Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

SOC Analyst & Incident Response Lead

$93k - $125.5k

Avaya

About Avaya

Avaya is an enterprise software leader that helps the world’s largest organizations and government agencies forge unbreakable connections.

The Avaya Infinity™ platform unifies fragmented customer experiences, connecting the channels, insights, technologies, and workflows that together create enduring customer and employee relationships.

We believe success is built through strong connections – with each other, with our work, and with our mission. At Avaya, you'll find a community that values your contributions and supports your growth every step of the way.

Learn more at

Job Information

Job Code: 00270114

Job Family: Information Technology

Job Function: Information Security

Job Description

We are seeking a highly skilled and experienced Tier 3 SOC Analyst who will also function as the Incident Response Lead. This is a hybrid technical-leadership position focused on managing critical security events, conducting forensic investigations, and continuously enhancing the incident response program. As a senior member of the SOC, you will be the escalation point for complex and high-impact security incidents, support forensic analysis, lead root cause investigations, and contribute to detection engineering efforts. 

Key Responsibilities

Tier 3 SOC Analyst Duties

  • Act as the final escalation point for complex security alerts and incidents identified through Azure Sentinel and other security monitoring tools. 

  • Conduct in-depth digital forensic investigations across endpoints, networks, and cloud infrastructure (Azure, M365, Microsoft Dynamics etc.). 

  • Perform malware analysis, reverse engineering, and memory/disk analysis to support incident triage and response. 

  • Provide expert-level guidance to Tier 1 and Tier 2 SOC analysts; coach and mentor to raise team capabilities. 

  • Correlate threat intelligence with incident data to understand adversary behavior and campaign objectives. 

  • Collaborate with SIEM engineers to tune, develop, and optimize detection use cases, particularly for emerging threats. 

  • Maintain documentation of playbooks, threat scenarios, and incident patterns. 

  • Assist in management of suite of security tools. 

Incident Response Lead Duties

  • Lead and coordinate the end-to-end incident response lifecycle, from detection through containment, eradication, and recovery. 

  • Own and maintain IR documentation including incident tracking, timelines, RCA, and after-action reports. 

  • Liaise with the CSIRT team and relevant business stakeholders during critical incidents. 

  • Lead post-incident reviews and facilitate lessons learned workshops, contributing to policy, procedure, and control improvements. 

  • Drive continuous process improvement across SOC and IR operations, ensuring integration with change and problem management. 

  • Ensure executive-level incident reporting and briefings are prepared and delivered as needed. 

Qualifications

Required

  • 5+ years of experience in a Security Operations Center or Incident Response role. 

  • Proven experience leading major incident response efforts (e.g., ransomware, APT, data breaches). 

  • Strong forensic analysis skills (disk, memory, log, and network forensics). 

  • Advanced proficiency in SIEM platforms (preferably Microsoft Sentinel), EDR tools (Defender for Endpoint), and forensic toolsets. 

  • Understanding of attacker TTPs mapped to MITRE ATT&CK and threat hunting methodologies. 

  • Hands-on experience with scripting and automation (e.g., PowerShell, Python) to streamline investigations and response. 

  • Knowledge of security controls, network protocols, operating systems, and cloud environments (Azure). 

  • U.S. citizenship is required for this position.
  • Strong communication skills and ability to present technical findings to non-technical stakeholders. 

  • Must be available to work outside of working hours when necessary.

Desirable Certifications

  • GIAC Certified Forensic Analyst (GCFA) or GIAC Certified Incident Handler (GCIH) 

  • CISSP, OSCP, GCIA, or equivalent 

  • Microsoft certifications: SC-200, SC-300, AZ-500 

Key Competencies

  • Calm and decisive under pressure 

  • Analytical and detail-oriented 

  • Strong leadership and collaboration skills 

  • Proactive approach to process optimization and threat mitigation 

  • Passion for continuous learning and capability development

The pay range for this opportunity is from $93,000 to $125,500 + bonus potential + benefits.  This range represents the anticipated low and high end of the salary for this position. Actual salaries will vary and are based on factors such as a candidate’s qualifications, skills, competencies.

#LI-CS1

Experience

3 - 6 Years of Experience

Education

Bachelor degree or equivalent experience

Footer

Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.

Avaya is an Equal Opportunity employer and a U.S. Federal Contractor. Our commitment to equality is a core value of Avaya. All qualified applicants and employees receive equal treatment without consideration for race, religion, sex, age, sexual orientation, gender identity, national origin, disability, status as a protected veteran or any other protected characteristic. In general, positions at Avaya require the ability to communicate and use office technology effectively. Physical requirements may vary by assigned work location. This job brief/description is subject to change. Nothing in this job description restricts Avaya right to alter the duties and responsibilities of this position at any time for any reason.

