Senior SOC Analyst- Tuesday- Saturday

BNY Mellon

$95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6-10 years of experience in SOC, incident response, or threat detection roles, focusing on Tier 2/3 investigations.
  • Bachelor's degree in Information Security, Computer Science, or related field; advanced certifications like CISSP or CISM preferred.
  • Advanced proficiency in SIEM, EDR, and SOAR platforms.
  • Strong knowledge of network security, Windows/Linux, and cloud logging sources.
  • Hands-on experience with the MITRE ATT&CK framework and detection tuning.
  • Ability to lead complex incidents and communicate effectively under pressure.
  • Scripting experience for investigation enrichment and automation.
  • Familiarity with NIST CSF/800-61 and regulatory requirements for incident response.

Responsibilities

  • Lead triage and investigate security alerts; escalate and coordinate incident response as necessary.
  • Perform root cause analysis, scope affected assets, and manage containment and recovery efforts.
  • Correlate data across multiple security platforms to identify threats and minimize false alarms.
  • Develop and maintain SOC playbooks and detection logic according to the MITRE ATT&CK framework.
  • Mentor junior analysts, providing insight on investigative techniques and best practices.
  • Collaborate with Threat Intelligence to enhance investigations and track adversary tactics.
  • Work with Engineering teams to improve detection and preventive control effectiveness.
  • Create incident reports and summaries, contributing to metrics and trend analysis.

Benefits

  • Access to flexible global resources and tools for life’s journey.
  • Focus on health and personal resilience with wellbeing programs.
  • Generous paid leaves, including paid volunteer time.
  • Support for family moments that matter.
Full Job Description
Job Description

We're seeking a future team member for the role of Senior SOC Analyst to join our Security Operations Center team. This role can be in Pittsburgh PA or Lake Mary FL. Schedule: Tuesday-Saturday.

Key Responsibilities
  • Lead triage and investigation of security alerts, escalating and coordinating incident response as needed.
  • Perform root cause analysis, scope affected assets, and drive containment, eradication, and recovery.
  • Correlate events across SIEM, EDR, IDS/IPS, firewalls, cloud logs, and identity platforms to identify true positives and reduce false positives.
  • Develop, refine, and maintain SOC playbooks, runbooks, and detection logic aligned to the MITRE ATT&CK framework.
  • Mentor junior analysts and provide guidance on investigation techniques, documentation standards, and operational best practices.
  • Coordinate with Threat Intelligence to enrich investigations, track adversary TTPs, and proactively hunt for indicators of compromise.
  • Partner with Engineering teams to tune detections, improve log fidelity, and strengthen preventive controls.
  • Create clear, actionable incident reports and executive summaries; contribute to metrics and trend analysis.
  • Support purple team exercises and post-incident reviews to capture lessons learned and drive continuous improvement.
  • Ensure adherence to regulatory and security policies; maintain audit-ready documentation for investigations and incidents.

Qualifications
  • 6-10; years of experience in a SOC, incident response, or threat detection role, including Tier 2/3 investigations.
  • Bachelor's degree in Information Security, Computer Science, or a related field - Advanced certifications such as CISSP or CISM are preferred
  • Advanced proficiency with SIEM (e.g., Splunk, QRadar, Sentinel), EDR (e.g., CrowdStrike, Microsoft Defender), and SOAR platforms.
  • Strong knowledge of network security, Windows/Linux, identity systems, and common cloud logging sources.
  • Hands-on experience with the MITRE ATT&CK framework, threat hunting, IOC/IOA development, and detection tuning.
  • Demonstrated ability to lead complex incidents, coordinate stakeholders, and communicate clearly under time pressure.
  • Scripting or automation experience (e.g., Python, PowerShell) for investigation enrichment and workflow improvements.
  • Familiarity with NIST CSF/800-61, CIS Controls, and common regulatory requirements impacting incident response.
  • Excellent documentation skills and an evidence-driven approach to investigations.

Preferred Qualifications
  • Relevant certifications: GCIA, GCED, GCIH, GCFA, GNFA, CISSP, CCSP, or equivalent experience.
  • Experience with ticketing and case management systems (e.g., ServiceNow) and knowledge management practices.
  • Prior experience with threat intel platforms, sandboxing tools, and malware triage is a plus.

Work Schedule
  • This role is scheduled Tuesday-Saturday, 8:00 AM -4 PM Eastern Time to support operational coverage.
  • Occasional flexibility may be required during major incidents or planned exercises.


Our Benefits and Rewards:

BNY offers highly competitive compensation, benefits, and wellbeing programs rooted in a strong culture of excellence and our pay-for-performance philosophy. We provide access to flexible global resources and tools for your life's journey. Focus on your health, foster your personal resilience, and reach your financial goals as a valued member of our team, along with generous paid leaves, including paid volunteer time, that can support you and your family through moments that matter.

Similar Jobs

More Jobs at BNY Mellon

More Information Technology Jobs

Find similar Senior SOC Analyst- Tuesday- Saturday jobs: