SOC Analyst & Incident Response Lead
$93k - $125.5kAvaya
About Avaya
Avaya is an enterprise software leader that helps the world’s largest organizations and government agencies forge unbreakable connections.
The Avaya Infinity™ platform unifies fragmented customer experiences, connecting the channels, insights, technologies, and workflows that together create enduring customer and employee relationships.
We believe success is built through strong connections – with each other, with our work, and with our mission. At Avaya, you'll find a community that values your contributions and supports your growth every step of the way.
Learn more at
Job Information
Job Code: 00270114
Job Family: Information Technology
Job Function: Information Security
Job Description
We are seeking a highly skilled and experienced Tier 3 SOC Analyst who will also function as the Incident Response Lead. This is a hybrid technical-leadership position focused on managing critical security events, conducting forensic investigations, and continuously enhancing the incident response program. As a senior member of the SOC, you will be the escalation point for complex and high-impact security incidents, support forensic analysis, lead root cause investigations, and contribute to detection engineering efforts.
Key Responsibilities
Tier 3 SOC Analyst Duties
Act as the final escalation point for complex security alerts and incidents identified through Azure Sentinel and other security monitoring tools.
Conduct in-depth digital forensic investigations across endpoints, networks, and cloud infrastructure (Azure, M365, Microsoft Dynamics etc.).
Perform malware analysis, reverse engineering, and memory/disk analysis to support incident triage and response.
Provide expert-level guidance to Tier 1 and Tier 2 SOC analysts; coach and mentor to raise team capabilities.
Correlate threat intelligence with incident data to understand adversary behavior and campaign objectives.
Collaborate with SIEM engineers to tune, develop, and optimize detection use cases, particularly for emerging threats.
Maintain documentation of playbooks, threat scenarios, and incident patterns.
Assist in management of suite of security tools.
Incident Response Lead Duties
Lead and coordinate the end-to-end incident response lifecycle, from detection through containment, eradication, and recovery.
Own and maintain IR documentation including incident tracking, timelines, RCA, and after-action reports.
Liaise with the CSIRT team and relevant business stakeholders during critical incidents.
Lead post-incident reviews and facilitate lessons learned workshops, contributing to policy, procedure, and control improvements.
Drive continuous process improvement across SOC and IR operations, ensuring integration with change and problem management.
Ensure executive-level incident reporting and briefings are prepared and delivered as needed.
Qualifications
Required
5+ years of experience in a Security Operations Center or Incident Response role.
Proven experience leading major incident response efforts (e.g., ransomware, APT, data breaches).
Strong forensic analysis skills (disk, memory, log, and network forensics).
Advanced proficiency in SIEM platforms (preferably Microsoft Sentinel), EDR tools (Defender for Endpoint), and forensic toolsets.
Understanding of attacker TTPs mapped to MITRE ATT&CK and threat hunting methodologies.
Hands-on experience with scripting and automation (e.g., PowerShell, Python) to streamline investigations and response.
Knowledge of security controls, network protocols, operating systems, and cloud environments (Azure).
- U.S. citizenship is required for this position.
Strong communication skills and ability to present technical findings to non-technical stakeholders.
Must be available to work outside of working hours when necessary.
Desirable Certifications
GIAC Certified Forensic Analyst (GCFA) or GIAC Certified Incident Handler (GCIH)
CISSP, OSCP, GCIA, or equivalent
Microsoft certifications: SC-200, SC-300, AZ-500
Key Competencies
Calm and decisive under pressure
Analytical and detail-oriented
Strong leadership and collaboration skills
Proactive approach to process optimization and threat mitigation
Passion for continuous learning and capability development
The pay range for this opportunity is from $93,000 to $125,500 + bonus potential + benefits. This range represents the anticipated low and high end of the salary for this position. Actual salaries will vary and are based on factors such as a candidate’s qualifications, skills, competencies.
#LI-CS1
Experience
3 - 6 Years of Experience
Education
Bachelor degree or equivalent experience
Footer
Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.
Avaya is an Equal Opportunity employer and a U.S. Federal Contractor. Our commitment to equality is a core value of Avaya. All qualified applicants and employees receive equal treatment without consideration for race, religion, sex, age, sexual orientation, gender identity, national origin, disability, status as a protected veteran or any other protected characteristic. In general, positions at Avaya require the ability to communicate and use office technology effectively. Physical requirements may vary by assigned work location. This job brief/description is subject to change. Nothing in this job description restricts Avaya right to alter the duties and responsibilities of this position at any time for any reason.
$93k - $125.5k
...SOC Analyst & Incident Response Lead We are seeking a highly skilled and experienced Tier 3 SOC Analyst who will also function as the Incident Response Lead. This is a hybrid technical-leadership position focused on managing critical security events, conducting forensic...SuggestedFor contractorsRemote workVisa sponsorship- A global cybersecurity consultancy is looking for a Senior Cybersecurity Analyst (SOC) to lead their SOC services. This role involves incident response, threat detection, and mentoring junior analysts within a hybrid working environment. Candidates should possess substantial...SuggestedRemote job
- ...BlueVoyant is looking for a SOC Security Analyst L2 to enhance clients' cybersecurity in a remote setting. This role includes monitoring... ...alerts, conducting investigations, and ensuring a robust incident response. The ideal candidate should have a strong technical...SuggestedRemote work
- ...cybersecurity solutions provider is seeking a Remote SOC Analyst to join their team in Atlanta, Georgia. The... ...and hold relevant security certifications. Responsibilities include investigating alerts, conducting incident response, and correlating data to identify threats...SuggestedRemote work
- A leading tech company is seeking an experienced SOC Analyst to maintain cybersecurity posture through monitoring and incident response. Candidates should have at least 4 years of SOC experience and familiarity with EDR and SIEM tools. This role offers remote work options...SuggestedRemote job
- As a SOC Analyst (m/f/d), you will strengthen our clients’ information security through... ...experience in analyzing security-critical incidents but also helping to further develop... ...Operations Center. With a sense of personal responsibility and team spirit, you will be an...Work from homeFlexible hours
- ...Security Operations Center (SOC). This fully remote role involves... ...position is suited for an analyst with a strong investigative mindset... ...continuous learning. Key Responsibilities Perform advanced EDR... .... Conduct initial incident response for malware, phishing...Remote workNight shift
- ...A leading cybersecurity firm seeks an experienced L3 SOC Analyst to join their remote team. In this role, you'll own complex security incidents, analyze and respond to high-severity events, and optimize SOC processes. Strong technical expertise in SIEM platforms and incident...Remote work
- A leading real estate firm in New York is seeking a Cybersecurity/SOC Analyst II to monitor and analyze threats and incidents to enhance security operations. The ideal candidate will have... ...bachelor's degree in a related field. Responsibilities include overseeing security...Remote work
- Ardent is seeking a Security Operations Center (SOC) Analyst to support 24x7 security monitoring, alert triage, and incident response activities. This role involves validating alerts, conducting investigations, and coordinating incident response efforts to effectively address...Remote job
$93k - $125.5k
...Avaya Corporation is seeking a highly skilled SOC Analyst & Incident Response Lead to manage critical security events and enhance the incident response program. Responsibilities include leading incident response efforts, conducting forensic investigations, and mentoring...Remote work- ...Ascend Learning is looking for a Senior Security Engineer to lead SOC operations and provide technical security leadership. The... .... Candidates should have a strong cybersecurity background, incident response certification, and experience in managing SOC operations. We...Work from homeFlexible hours
$127k - $140k
Deepwatch is hiring an Incident Response Analyst in Austin, TX to drive investigations and handle complex cybersecurity threats. This role requires... ...will thrive in high-pressure situations and be capable of leading clients through the incident response lifecycle. Offering a...Remote job$127k - $140k
Deepwatch is looking for an Incident Response Analyst located in the United States, Colorado. This mission-critical role requires a candidate proficient in leading incident response investigations and operating in high-pressure environments to defend organizations against...Remote job- Deepwatch is seeking an Incident Response Analyst to join their cybersecurity team in Boston, MA. This role requires proven experience in incident response investigations, leading engagements in high-pressure environments. Responsibilities include analyzing threats, conducting...Remote job
- ...A national financial institution is seeking an Intermediate SOC Analyst for a remote night shift position to perform security event triage and manage incidents. Ideal candidates will understand information technologies and security threats, with opportunities to develop...Remote workNight shift
- ...Corinth is seeking a SADOM Analyst to enhance security operations through expert maintenance of tools in a remote environment. The... ...7 availability of security applications, optimizing security incident response capabilities, and requires a Bachelor's degree along with relevant...Remote work
- ...Covenant HR is seeking a SOC Analyst for a 6-month contract role focused on monitoring and responding to security incidents in a remote capacity. The ideal candidate should have experience with CrowdStrike and SIEM platforms, strong skills in investigating security alerts...Contract workRemote work
- ...A leading cybersecurity consulting firm is hiring a SOC Manager to lead the security operations team. This role entails overseeing SOC operations, managing incident responses, and mentoring analysts. The ideal candidate has over seven years of cybersecurity experience...Remote work
$168k - $195k
...About The Role As the Principal Lead Analyst of DART , you are the ultimate technical authority for cyber defense and incident response. This is a high-impact leadership role that... ...Force Multiplier: Elevate the entire SOC/DART capability by providing technical mentorship...Work at officeLocal areaImmediate startRemote workRelocationShift work- ...Incident Response Analyst (AI Training) We're looking for experienced incident response professionals... ...that helps AI reflect how real SOC teams operate Work independently and... ...Work on frontier AI systems with leading AI research labs Fully remote and flexible...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of intelligent security tools - and we... ...This is a unique opportunity to take your SOC and IR expertise beyond the day-to-day and...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI research labs to build and refine AI systems designed to understand and respond to... ...not just algorithms. Your expertise in SOC workflows, alert triage, and digital investigations...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of security-focused AI systems - and we... ...make it happen. Your hands-on experience in SOC environments, alert triage, and digital investigations...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
$131.3k - $237.35k
...scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services is a US Government program responsible to monitor...Local areaImmediate startRemote workFlexible hours$72.96k - $115.2k
...Job Description Incident Response Center (Analyst) Job Title - IRC Analyst Summary The IRC (Incident Response Center) is the first layer... ...IAM policies, and compliance standards like ISO 27001 and SOC 2. Qualifications Required Qualifications / Soft...Full timeTemporary workRemote workFlexible hoursShift workNight shift- ...Incident Response Analyst (Task 4 – Federal Cybersecurity Contract) Location: Remote with occasional on-site (Washington, D.C. Metro Area) Employment... ...~2–5+ years of experience in cybersecurity operations, SOC analysis, or incident response. ~ Direct hands-on...Full timeContract workRemote workMonday to Friday
- ...Incident Response Analyst Job Location - Cincinnati, OH (Temporarily remote until Covid) Job Type - Full time/ Permanent We... ...experience. Key Responsibilities: Experience in SOC operations, hands on experience in SIEM tool, Security event...Permanent employmentFull timeRemote work
- ...Alignerr is seeking an experienced Incident Response Analyst to train and evaluate AI systems for modern digital investigations. You will leverage... ...of 10–40 hours per week. Ideal candidates have experience in SOC or security operations and strong communication skills. #J-1...Remote work10 hours per week
- ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of security-focused AI systems - and we... ...supports digital investigations. Your hands-on SOC experience is exactly what's needed to make...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to SOC Analyst & Incident Response Lead. Be the first to apply!

