- Company Name
- Graystone Group
- Job Title
- Remote Sr. SOC Analyst, Tier III
- Job Description
-
Job Title: Remote Senior SOC Analyst – Tier III
Role Summary: Tier‑III SOC analyst investigates escalated alerts, performs deep forensic analysis, tunes SIEM detection rules, conducts threat hunting, and collaborates with incident response teams to mitigate advanced cyber threats.
Expactations: • 5+ years SOC or security operations experience
• 4+ years with CrowdStrike, Splunk, and Microsoft Defender
• Proven ability to analyze and correlate host, network, and identity data
• Experience tuning alerts and reducing false positives
• Familiarity with threat intelligence (IOCs, TTPs) and its application in detection
• Proficiency in Windows, macOS, and Linux environments
• Strong written and verbal communication & documentation skills
Key Responsibilities: • Investigate security alerts escalated from Tier 1 / 2 and determine root causes.
• Correlate data across host, network, identity, and log sources to validate incidents.
• Tune SIEM alerts (CrowdStrike, Splunk, Defender) to improve detection effectiveness.
• Conduct threat hunting using IOCs, adversary TTPs, and internal datasets.
• Support development and execution of runbooks and escalation processes.
• Escalate complex cases to Incident Response or higher‑tier teams.
• Document investigation steps and findings for technical and managerial audiences.
• Collaborate with internal IT, application, and infrastructure teams during investigations.
Required Skills: • Advanced SOC operation and incident investigation.
• Expert use of CrowdStrike, Splunk, Microsoft Defender SIEM tools.
• Threat hunting and threat intelligence analysis.
• Alert tuning, false‑positive reduction, and rule optimization.
• Multi‑platform (Windows, macOS, Linux) forensics and analysis.
• Strong analytical, problem‑solving, and documentation abilities.
• Excellent communication and stakeholder management.
Required Education & Certifications: • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or related field (or equivalent professional experience).
• Security certifications such as CISSP, CISM, GCIH, or comparable demonstrate advanced knowledge.