Level 3 SOC Analyst – Senior Security Operations
Synergy Business Consulting, Inc. · Broward County, FL
Apply & track with Apply EdgeHybrid | Broward county FL | 24x7x365 SOCWe are seeking an experienced Level 3 SOC Analyst to serve as a senior technical authority within a 24x7x365 Security Operations Center.This is a hands-on technical role, not a people-management position. The Level 3 Analyst will own complex investigations escalated by Level 1 and Level 2 analysts, conduct advanced threat hunting and forensic analysis, improve detection quality, and provide technical mentorship and escalation support to the SOC team.The ideal candidate is an experienced security professional who can independently investigate sophisticated threats, make sound decisions during high-severity incidents, and clearly communicate findings to both technical teams and customers.Key ResponsibilitiesAdvanced Investigation & Threat AnalysisOwn complex security investigations escalated from Level 1 and Level 2 analysts.Determine incident scope, impact, root cause, and disposition.Investigate advanced threats including:Ransomware and pre-ransomware activityAdvanced persistent threats (APTs)Business Email Compromise (BEC)Identity-based attacksInsider threatsReconstruct attack timelines across endpoint, identity, network, email, and cloud telemetry.Perform forensic analysis involving logs, host artifacts, identity activity, memory/disk artifacts, and network traffic.Produce technically defensible findings suitable for customers and regulated environments.Security Technology & Detection StackWork across enterprise security technologies including:Huntress MDR/EDR/ITDRGoogle Chronicle / Google SecOpsCrowdStrikeMicrosoft DefenderMicrosoft 365Microsoft Entra IDSIEM/SOAR technologiesThreat intelligence platformsEndpoint and network telemetryComparable experience with platforms such as Microsoft Sentinel or Splunk is also highly relevant.Incident ResponseServe as the senior technical escalation point during high-severity security incidents.Coordinate response activities with SOC leadership, infrastructure/NOC teams, cybersecurity teams, and external partners.Confirm true-positive incidents and identify indicators of compromise.Coordinate containment activities with infrastructure teams.Support major incident response and incident command.Work against defined severity-based response requirements and MTTA, MTTD, and MTTR objectives.Identify incidents that may trigger contractual or regulatory notification requirements and escalate appropriately.Lead technical post-incident reviews and identify required detection or process improvements.Threat Hunting & Proactive DefenseConduct structured, hypothesis-driven threat hunts across customer environments.Search for Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).Perform retrospective analysis against historical telemetry.Use threat intelligence and MITRE ATT&CK to guide investigations.Identify gaps in existing detection coverage.Help improve overall threat-detection capabilities.Detection Engineering & TuningAnalyze detection rules, correlation logic, raw logs, and normalized security data.Investigate false positives, detection gaps, parser failures, and missing telemetry.Develop evidence-based recommendations for detection-rule improvements.Work with SIEM/SOAR and detection-engineering teams on:Detection tuningParser and schema mappingUse-case developmentDetection scoringLog ingestionValidate that detection changes continue to identify the threats they were designed to detect.Identify repetitive investigation, enrichment, triage, and containment processes that can be automated.Support the development of security automation and SOAR workflows.Mentorship & Technical LeadershipProvide technical guidance and escalation support to Level 1 and Level 2 SOC Analysts.Review investigations and case documentation for technical quality.Help junior analysts develop stronger investigation and incident-response skills.Develop and maintain:Incident-response playbooksRunbooksStandard Operating Procedures (SOPs)Support SOC onboarding, tabletop exercises, and incident-response simulations.This position does not have direct reports. Technical mentorship is a core responsibility.Customer Communication & DocumentationIndependently produce professional incident reports covering:Incident timelineRoot causeScope and impactActions takenRecommended remediationClearly communicate complex security findings to technical and non-technical audiences.Participate in customer incident calls when required.Maintain accurate investigation documentation throughout the incident lifecycle.Contribute technical security findings and trends to customer service reviews and quarterly business reviews.Participate in formal SOC shift handoffs to ensure continuity of open investigations.Required Experience5+ years of SOC, cybersecurity operations, incident response, or related security experience.Demonstrated ownership of complex or escalated security investigations.Hands-on experience with incident response, forensic analysis, and threat hunting.Experience working with modern SIEM/SOAR and EDR/MDR platforms.Strong understanding of endpoint, network, identity, and cloud security telemetry.Experience investigating Microsoft 365 and Microsoft Entra ID environments.Experience with at least one major cloud platform:AzureAWSGoogle Cloud PlatformStrong working knowledge of MITRE ATT&CK.Ability to independently investigate complex security incidents with limited supervision.Experience mentoring or providing escalation support to junior SOC analysts.Strong written and verbal English communication skills.Experience within a multi-client MSSP, MSP, MDR, or managed-security environment is strongly preferred.Technical SkillsCandidates should have strong experience in several of the following areas:SIEM / SOARGoogle Chronicle / Google SecOpsMicrosoft SentinelSplunkHuntressCrowdStrike FalconMicrosoft DefenderEDR / MDR / XDRIncident ResponseDigital ForensicsThreat HuntingDetection EngineeringMalware AnalysisThreat IntelligenceMicrosoft 365Entra IDAzure / AWS / GCPMITRE ATT&CKLog and network analysisPython and/or PowerShellSecurity automationConnectWise Manage or similar PSA/ticketing platformsKnowledge of security frameworks and regulatory requirements including NIST, CIS, ISO 27001, HIPAA, PCI-DSS, and GLBA is highly desirable.EducationBachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field preferred.Equivalent professional cybersecurity experience will also be considered.Certificatio