L3 SOC Analyst
Saviynt
L3 SOC Analyst
Saviynt's AI-powered identity platform manages and governs human and non-human access to all of an organization's applications, data, and business processes. Customers trust Saviynt to safeguard their digital assets, drive operational efficiency, and reduce compliance costs. Built for the AI age, Saviynt is today helping organizations safely accelerate their deployment and usage of AI. Saviynt is recognized as the leader in identity security, with solutions that protect and empower the world's leading brands, Fortune 500 companies and government institutions.
Location: United Kingdom
Type: Full-time, permanent
Due to the nature of the UK Government projects this role supports, this position is classified as a Reserved Post. In accordance with the Civil Service Nationality Rules, paragraph 1 of Schedule 23 and paragraph 5 of Schedule 22 of the Equality Act 2010, we can only accept applications from persons with UK residency (at least five years).
Successful candidates must undergo National Security Vetting (NSV). This role requires Security Check SC level clearance as a minimum. Any offer of employment is strictly conditional upon the candidate successfully obtaining and maintaining this clearance.
To meet the vetting criteria, you will be required to have been resident in the UK for a minimum of 5 years immediately prior to your application. Failure to obtain clearance or a lapse in residency history may result in the withdrawal of the employment offer, and you will not be entitled to any compensation from Saviynt as a result.
In line with the Immigration, Asylum and Nationality Act 2006, all shortlisted candidates will be required to provide original documentation verifying their Right to Work in the UK and their British Citizenship during the initial interview stage. We conduct thorough Baseline Personnel Security Standard (BPSS) checks as a precursor to all higher-level clearances.
Role Overview
We are establishing a modern Security Operations Centre designed to deliver proactive, intelligence-driven security outcomes. Moving beyond traditional reactive monitoring, our SOC emphasises AI, automation, detection engineering, and deep cloud security visibility to identify and neutralise sophisticated threats at scale.
The L3 SOC Analyst will act as the senior technical escalation point within the SOC, leading complex investigations, driving automation initiatives, and mentoring junior analysts. This role requires strong hands-on expertise across cloud security, threat hunting, incident response, and orchestration technologies.
What You Will Do
- Incident Response & Technical Escalation
- Act as the final escalation point for complex incidents originating from L1/L2 analysis.
- Lead investigations into high-severity security events, including those impacting AWS, Kubernetes clusters and hybrid environments.
- Perform advanced forensic analysis across endpoints, cloud workloads, and network telemetry to determine root cause, impact, and remediation actions.
- Correlate telemetry from SIEM, EDR, CSPM, and cloud-native sources to identify sophisticated attack chains.
- Security Automation & SOAR Engineering
- Design, develop, and maintain automated response playbooks within the SOAR platform to improve response efficiency.
- Build and maintain automation scripts (Python, go, etc.) for alert enrichment, evidence collection, and containment.
- Integrate security platforms via APIs to enable streamlined, automated detection and response workflows.
- Identify opportunities to reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) through automation and process optimisation.
- Threat Hunting & Detection Engineering
- Conduct proactive threat hunting across enterprise and cloud environments using intelligence-driven and hypothesis-based methodologies.
- Serve as an SME for cloud security monitoring leveraging tools such as AWS GuardDuty, CloudTrail, CrowdStrike, and Proofpoint.
- Develop and tune SIEM detections, correlation rules, and EDR queries aligned to MITRE ATT&CK tactics and emerging threat intelligence.
- Mentorship & Continuous Improvement
- Provide technical mentoring and guidance to L1/L2 analysts to strengthen SOC capability.
- Maintain and enhance SOC documentation including SOPs, runbooks, and response playbooks.
- Analyse incident trends and operational metrics to recommend improvements in detection coverage, automation effectiveness, and security posture.
What You Bring
- Bachelor's degree in Computer Science, Cybersecurity, or related discipline (or equivalent industry experience).
- Extensive experience in Security Operations with demonstrable time in a senior analyst, threat hunter, or L3 role.
- Strong hands-on experience in cloud security monitoring and incident response across AWS - AWS experience is essential for this role.
- Proven scripting and automation capability using Python, Go, PowerShell, Bash, etc.