Vacancy posted 10 days ago
Similar jobs that could be interesting for youBased on the SOC Analyst & Incident Response Lead in Remote vacancy
  • $93k - $125.5k

     ...SOC Analyst & Incident Response Lead We are seeking a highly skilled and experienced Tier 3 SOC Analyst who will also function as the Incident Response Lead. This is a hybrid technical-leadership position focused on managing critical security events, conducting forensic... 
    Suggested
    For contractors
    Remote work
    Visa sponsorship

    Avaya

    United States
    1 day ago
  • A global cybersecurity consultancy is looking for a Senior Cybersecurity Analyst (SOC) to lead their SOC services. This role involves incident response, threat detection, and mentoring junior analysts within a hybrid working environment. Candidates should possess substantial... 
    Suggested
    Remote job

    S-RM Intelligence and Risk Consulting

    Seattle, WA
    3 days ago
  •  ...BlueVoyant is looking for a SOC Security Analyst L2 to enhance clients' cybersecurity in a remote setting. This role includes monitoring...  ...alerts, conducting investigations, and ensuring a robust incident response. The ideal candidate should have a strong technical... 
    Suggested
    Remote work

    BlueVoyant

    New York, NY
    2 days ago
  •  ...cybersecurity solutions provider is seeking a Remote SOC Analyst to join their team in Atlanta, Georgia. The...  ...and hold relevant security certifications. Responsibilities include investigating alerts, conducting incident response, and correlating data to identify threats... 
    Suggested
    Remote work

    Global Channel Management

    Atlanta, GA
    7 days ago
  • A leading tech company is seeking an experienced SOC Analyst to maintain cybersecurity posture through monitoring and incident response. Candidates should have at least 4 years of SOC experience and familiarity with EDR and SIEM tools. This role offers remote work options... 
    Suggested
    Remote job

    Protera

    Chicago, IL
    4 days ago
  • As a SOC Analyst (m/f/d), you will strengthen our clients’ information security through...  ...experience in analyzing security-critical incidents but also helping to further develop...  ...Operations Center. With a sense of personal responsibility and team spirit, you will be an... 
    Work from home
    Flexible hours

    Possehl Secure

    New Bremen, OH
    4 days ago
  •  ...Security Operations Center (SOC). This fully remote role involves...  ...position is suited for an analyst with a strong investigative mindset...  ...continuous learning. Key Responsibilities Perform advanced EDR...  .... Conduct initial incident response for malware, phishing... 
    Remote work
    Night shift

    Apex Systems

    United States
    1 day ago
  •  ...A leading cybersecurity firm seeks an experienced L3 SOC Analyst to join their remote team. In this role, you'll own complex security incidents, analyze and respond to high-severity events, and optimize SOC processes. Strong technical expertise in SIEM platforms and incident... 
    Remote work

    Hamilton Barnes ?

    New York, NY
    3 days ago
  • A leading real estate firm in New York is seeking a Cybersecurity/SOC Analyst II to monitor and analyze threats and incidents to enhance security operations. The ideal candidate will have...  ...bachelor's degree in a related field. Responsibilities include overseeing security... 
    Remote work

    RELATED

    New York, NY
    11 hours ago
  • Ardent is seeking a Security Operations Center (SOC) Analyst to support 24x7 security monitoring, alert triage, and incident response activities. This role involves validating alerts, conducting investigations, and coordinating incident response efforts to effectively address... 
    Remote job

    Ardent

    Washington DC
    3 days ago
  • $93k - $125.5k

     ...Avaya Corporation is seeking a highly skilled SOC Analyst & Incident Response Lead to manage critical security events and enhance the incident response program. Responsibilities include leading incident response efforts, conducting forensic investigations, and mentoring... 
    Remote work

    Avaya

    New York, NY
    3 days ago
  •  ...Ascend Learning is looking for a Senior Security Engineer to lead SOC operations and provide technical security leadership. The...  .... Candidates should have a strong cybersecurity background, incident response certification, and experience in managing SOC operations. We... 
    Work from home
    Flexible hours

    Ascend Learning

    Leawood, KS
    11 hours ago
  • $127k - $140k

    Deepwatch is hiring an Incident Response Analyst in Austin, TX to drive investigations and handle complex cybersecurity threats. This role requires...  ...will thrive in high-pressure situations and be capable of leading clients through the incident response lifecycle. Offering a... 
    Remote job

    Deepwatch

    Austin, TX
    11 hours ago
  • $127k - $140k

    Deepwatch is looking for an Incident Response Analyst located in the United States, Colorado. This mission-critical role requires a candidate proficient in leading incident response investigations and operating in high-pressure environments to defend organizations against... 
    Remote job

