L3 SOC Analyst
Saviynt
Security Operations Centre Analyst
Saviynt's AI-powered identity platform manages and governs human and non-human access to all of an organization's applications, data, and business processes. Customers trust Saviynt to safeguard their digital assets, drive operational efficiency, and reduce compliance costs. Built for the AI age, Saviynt is today helping organizations safely accelerate their deployment and usage of AI. Saviynt is recognized as the leader in identity security, with solutions that protect and empower the world's leading brands, Fortune 500 companies and government institutions.
Location: United Kingdom
Type: Full-time, permanent
Due to the nature of the UK Government projects this role supports, this position is classified as a Reserved Post. In accordance with the Civil Service Nationality Rules, we can only accept applications from persons with UK residency (at least five years).
Successful candidates must undergo National Security Vetting (NSV). This role requires Security Check SC level clearance as a minimum. Any offer of employment is strictly conditional upon the candidate successfully obtaining and maintaining this clearance.
To meet the vetting criteria, you will be required to have been resident in the UK for a minimum of 5 years immediately prior to your application. Failure to obtain clearance or a lapse in residency history may result in the withdrawal of the employment offer, and you will not be entitled to any compensation from Saviynt as a result.
In line with the Immigration, Asylum and Nationality Act 2006, all shortlisted candidates will be required to provide original documentation verifying their Right to Work in the UK and their British Citizenship during the initial interview stage. We conduct thorough Baseline Personnel Security Standard (BPSS) checks as a precursor to all higher-level clearances.
Role Overview
We are establishing a modern Security Operations Centre designed to deliver proactive, intelligence-driven security outcomes. Moving beyond traditional reactive monitoring, our SOC emphasises AI, automation, detection engineering, and deep cloud security visibility to identify and neutralise sophisticated threats at scale.
The L3 SOC Analyst will act as the senior technical escalation point within the SOC, leading complex investigations, driving automation initiatives, and mentoring junior analysts. This role requires strong hands-on expertise across cloud security, threat hunting, incident response, and orchestration technologies.
What You Will Do
- Act as the final escalation point for complex incidents originating from L1/L2 analysis.
- Lead investigations into high-severity security events, including those impacting AWS, Kubernetes clusters and hybrid environments.
- Perform advanced forensic analysis across endpoints, cloud workloads, and network telemetry to determine root cause, impact, and remediation actions.
- Correlate telemetry from SIEM, EDR, CSPM, and cloud-native sources to identify sophisticated attack chains.
- Design, develop, and maintain automated response playbooks within the SOAR platform to improve response efficiency.
- Build and maintain automation scripts (Python, go, etc.) for alert enrichment, evidence collection, and containment.
- Integrate security platforms via APIs to enable streamlined, automated detection and response workflows.
- Identify opportunities to reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) through automation and process optimisation.
- Conduct proactive threat hunting across enterprise and cloud environments using intelligence-driven and hypothesis-based methodologies.
- Serve as an SME for cloud security monitoring leveraging tools such as AWS GuardDuty, CloudTrail, CrowdStrike, and Proofpoint.
- Develop and tune SIEM detections, correlation rules, and EDR queries aligned to MITRE ATT&CK tactics and emerging threat intelligence.
- Provide technical mentoring and guidance to L1/L2 analysts to strengthen SOC capability.
- Maintain and enhance SOC documentation including SOPs, runbooks, and response playbooks.
- Analyse incident trends and operational metrics to recommend improvements in detection coverage, automation effectiveness, and security posture.
What You Bring
- Bachelor's degree in Computer Science, Cybersecurity, or related discipline (or equivalent industry experience).
- Extensive experience in Security Operations with demonstrable time in a senior analyst, threat hunter, or L3 role.
- Strong hands-on experience in cloud security monitoring and incident response across AWS.
- Proven scripting and automation capability using Python, Go, PowerShell, Bash, etc.
- Practical experience with SOAR platforms (e.g., CrowdStrike Fusion SOAR) and SIEM technologies (e.g., CrowdStrike Falcon, Splunk, QRadar, Microsoft Sentinel).
- Deep understanding of EDR tooling, host/network forensics, and detection engineering practices.
- Strong working knowledge of the MITRE ATT&CK framework and its application in threat detection and hunting.
