can address the scale, precision, pace and trust that this demands, and we’re proud to support the global economy.
Position OverviewThe Cyber Fusion Centre (CFC) is looking for a Lead SOC (Security Operations Center) Analyst to join us. This team is responsible for preventing cyber security incidents by monitoring, detecting, and responding to potential intrusions in real time within the Swift network. As Lead SOC Analyst, you will provide input to security strategy and controls for systems, networks, physical infrastructure, people, and information;
participate in the design, communication, and execution of policies and procedures; and act as an operational mentor, coaching junior members within the team.
- Lead the creation and operationalization of a formalized Threat Hunting program within the SOC.
- Participate in a 24×7 SOC; occasional shift work is required—one week per month Monday‑Sunday, 11 AM‑7 PM, with regular working hours outside those shifts.
- Provide expertise and guidance to less senior team members.
- Support Incident Response (IR) and Threat Detection development activities and report to Senior Management to ensure proper awareness and ownership.
- Support the introduction and implementation of new capabilities and IR processes and procedures within the Cyber Fusion Centre.
- Interact closely with Swift’s Red Team to further enhance detection capabilities.
- Lead and participate in IR simulation exercises from a blue‑team perspective.
- Perform proper triage, identification, and scoping of incidents—investigate, contain, and follow up on containment actions.
- Participate in the identification, development, and communication of Indicators of Compromise (IOCs).
- Coordinate eradication and remediation actions with various stakeholders, ensuring timely follow‑up.
- Enhance and tune tools to efficiently manage large collections of security events.
- Stay abreast of changing technologies, emerging cyber threats and attack methodologies.
- Strong analytical and problem‑solving skills.
- Excellent verbal and written communication, with the ability to concisely and accurately document technical investigations.
- Ability to thrive in a fast‑paced, multi‑dimensional, technical environment.
- Bachelor’s degree in Computer Science, IT, or related field.
- 8+ years of working experience in a SOC, Incident Response, or Threat Hunting role.
- Experience performing or leading threat hunting activities.
- Experience with cloud technologies such as Azure, Google Cloud, or AWS.
- Experience with security tools such as SIEM, IDS/IPS, EDR/XDR, SOAR, etc.
- Strong verbal and written communication and the ability to concisely and accurately document technical investigations.
- Familiarity with scripting languages such as PHP, Perl, or Python and databases such as MySQL; knowledge of Unix and Windows.
- Security certifications such as GIAC GCIA/GCIH, CISSP, or other relevant certifications.
- Knowledge of penetration testing and vulnerability assessment capabilities and tools.
The estimated salary range for a new hire in this position in Virginia is $ USD Annual Minimum to $ USD Annual Maximum. Salary may vary based on job‑related factors such as knowledge, skills, experience, and location. Our compensation package includes a competitive base salary and a bonus opportunity for all employees contingent on personal and company performance. Our generous benefits program includes medical, dental, vision, and life insurance with no premium costs for employees and their families, as well as a 401(k) retirement plan with employer matching.
EEOStatement and Accessibility
We are committed to an inclusive and accessible recruitment process. If you require a reasonable accommodation related to accessibility during your application or interview, please contact accessibility‑ or indicate this in your application. All requests are confidential and will not affect your candidacy.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).