Security Operations Center; SOC) Lead - L3
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Security Management & Operations
Overview Who we are
Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like one of the world’s most admired brands, Toyota is growing and leading the future of mobility through innovative, high-quality solutions designed to enhance lives and delight those we serve. We’re looking for talented team members who want to Dream. Do. Grow.
with us.
An important part of the Toyota family is Toyota Financial Services (TFS), the finance and insurance brand for Toyota and Lexus in North America. While TFS is a separate business entity, it is an essential part of this world-changing company- delivering on Toyota's vision to move people beyond what's possible. At TFS, you will help create best-in-class customer experience in an innovative, collaborative environment.
Toyota does not offer support or sponsorship of job applicants for employment-based visas or any other work authorization for this role now or in the future. You must have the right to work in the United States and not require Toyota support or sponsorship for immigration-related employment (e.g., H-1B, O-1, E-3, H-1B1, TN, F-1 OPT, F-1 STEM OPT, F-1 CPT, ‘job flexibility benefits’ [also known as I-140 or Adjustment of Status portability], etc.)
now or in the future. You should not apply for this role if you will require Toyota to assist with immigration support or sponsorship now or in the future.
The SOC Analyst III serves as a senior member of the Security Operations Center, responsible for advanced threat detection, investigation, incident response, and security monitoring activities. This role provides technical leadership for complex cybersecurity incidents, develops and optimizes detection content, and collaborates with cross-functional teams to strengthen the organization's security posture. The SOC Analyst III also mentors junior analysts, drives continuous improvement initiatives, and contributes to the development of security operations processes and procedures.
Whatyou’llbedoing
Threat Detection & Monitoring
Lead advanced monitoring and analysis of security events, alerts, and telemetry from multiple security platforms.
Identify, investigate, and validate potential cybersecurity threats and suspicious activities.
Perform threat hunting activities to proactively detect malicious behavior and emerging threats.
Develop and maintain detection logic, use cases, correlation rules, and alerting content to improve security visibility.
Lead investigations of complex security incidents across endpoint, network, cloud, and identity environments.
Perform root cause analysis and determine the scope, impact, and severity of security events.
Coordinate containment, eradication, and recovery efforts with internal and external stakeholders.
Document incident findings, actions taken, and lessons learned.
Evaluate and tune security monitoring technologies to improve detection effectiveness and reduce false positives.
Assist with onboarding and integration of new log sources, security tools, and data feeds.
Support automation initiatives that enhance SOC efficiency and operational effectiveness.
Contribute to the development and maintenance of SOC processes, playbooks, and operational standards.
Provide technical mentorship and guidance to Tier 1 and Tier 2 analysts.
Serve as an escalation point for complex investigations and security incidents.
Collaborate with IT, infrastructure, cloud, engineering, and business teams to address security risks.
Participate in security exercises, tabletop events, and post-incident reviews.
Prepare incident summaries, metrics,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).