If required for this role, you will:
- Complete security & privacy literacy and awareness training during onboarding and annually thereafter
- Review (initially and annually thereafter), understand, and adhere to Information Security/Privacy Policies and Procedures such as:
- Data Classification, Retention & Handling Policy
- Incident Response Policy/Procedures
- Business Continuity/Disaster Recovery Policy/Procedures
- Mobile Device Policy
- Account Management Policy
- Access Control Policy
- Personnel Security Policy
- Privacy Policy
Saviynt is an amazing place to work. We are a high-growth, Platform as a Service company focused on Identity Authority to power and protect the world at work. You will experience tremendous growth and learning opportunities through challenging yet rewarding work which directly impacts our customers, all within a welcoming and positive work environment. If you're resilient and enjoy working in a dynamic environment you belong with us!
Saviynt is an equal opportunity employer and we welcome everyone to our team. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
- ...SOC Analyst - L3 Budapest, HUN Are you a skilled cybersecurity professional who thrives in high-stakes environments and loves solving complex incidents? Do you want to grow your career in a dynamic, global team working with the latest in SecOps tools and threat intelligence...SuggestedFull timeRemote workShift work
- ...We are looking for an experienced L3 SOC Analyst to join a fast-paced, 24x7 Security Operations Centre. This role is perfect for someone who thrives on ownership of complex security incidents , alert tuning , and ensuring consistent, high-quality incident response across...SuggestedRemote work
$127.6k - $175.45k
...people globally, ADI ensures today's innovators stay Ahead of What's Possible™. Learn more at and on LinkedIn and Twitter (X). L3 SOC Analyst - Cyber Threat Intelligence (CTI) Focus P4 Location: MA, USA - (HYBRID) Department: Cybersecurity - Security...SuggestedPermanent employmentWork at officeFlexible hoursShift workDay shift- ...A leading cybersecurity firm seeks an experienced L3 SOC Analyst to join their remote team. In this role, you'll own complex security incidents, analyze and respond to high-severity events, and optimize SOC processes. Strong technical expertise in SIEM platforms and incident...SuggestedRemote work
- ...SOC Quality Assurance Role This is going to be a specialized L2 role that will be working in our Quality Assurance (QA) function... ...scheduled weekly/bi-monthly/monthly QA meetings with L2 and L3 analysts. Coordinate Roundtable topics/training and lunch & learn sessions...SuggestedWork at officeAll shifts
- ...Job Title: Tier 3 Security Analyst Location: Full Remote Contract: 6-month Contract-to-Hire Job Summary: As a Security Operations Center (SOC) Senior Analyst you will be responsible for the identification and tracking of potential security incidents across...Contract workLocal areaRemote work
- ...led investigation, built for mid-market organizations and the MSPs that serve them. Position Overview AgileBlue is hiring L3 SOC Analysts to own the most critical phases of our security operation. You will lead complex investigations, handle client calls and...Full timeRemote workShift workDay shift
- ...staffing and consulting firm is seeking an Information Security Analyst to play a critical role in protecting company data and systems.... ...remote position, preferably based in Texas, involves monitoring SOC alerts, investigating incidents, and managing vulnerabilities. Candidates...Remote work
$40 per hour
...Description # Home # Search Jobs # Job Description Junior Information Security/SOC Analyst Contract: Chandler, AZ, Arizona, US Salary Range: 35.00 - 40.00 | Per Hour Job Code: 369664 End Date: 2026-06-25 Days Left: 24 days,...Hourly payContract workTemporary workWork at officeRemote workWeekend workAfternoon shift- ...Reporting Specialist based in Virginia. In this full-time role, you will support federal government initiatives by providing structured SOC reports and maintaining critical KPIs. The ideal candidate holds a bachelor’s degree and has over three years of experience in SOC...Full time
- ...SOC Analyst Level 3 Location: Iselin NJ and Bridge water NJ (2-3 days from Office) Duration: Contract/Full Time Must have: IBM QRadar... ...and incident response. The main responsibilities of a SOC L3 Technician with QROC experience include: Utilizing the QROC...Full timeContract workWork at office
- ...Title: SOC Analyst Location: San Jose, CA 95134 Schedule: Onsite M-F 8am-5pm PST Pay: up to $45/hr W2 Type: 6-12 month contract... ...activities Escalate complex or high-risk incidents to senior (L3) analysts or incident response teams with clear documentation and...Contract workShift work
- ...Senior SOC Analyst (L3) Location: Denver, CO (Hybrid) Contract - 12 Months Must need 3-4 years of Telecom domain experience in recent. Project-Specific Prerequisite Skills: Rapid7 InsightIDR (XDR+SIEM) Rapid7 InsightConnect (SOAR) Key Responsibilities...Permanent employmentContract workInterim role
$45k - $121k
...BUSINESS ANALYST L3 City: Stanford State/Province: California Posting Start Date: 4/8/26 Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients' most...Minimum wageWork at officeLocal area$40 - $42 per hour
...BUSINESS ANALYST L3 City: Austin State/Province: Texas Posting Start Date: 5/22/26 Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients' most complex...Minimum wageLocal area$75k - $90k
Position Title: SOC Analyst T3 Position Type: Full-time/exempt Clearance: n/a Location: Huntsville, AL/Remote Salary*: $75,000 - $90,000... ...platforms. Assistance with compliance mandates related to CMMC L2 and L3 implementation. Track and understand emerging security...Full timeRemote work- ...Information Security Office (ISO), Security Operations Center (SOC) The Information Security Office (ISO), Security Operations Center... ...Counsel, etc.) Required Skills: Network Security Additional Skills: Security Analyst This is a high PRIORITY requisition....Work at office
- The L3 Security Analyst is responsible for providing advanced-level security analysis and incident response within the SOC team. They will be involved in proactive threat hunting, complex incident investigations, and handling security breaches. Proactive threat hunting...
