Security Operations Center (SOC) Lead (Tier III)
Full-time Mid-Senior LevelJob Overview
Who You’ll Work With
As the Tier III SOC Lead, you will report directly to the Sr. Security Manager of Security Operations while managing and mentoring a remote team of junior and mid-level SOC analysts. On a daily basis, you will collaborate closely with the Incident Response (IR) team to hand off escalated critical threats, partner with cross-functional IT and infrastructure teams to deploy remediation strategies, and coordinate with detection engineering peers to architect sophisticated queries using tools like CrowdStrike.
What You’ll Do
We are seeking a highly experienced and strategic Security Operations Center (SOC) Lead to spearhead our dynamic, remote cybersecurity team. The ideal candidate is a subject matter expert and technical leader with a protagonist track record of resolving complex security incidents and providing high-level technical guidance.
In this Tier III role, you will provide leadership and mentorship to the SOC team, ensuring the effective resolution of the most critical threats across Mac, Linux, and Windows environments. We are looking for a professional who drives technical excellence, mentors junior staff, and leverages deep expertise in CrowdStrike Query Language (CQL) to architect sophisticated detection strategies that protect our organization’s global assets.
Key Responsibilities:
- Lead and mentor a team of junior and mid-level SOC analysts, fostering professional growth and technical proficiency.
- Drive resolution for high-priority and critical security incidents, acting as the primary technical point of escalation.
- Oversee and strategize proactive threat-hunting operations and detection engineering workflows.
- Monitor and triage security alerts.
- Build, test, and refine detections to enhance threat identification across Mac, Linux, and Windows systems.
- Conduct in-depth analysis of security incidents, including malware, phishing, and advanced persistent threats, leveraging SIEM and EDR capabilities.
- Perform proactive threat hunting using the SIEM and EDR features.
- Investigate and respond to incidents swiftly, following established incident response protocols.
- Document findings clearly and provide actionable remediation recommendations.
- Collaborate with cross-functional teams to strengthen security controls and mitigate vulnerabilities.
- Stay current on emerging threats, vulnerabilities, and industry trends through self-directed learning.
- Participate in on-call rotation for 24x7x365 SOC coverage, demonstrating reliability and accountability.
- Escalate confirmed or suspicious incidents and cases to the Incident Response team.
Make Your Resume Now