As a Senior SOC Analyst, you will play a pivotal role in defending critical infrastructure that powers millions of residents across New England. Our organization is responsible for safeguarding the electric grid, a cornerstone of public safety, economic stability, and national security.
What we offer you:- Hybrid work environment (4 days/week on-site)
- Distance-based relocation assistance available
- 7 people paid on-call rotation
- Competitive compensation with a base salary + performance bonus
- Robust benefits package, including:
- Enhanced 401(k) and financial planning support
- Tuition reimbursement and professional development
- Wellness programs, including an onsite gym
- Free coffee at our onsite café
- Flexible work hours
- Employee Business Networks
- A stable, mission-driven workplace where your impact truly matters
How you will make an Impact- Operate independently with minimal supervision to detect, analyze, and respond to complex security threats in a fast paced, mission critical SOC environment supporting electric grid operations.
- Lead response efforts for high severity and complex security incidents, coordinating containment, eradication, and recovery across IT, OT, and engineering teams.
- Apply threat modeling techniques to anticipate adversary attack paths, inform detection strategy, and improve defensive coverage across critical infrastructure systems.
- Perform advanced threat detection and analysis using SIEM, EDR/XDR, network monitoring, and forensic tools.
- Conduct malware analysis, digital forensics, and root cause investigations following security events affecting critical systems.
- Develop, tune, and maintain detection rules, correlation logic, and automated response playbooks to continuously improve SOC effectiveness.
- Coordinate tabletop exercises, purple team activities, and grid focused security assessments.
- Mentor and train junior SOC analysts, providing guidance on investigation techniques, tools, and best practices.
- Serve as the project implementor for SOC-related initiatives, partnering with the PMO to plan, coordinate, and execute corporate security projects impacting SOC operations.
What we are looking for - SIEM platforms (Splunk, QRadar, ArcSight, Microsoft Sentinel, or similar)
- EDR/XDR solutions (CrowdStrike, Carbon Black, Microsoft Defender, SentinelOne, or similar)
- Network analysis tools (Wireshark, Zeek, tcpdump)
- Forensic tools and techniques (EnCase, FTK, Volatility, Autopsy)
- Attack frameworks such as MITRE ATT&CK and the Cyber Kill Chain
- Threat actor tactics, techniques, and procedures (TTPs)
- Threat intelligence frameworks and indicators of compromise (IOCs)
- Network protocols (TCP/IP, DNS, HTTP/S, SMTP, SMB)
- Firewalls, IDS/IPS, and proxy technologies
- Windows and Linux operating systems (administration and security hardening)
- Cloud environments (AWS, Azure, GCP) and cloud security principles
- Scripting languages (Python, PowerShell, Bash)
- Malware analysis techniques (static and dynamic analysis)
- Log analysis and event correlation
- Vulnerability management concepts
Skills and Abilities:
- Self-starter mindset with strong ownership, accountability, and professional judgment.
- Proven ability to remain calm and decisive under pressure in incidents impacting critical infrastructure.
- Strong analytical, problem solving, and critical thinking skills.
- Excellent written and verbal communication, with the ability to explain complex issues clearly.
- Commitment to continuous learning and staying current with evolving threats and technologies.
Critical Infrastructure SOC Competencies:
- Composure under pressure: Ability to remain calm, focused, and methodical during high-severity incidents where decisions directly impact grid reliability and public safety
- Mission-driven mindset: Deep understanding of the responsibility that comes with defending critical infrastructure essential to national security and public welfare
- Rapid triage and prioritization: Ability to quickly assess multiple simultaneous alerts and threats, making rapid decisions on priority and resource allocation
- Situational awareness: Continuous awareness of the operational environment, threat landscape, and potential cascading impacts of security events on critical systems
- Team coordination: Skill in working seamlessly with cross-functional teams including IT, OT, engineering, and leadership during incident response
- Clear communication under stress: Ability to convey technical information accurately and concisely to diverse stakeholders while managing active incidents
Preferred qualifications:
- Relevant certifications such as GCIA, GCIH, GCFA, GREM, CISSP, CySA+, or equivalent
- Experience in critical infrastructure or energy sector environments
- Background in threat hunting or offensive security concepts
- Familiarity with NERC CIP compliance requirements
- Experience with SOAR platforms (Splunk SOAR, Palo Alto XSOAR, Swimlane)
- Knowledge of OT/ICS security concepts
This employer will not sponsor applicants for work visas for this position (ex: H-1B, F-1/CPT/OPT, O-1, E-3, TN, J, etc.).
The expected salary range for this position is $115,000 - $142,000 per year. This role is also eligible for an annual performance bonus, comprehensive health insurance (medical, dental and vision), flexible spending and health savings accounts, a 401(k) plan with generous employer contributions and a student debt benefit, life and AD&D insurance, disability insurance, critical illness and hospital indemnity benefits, paid time off, paid leave, a wellness program, an employee assistance program and other great company perks.
#LI-HYBRID
This is a U.S. based role. If the successful candidate resides outside of the U.S., relocation will be required.