    Deepwatch

    Denver, CO
    3 days ago
  • Deepwatch is seeking an Incident Response Analyst to join their cybersecurity team in Boston, MA. This role requires proven experience in incident response investigations, leading engagements in high-pressure environments. Responsibilities include analyzing threats, conducting... 
    Remote job

    Deepwatch

    Boston, MA
    3 days ago
  •  ...A national financial institution is seeking an Intermediate SOC Analyst for a remote night shift position to perform security event triage and manage incidents. Ideal candidates will understand information technologies and security threats, with opportunities to develop... 
    Remote work
    Night shift

    Federal Reserve

    Oklahoma City, OK
    11 hours ago
  •  ...Corinth is seeking a SADOM Analyst to enhance security operations through expert maintenance of tools in a remote environment. The...  ...7 availability of security applications, optimizing security incident response capabilities, and requires a Bachelor's degree along with relevant... 
    Remote work

    Corinth

    New York, NY
    3 days ago
  •  ...Covenant HR is seeking a SOC Analyst for a 6-month contract role focused on monitoring and responding to security incidents in a remote capacity. The ideal candidate should have experience with CrowdStrike and SIEM platforms, strong skills in investigating security alerts... 
    Contract work
    Remote work

    Covenant HR

    New York, NY
    3 days ago
  •  ...A leading cybersecurity consulting firm is hiring a SOC Manager to lead the security operations team. This role entails overseeing SOC operations, managing incident responses, and mentoring analysts. The ideal candidate has over seven years of cybersecurity experience... 
    Remote work

    Acumenz Consulting Inc

    New York, NY
    3 days ago
  • $168k - $195k

     ...About The Role As the Principal Lead Analyst of DART , you are the ultimate technical authority for cyber defense and incident response. This is a high-impact leadership role that...  ...Force Multiplier: Elevate the entire SOC/DART capability by providing technical mentorship... 
    Work at office
    Local area
    Immediate start
    Remote work
    Relocation
    Shift work

    Corebridge Financial

    Houston, TX
    4 days ago
  •  ...Incident Response Analyst (AI Training) We're looking for experienced incident response professionals...  ...that helps AI reflect how real SOC teams operate Work independently and...  ...Work on frontier AI systems with leading AI research labs Fully remote and flexible... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    United States
    2 days ago
  •  ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of intelligent security tools - and we...  ...This is a unique opportunity to take your SOC and IR expertise beyond the day-to-day and... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Miami, FL
    3 days ago
  •  ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI research labs to build and refine AI systems designed to understand and respond to...  ...not just algorithms. Your expertise in SOC workflows, alert triage, and digital investigations... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    New York, NY
    3 days ago
  •  ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of security-focused AI systems - and we...  ...make it happen. Your hands-on experience in SOC environments, alert triage, and digital investigations... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Denver, CO
    3 days ago
  • $131.3k - $237.35k

     ...scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services is a US Government program responsible to monitor... 
    Local area
    Immediate start
    Remote work
    Flexible hours

    Leidos

    Arlington, VA
    11 hours ago
  • $72.96k - $115.2k

     ...Job Description Incident Response Center (Analyst) Job Title - IRC Analyst Summary The IRC (Incident Response Center) is the first layer...  ...IAM policies, and compliance standards like ISO 27001 and SOC 2. Qualifications Required Qualifications / Soft... 
    Full time
    Temporary work
    Remote work
    Flexible hours
    Shift work
    Night shift

    Astreya

    San Jose, CA
    2 days ago
  •  ...Incident Response Analyst (Task 4 – Federal Cybersecurity Contract) Location: Remote with occasional on-site (Washington, D.C. Metro Area) Employment...  ...~2–5+ years of experience in cybersecurity operations, SOC analysis, or incident response. ~ Direct hands-on... 
    Full time
    Contract work
    Remote work
    Monday to Friday

    Cyber Synergy

    Washington DC
    3 days ago
  •  ...Incident Response Analyst Job Location - Cincinnati, OH (Temporarily remote until Covid) Job Type - Full time/ Permanent We...  ...experience. Key Responsibilities: Experience in SOC operations, hands on experience in SIEM tool, Security event... 
    Permanent employment
    Full time
    Remote work

    Futran Tech Solutions Pvt. Ltd.

    Cincinnati, OH
    3 days ago
  •  ...Alignerr is seeking an experienced Incident Response Analyst to train and evaluate AI systems for modern digital investigations. You will leverage...  ...of 10–40 hours per week. Ideal candidates have experience in SOC or security operations and strong communication skills. #J-1... 
    Remote work
    10 hours per week

    Alignerr

    Dallas, TX
    1 day ago
  •  ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of security-focused AI systems - and we...  ...supports digital investigations. Your hands-on SOC experience is exactly what's needed to make... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Seattle, WA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to SOC Analyst & Incident Response Lead. Be the first to apply!