Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

SOC Analyst & Incident Response Lead

$93k - $125.5k

Avaya

About Avaya

Avaya is an enterprise software leader that helps the world’s largest organizations and government agencies forge unbreakable connections.

The Avaya Infinity™ platform unifies fragmented customer experiences, connecting the channels, insights, technologies, and workflows that together create enduring customer and employee relationships.

We believe success is built through strong connections – with each other, with our work, and with our mission. At Avaya, you'll find a community that values your contributions and supports your growth every step of the way.

Learn more at

Job Information

Job Code: 00270114

Job Family: Information Technology

Job Function: Information Security

Job Description

We are seeking a highly skilled and experienced Tier 3 SOC Analyst who will also function as the Incident Response Lead. This is a hybrid technical-leadership position focused on managing critical security events, conducting forensic investigations, and continuously enhancing the incident response program. As a senior member of the SOC, you will be the escalation point for complex and high-impact security incidents, support forensic analysis, lead root cause investigations, and contribute to detection engineering efforts. 

Key Responsibilities

Tier 3 SOC Analyst Duties

  • Act as the final escalation point for complex security alerts and incidents identified through Azure Sentinel and other security monitoring tools. 

  • Conduct in-depth digital forensic investigations across endpoints, networks, and cloud infrastructure (Azure, M365, Microsoft Dynamics etc.). 

  • Perform malware analysis, reverse engineering, and memory/disk analysis to support incident triage and response. 

  • Provide expert-level guidance to Tier 1 and Tier 2 SOC analysts; coach and mentor to raise team capabilities. 

  • Correlate threat intelligence with incident data to understand adversary behavior and campaign objectives. 

  • Collaborate with SIEM engineers to tune, develop, and optimize detection use cases, particularly for emerging threats. 

  • Maintain documentation of playbooks, threat scenarios, and incident patterns. 

  • Assist in management of suite of security tools. 

Incident Response Lead Duties

  • Lead and coordinate the end-to-end incident response lifecycle, from detection through containment, eradication, and recovery. 

  • Own and maintain IR documentation including incident tracking, timelines, RCA, and after-action reports. 

  • Liaise with the CSIRT team and relevant business stakeholders during critical incidents. 

  • Lead post-incident reviews and facilitate lessons learned workshops, contributing to policy, procedure, and control improvements. 

  • Drive continuous process improvement across SOC and IR operations, ensuring integration with change and problem management. 

  • Ensure executive-level incident reporting and briefings are prepared and delivered as needed. 

Qualifications

Required

  • 5+ years of experience in a Security Operations Center or Incident Response role. 

  • Proven experience leading major incident response efforts (e.g., ransomware, APT, data breaches). 

  • Strong forensic analysis skills (disk, memory, log, and network forensics). 

  • Advanced proficiency in SIEM platforms (preferably Microsoft Sentinel), EDR tools (Defender for Endpoint), and forensic toolsets. 

  • Understanding of attacker TTPs mapped to MITRE ATT&CK and threat hunting methodologies. 

  • Hands-on experience with scripting and automation (e.g., PowerShell, Python) to streamline investigations and response. 

  • Knowledge of security controls, network protocols, operating systems, and cloud environments (Azure). 

  • U.S. citizenship is required for this position.
  • Strong communication skills and ability to present technical findings to non-technical stakeholders. 

  • Must be available to work outside of working hours when necessary.

Desirable Certifications

  • GIAC Certified Forensic Analyst (GCFA) or GIAC Certified Incident Handler (GCIH) 

  • CISSP, OSCP, GCIA, or equivalent 

  • Microsoft certifications: SC-200, SC-300, AZ-500 

Key Competencies

  • Calm and decisive under pressure 

  • Analytical and detail-oriented 

  • Strong leadership and collaboration skills 

  • Proactive approach to process optimization and threat mitigation 

  • Passion for continuous learning and capability development

The pay range for this opportunity is from $93,000 to $125,500 + bonus potential + benefits.  This range represents the anticipated low and high end of the salary for this position. Actual salaries will vary and are based on factors such as a candidate’s qualifications, skills, competencies.

