- Location
- Remote - United States
- Workplace
- Remote
- Type
- Full-time
- Seniority
- Senior
- Experience
- 30+ years
- Education
- Bachelor
- Source
- Pinpoint
Description
Senior SOC Analyst
Department: Threat Management: Strategic Services
Employment Type: Full Time
Location: Remote - United States
Description
Key Responsibilities
- Leads and mentors a team of L1 and L2 incident responders in handling security incidents.
- Coordinates with internal and external stakeholders during high-severity incidents.
- Develops, refines, and tests incident response playbooks and procedures.
- Conducts advanced threat-hunting activities to detect sophisticated adversaries.
- Collaborates with threat intelligence and vulnerability management teams to stay current on emerging threats and vulnerabilities.
- Provides expert guidance in root cause analysis and post-incident reviews.
- Develops and fine-tunes detection rules to enhance threat detection capabilities.
- Uses frameworks such as MITRE ATT&CK to understand and categorize threat actor TTPs.
- Drives continuous improvement initiatives within the SOC.
- Generates metrics and reports on incident response activities and trends for leadership.
- Conducts regular briefings to leadership on security incidents and trends.
- Develops and maintains scripts to automate and enhance incident response processes.
- Conducts in-depth malware analysis to determine malware samples' functionality, origin, and impact.
- Collaborates with threat intelligence teams to correlate malware findings with known threat actor campaigns.
- Provides recommendations to enhance detection and prevention capabilities based on malware analysis findings.
- Leads digital forensics investigations, including memory forensics, to uncover evidence and artifacts related to security incidents.
- Oversees network forensics activities to analyze network traffic logs and detect malicious activities or patterns.
- Serves as a subject matter expert on incident response, providing guidance and advice to DeepSeas and client leadership.
Experience, Education, and Skills Required
- 5+ years of experience in security operations, incident response, or threat detection, including time operating at a senior (L3) level or leading investigations; or an equivalent combination of education and experience.
- Proven experience leading high-severity incident response from triage through containment, eradication, and recovery.
- Strong hands-on proficiency with SIEM, EDR/XDR, and SOAR platforms, including writing and tuning detection content (e.g., KQL, SPL, Sigma, YARA).
- Working knowledge of MITRE ATT&CK and the incident response lifecycle (e.g., NIST SP 800-61).
- Experience with host, memory, and network forensics, as well as static and dynamic malware analysis.
- Scripting proficiency in Python, PowerShell, or Bash to automate investigation and response tasks.
- Experience mentoring or leading junior analysts.
- Excellent written and verbal communication skills, with the ability to brief both technical teams and executive or client audiences.
- This position is open only to U.S. citizens who currently reside within the United States.
- Advanced certifications such as GCIH, GCFA, GREM, GNFA, OSCP, or CISSP.
- Experience in an MDR or MSSP environment supporting multiple clients.
- Familiarity with reverse engineering and memory forensics tools (e.g., Ghidra, IDA Pro, x64dbg, Volatility).
- Experience building or maturing a threat-hunting or detection engineering program.
- Bachelor's degree in Cybersecurity, Computer Science, or a related field.
Why DeepSeas?
- We are client obsessed.
- We stand in solidarity with our teammates.
- We prioritize personal health and well-being.
- We believe in the power of diversity.
- We solve hard problems at the speed of cyber.
Information security is everyone’s responsibility:
- Understanding and following DeepSeas’s information security policies and procedures.
- Remaining vigilant and reporting any suspicious activity or possible weaknesses in DeepSeas’s information security.
- Actively participating in DeepSeas’s efforts to maintain and improve information security.
- DeepSeas considers this position is as Moderate Risk with a potential to view/access/download restricted/private client/internal data.
- This information must be treated with sensitivity and in the most secure manner.
- HR reserves the right to perform random background/drug screens to ensure the safety of client/DeepSeas data