$119k - $124k
...Business Analyst It L3 Position We are currently accepting resumes for a Business Analyst IT L3 position in Torrance, CA. This position is hybrid. Salary range: $119-124k. Benefits offered: medical, vision, dental, 401 K. The selected candidate will perform the...- MarkMonitor Inc. is looking for a Governance, Risk, and Comp Security Analyst in Meridian, ID. This full-time hybrid role involves leading... ...and ensuring compliance with frameworks like ISO 27001, SOC 2, and Cyber Essentials. The ideal candidate should have 2-4 years...Full time
- ...Security Operations Analyst - Contract - 100% Remote - (US Only) The Security Operations Center (SOC) Analyst is the first line of defense for the Information Security team. This role is responsible for receiving, researching, triaging, and documenting all security...Contract workRemote work
- ...A cybersecurity service provider is looking for a SOC Analyst to monitor and respond to security incidents while collaborating with various teams. The candidate will support essential cybersecurity services within a Managed Security Services environment. Ideal applicants...Remote work
- ...Role: SOC Analyst 2 Location: 200 E Grand, Des Moines, IA 50309 (REMOTE) Duration: 12+ months contract 2nd shift [4pm to 12:30 am] Wednesday - Sunday (Monday and Tuesday off) Security Operations Center Analyst 2. This position supports...Contract workWork at officeRemote workAfternoon shift
- ...A company is looking for a Security Operations Center (SOC) Analyst (Remote). Key Responsibilities Monitor security alerts and events from various security technologies Perform triage and analysis of security events to determine severity and impact Document and escalate...Remote work
- ...Caesars is seeking a Specialist Analyst to join our cybersecurity team and play a critical role in managing and enhancing our Security Operations Center (SOC) with a focus on AWS cloud environment. In this position, you will apply your expertise in cloud security, threat...
- ...SailPoint Business Analyst L3 / Technical Analyst ~ We are currently seeking a business analyst with good level expertise in Identity and Access Management solutions, and the implementation of Identity Governance systems in the enterprise. Required Skills...
- ...solving real-world challenges and helping to build a safer digital future for our clients. About this role We are looking for a SOC Analyst - Tier 1 (f/m/x) to join our Security Operations team. In this role, you will act as the first line of defense, monitoring...InternshipRemote work
- ...About the job Remote SOC Analyst Remote SOC Analyst needs 2+ years of experience in a SOC or cybersecurity operations role. SOC Analyst requires: Security certifications such as Security+, CySA+, GCIH, GCIA, or equivalent. Experience with scripting...Remote work
$95.86k - $208.27k
...inspiration and expand your capabilities, then consider a career in Advisory. KPMG is currently seeking a Senior Specialist, SOC Analyst Level II to join our Advisory Services practice. Responsibilities: Lead advanced security event investigation and...H1bLocal areaShift workNight shiftWeekend work- ...Avint is hiring a Cybersecurity Analyst (SOC Analyst / Threat Monitoring & Response) to support and protect critical systems within the HACS program at. In this role, you’ll monitor security events, analyze threats, and support incident response efforts to maintain a...Work experience placementRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to L3 SOC Analyst. Be the first to apply!
- document review analyst United States
- facility analyst United States
- senior strategy analyst United States
- disaster recovery analyst United States
- consulting analyst United States
- contracts analyst United States
- compensation analyst United States
- due diligence analyst United States
- invoice analyst United States
- import analyst United States