#LI-CS1

Experience

3 - 6 Years of Experience

Education

Bachelor degree or equivalent experience

Footer

Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.

Avaya is an Equal Opportunity employer and a U.S. Federal Contractor. Our commitment to equality is a core value of Avaya. All qualified applicants and employees receive equal treatment without consideration for race, religion, sex, age, sexual orientation, gender identity, national origin, disability, status as a protected veteran or any other protected characteristic. In general, positions at Avaya require the ability to communicate and use office technology effectively. Physical requirements may vary by assigned work location. This job brief/description is subject to change. Nothing in this job description restricts Avaya right to alter the duties and responsibilities of this position at any time for any reason.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the SOC Analyst & Incident Response Lead in Remote vacancy
  • A global cybersecurity consultancy is looking for a Senior Cybersecurity Analyst (SOC) to lead their SOC services. This role involves incident response, threat detection, and mentoring junior analysts within a hybrid working environment. Candidates should possess substantial... 
    Suggested
    Remote job

    S-RM Intelligence and Risk Consulting

    Seattle, WA
    3 days ago
  •  ...cybersecurity solutions provider is seeking a Remote SOC Analyst to join their team in Atlanta, Georgia. The...  ...and hold relevant security certifications. Responsibilities include investigating alerts, conducting incident response, and correlating data to identify threats... 
    Suggested
    Remote work

    Global Channel Management

    Atlanta, GA
    2 days ago
  • As a SOC Analyst (m/f/d), you will strengthen our clients’ information security through...  ...experience in analyzing security-critical incidents but also helping to further develop...  ...Operations Center. With a sense of personal responsibility and team spirit, you will be an... 
    Suggested
    Work from home
    Flexible hours

    Possehl Secure

    New Bremen, OH
    4 days ago
  • Hyland is seeking a Senior Cyber Security Analyst (SOC) responsible for maintaining a secure computing environment. The role involves designing solutions, responding to incidents, and driving best practices across the organization. The ideal candidate will possess significant... 
    Suggested
    Remote job

    Hyland

    New York, NY
    2 days ago
  • ActiveSoft, Inc. is seeking a mid-level or senior SOC Analyst to join their Cyber Defense team in Atlanta, GA. This hybrid role allows...  ...to strategic transformations, with a focus on improving incident response workflows and collaborating closely with engineers. The ideal... 
    Suggested
    Remote work

    Itlearn360

    Atlanta, GA
    3 days ago
  • Eliassen Group is seeking a SOC Analyst to join their team in Washington, DC. This role involves...  ...monitoring, detection, analysis, and response to cybersecurity events across hybrid...  ...experience with security monitoring and incident response, proficiency with SIEM tools like... 
    Remote work

    Eliassen Group

    Washington DC
    1 day ago
  • $127k - $140k

    Deepwatch is looking for an Incident Response Analyst located in the United States, Colorado. This mission-critical role requires a candidate proficient in leading incident response investigations and operating in high-pressure environments to defend organizations against... 
    Remote job

    Deepwatch

    Denver, CO
    3 days ago
  •  ...Corinth is seeking a SADOM Analyst to enhance security operations through expert maintenance of tools in a remote environment. The...  ...7 availability of security applications, optimizing security incident response capabilities, and requires a Bachelor's degree along with relevant... 
    Remote work

    Corinth

    New York, NY
    3 days ago
  • A national financial institution is seeking an Intermediate SOC Analyst for a remote night shift position to perform security event triage and manage incidents. Ideal candidates will understand information technologies and security threats, with opportunities to develop... 
    Remote job
    Night shift

