Position Title:SOC Analyst T3
Position Type:Full-time/exempt
Clearance:n/a
Location:Huntsville, AL/Remote
SOC Code: Salary*:$100,000 - $140,000
*Dependent upon qualifications
Essential Functions:- Senior level staff within the Security Operations Team are responsible for handling higher level cybersecurity incidents in accordance with the full IR Lifecycle.
- Liaison between Summit 7 and clients for the MSSP agreement.
- Responsible for triage, detection, and investigating potential security threats and handling them according to processes and procedures.
- Deployment, tuning and maintenance of SIEM and Detection Engineering Platforms.
- Assistance with compliance mandates related to CMMC L2 and L3 implementation
- Track and understand emerging security practices and threats, leveraging this knowledge to improve security configurations.
- Escalation points for SOC Tier 2 in relation to triage, analysis and incident response.
- Escalation points for SOC Tier 2 in SIEM and Detection Engineering.
- Responsible for projects dedicated to Service improvement and optimization.
Additional responsibilities include, but are not limited to:- Implement security measures to assist in disaster recovery and planning
- Review of the most recent SIEM alerts to determine relevance and urgency
- Triage according to organizational procedures to ensure that a genuine security incident is occurring
- Assist with the configuration of security monitoring tools
- Other duties as assigned
Job SpecificationsRequired
- Administrative skills in several operating systems, such as Windows, OS X, and Linux
- Experience with the Microsoft Security Stack.
- Experience with KQL for security analysis.
- Base level of knowledge of SIEM architecture and custom integration.
- Understand basic principles of Information Security
- Clear Communication and presentation skills pertaining to security services
- Writing proficiency requirements with the ability to draft clear and professional internal and external correspondence.
- Familiar with the concept/purpose of a SIEM
- Security + certification or SANS SEC401
Optional / Desired
- Additional Scripting languages
- Certified Ethical Hacker or better
- Blue Team Security Level 1 Certification
- Proficient in a python or PowerShell
- EC-Council Certified SOC Analyst (CSA)
- Microsoft SC 200
- MS or AZ 500
- Experience with Microsoft Sentinel preferred