    Federal Reserve

    Oklahoma City, OK
    4 days ago
  • $80 - $90 per hour

    Apex Systems is seeking a SOC Analyst in Denver, Colorado. The candidate will be responsible for monitoring, analyzing, and responding to security events, requiring a solid understanding of security tools and experience with SEIM platforms. The ideal applicant should have... 
    Remote job
    Hourly pay
    Contract work

    Apex Systems

    Denver, CO
    2 days ago
  • $168k - $195k

     ...principles. About The Role As the Principal Lead Analyst of DART, you are the ultimate technical authority for cyber defense and incident response. This is a high-impact leadership role...  ...Force Multiplier: Elevate the entire SOC/DART capability by providing technical mentorship... 
    16 hours
    Work at office
    Local area
    Immediate start
    Remote work
    Relocation
    Shift work

    Corebridge Financial

    Houston, TX
    4 days ago
  • A leading cybersecurity consulting firm is hiring a SOC Manager to lead the security operations team. This role entails overseeing SOC operations, managing incident responses, and mentoring analysts. The ideal candidate has over seven years of cybersecurity experience,... 
    Remote job

    Acumenz Consulting

    New York, NY
    3 days ago
  • $155.4k - $233.2k

     ...the future—you’ll build it. A Tier-3 Team Lead SOC Analyst sets and enforces operational standards, coordinates...  ..., and technology to strengthen detection, response, and reporting outcomes. Responsibilities: Ensure consistent incident handling across multiple SOC locations... 
    Full time
    Temporary work
    Work experience placement
    Work at office
    Local area
    Remote work
    Relocation
    Shift work

    AT&T

    Charlotte, NC
    3 days ago
  • Incident Response Analyst (Task 4 - Federal Cybersecurity Contract) Location: Remote with occasional on-site (Washington, D.C. Metro Area) Employment...  ...2-5+ years of experience in cybersecurity operations, SOC analysis, or incident response. Direct hands‑on experience... 
    Full time
    Contract work
    Remote work
    Monday to Friday

    Cyber Synergy

    Washington DC
    2 days ago
  • Alignerr is hiring an Incident Response Analyst to enhance AI-driven security systems by evaluating real incident data. This remote role allows for...  ...The ideal candidate will have over 2 years of experience in SOC or incident response, with expertise in SIEM platforms and a... 
    Remote job
    10 hours per week
    Flexible hours

    Alignerr

    Seattle, WA
    21 hours ago
  •  ...join us! About the Role: We are hiring a Staff Incident Response Analyst to serve as the technical escalation point for our L2 SOC analysts and 24/7 managed detection and...  ...across all severity levels; take over technical lead role on Sev2+ Scope incidents accurately and... 
    Remote work

    BetterCloud

    Indianapolis, IN
    3 days ago
  • ArdentMC is seeking a Security Operations Center (SOC) Analyst for a remote position to support 24x7 security monitoring and incident response activities. The successful candidate will have at least 4 years of experience in a SOC role and a Bachelor’s degree in Cybersecurity... 
    Remote job
    Flexible hours

    ArdentMC

    New York, NY
    3 days ago
  •  ...We’re looking for a Sr. Lead Incident Response / Supervisor Level 5 professional to help protect the integrity, reliability, and security of the enterprise systems, data, and networks. In this role, you’ll lead complex security initiatives, guide cross‑functional teams... 
    Remote work

    Wavestrong

    United States
    5 days ago
  • $30 - $39 per hour

     ...Cayuse Holdings is seeking an ITSM Incident Response Analyst to support and respond to incidents remotely. The role involves overseeing incident documentation, restoring failed IT applications, and managing critical events alongside technical support teams. With a contract... 
    Contract work
    Immediate start
    Remote work

    Cayuse Holdings

    Richmond, VA
    4 days ago
  •  ...Cayuse Holdings is seeking an ITSM Incident Response Analyst for remote work. This role involves supporting incident management processes and working with Service Desk teams to resolve IT issues effectively. Ideal candidates have strong skills in Service Now and ITIL.... 
    Contract work
    Remote work

    Cayuse Holdings

    Topeka, KS
    4 days ago
  • $30 - $39 per hour

     ...Cayuse Holdings is seeking an ITSM Incident Response Analyst to support and respond to IT incidents. This role involves overseeing incident documentation and collaborating with technical support teams. The ideal candidate will have strong Service Now skills and experience... 
    Contract work
    Remote work

    Cayuse Holdings

    Lincoln, NE
    4 days ago
  • ## Job Description# Incident Response Analyst - FULLY REMOTE* Review current configurations of production information systems and networks against compliance standards.* Prepare for the prevention and resolution of security breaches and ensure incident response processes... 
    Remote work

    Apex Systems

    United States
    1 day ago
  • $120.19k - $223.21k

     ...of expertise, Strada blends leading-edge technology with human...  ...highly skilled and motivated Incident Response Lead to join our cybersecurity...  ...partner closely with the SOC Leads, who own monitoring...  ...incidents and mentor responders, analysts, and technical stakeholders... 
    Full time
    Local area
    Remote work
    Worldwide
    Visa sponsorship
    Flexible hours

    Strada

    United States
    3 days ago
  • $139.99k - $174.01k

     ...Our partner is looking for a Lead PCI Analyst based in United States....  ...coordinate cross-functional responses to compliance events. With exposure...  ...workflows. Oversee PCI incident and event response,...  ...with PCI DSS, ISO 27001, and SOC frameworks. Requirements:... 
    Remote job
    Full time
    Flexible hours

    jobgether

    United States
    6 days ago
  • $127k - $140k

     ...comprehensive detection and automated response to cyber threats together with tailored...  ...Manager of Adversary Response, the Incident Response Analyst operates on the front lines of active...  ...during live incident engagements, you will lead hands-on investigations into complex... 
    Permanent employment
    Work experience placement
    Work at office
    Remote work
    Work from home
    Home office
    Flexible hours

    Deepwatch

    Washington DC
    4 days ago
  • Cayuse Holdings is looking for an ITSM Incident Response Analyst to support and manage incident responses effectively within their IT teams. You will oversee incident documentation and ensure alignment with ITIL processes for consistent service management. The ideal candidate... 
    Remote job
    Contract work

    Cayuse Holdings

    Denver, CO
    3 days ago
  • Cayuse Holdings is seeking an ITSM Incident Response Analyst to support and respond to incidents while collaborating with the Service Desk and Desktop support teams. This remote position emphasizes adherence to ITIL-aligned processes, ensuring effective incident management... 
    Remote job
    Contract work

    Cayuse Holdings

    Washington DC
    4 days ago
  • Experis ManpowerGroup Sp. z o.o. is looking for a Junior to Early Mid‑Level Cyber Security Incident Response Analyst to support daily incident response operations in a fully remote role. Key responsibilities include monitoring and responding to security incidents, with... 
    Remote job
    Contract work
    Weekend work

    Experis ManpowerGroup Sp. z o.o.

    Denver, CO
    2 days ago
  • Qualifications At least 2 years of incident response experience Experience with Crowdstrike and Web Application Firewall (WAF) Proficient with at least one scripting language (Python, Java, PowerShell, Bash) Cloud experience is a plus Responsibilities Address cybersecurity... 
    Remote work
    Visa sponsorship

    Breeze End Technology, LLC

    Alexandria, VA
    3 days ago
  •  ...SkillBridge participation and is not eligible for direct hire. CrowdStrike is looking for a highly motivated, self‑driven Incident Response Analyst to support the Incident Response lifecycle via triage and investigation of detections and take action as appropriate (e.g.... 
    Remote job
    Full time
    Temporary work
    Internship
    Local area

    CrowdStrike

    New York, NY
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to SOC Analyst & Incident Response Lead. Be the first to apply!