- Practical experience with SOAR platforms (e.g., CrowdStrike Fusion SOAR) and SIEM technologies (e.g., CrowdStrike Falcon, Splunk, QRadar, Microsoft Sentinel).
- Deep understanding of EDR tooling, host/network forensics, and detection engineering practices.
- Strong working knowledge of the MITRE ATT&CK framework and its application in threat detection and hunting.
Saviynt is an amazing place to work. We are a high-growth, Platform as a Service company focused on Identity Authority to power and protect the world at work. You will experience tremendous growth and learning opportunities through challenging yet rewarding work which directly impacts our customers, all within a welcoming and positive work environment. If you're resilient and enjoy working in a dynamic environment you belong with us!
Security & Compliance This role requires adherence to Saviynt's information security and privacy policies and procedures, including annual security training. Saviynt is an equal opportunity employer and we welcome everyone to our team. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
- ...SOC Analyst - L3 Budapest, HUN Are you a skilled cybersecurity professional who thrives in high-stakes environments and loves solving complex incidents? Do you want to grow your career in a dynamic, global team working with the latest in SecOps tools and threat intelligence...SuggestedFull timeRemote workShift work
- ...Quality Assurance (QA) function. Role will be primarily focused on SOC KPIs/metrics/reporting than active incident work. Assisting in... ...scheduled weekly/bi-monthly/monthly QA meetings with L2 and L3 analysts. Coordinate Roundtable topics/training and lunch & learn sessions...SuggestedWork at officeRemote workAll shifts
- ...Job Title: Tier 3 Security Analyst Location: Full Remote Contract: 6-month Contract-to-Hire Job Summary: As a Security Operations Center (SOC) Senior Analyst you will be responsible for the identification and tracking of potential security incidents across...SuggestedContract workLocal areaRemote work
- ...SOC Senior Analyst Location: REMOTE Mode: Contract (6+ Months) The SOC Senior Analyst / Incident Response Specialist is a senior-level... ...in SOC/Cyber Defense operations, with at least 3–4 years at L2/L3, incident response, or threat hunting depth. ~ Expertise...SuggestedContract workRemote work
- SOC AnalystBerlin, CT( Onsite)This is designed for a highpriority P1 role in a Security... ...proactive defence.As a P1 SOC Monitoring Analyst you will be responsible for realtime monitoring... ....Escalate confirmed incidents to L2 L3 teams with detailed analysis and recommendations...Suggested
$70k - $90k
Title: Security Operations Center (SOC) - Information Security Analyst Company: Award-Winning, $50B Publicly Traded Company Type: Full-Time Location: Hybrid - Chicagoland Area (Onsite 3-4 Days/Week) Travel: None Job Overview Join an award-winning, publicly traded company...Full time3 days per week- ...information and cyber security related projects, matters and issues. Your Role Overview: The Security Operations Center (SOC) Analyst is responsible for monitoring, detecting, investigating, and responding to cybersecurity events and alerts across the organization...Work at officeWork from homeFlexible hours2 days per week
- SMX is seeking a Senior Information Security Analyst to serve as the Security Operations Center (SOC) Team Lead responsible for managing a team of cybersecurity professionals providing continuous monitoring, incident response, RMF support, vulnerability management, and...Full timeH1b
- Syracuse University is seeking an Information Security Analyst to join the Information Security group within ITS. The role defends university... ...operations, incident response, and AI-assisted tooling in a SOC environment. The ideal candidate has a BS in a related field and...
- Sumitomo Mitsui Trust Bank, Limited is seeking an Information Security Risk Analyst (SOC) for its New York operations. The role focuses on monitoring, detecting, investigating, and responding to cybersecurity events within a hybrid work environment in New York City. The...
- ...Job Description Job Description CyberLinx Solutions is seeking a SOC Analyst (Tier 1) / Security Monitoring Analyst to support our Security Operations Center (SOC). This role is responsible for continuous monitoring of security alerts generated by SIEM, provide continuous...
$85.91k - $162.89k
...informational technology risk advisory?If yes, consider joining Baker Tilly (BT) as an IT Audit, Cybersecurity & Risk Senior Consultant (SOC focus)! Our Risk Advisory practice provides a full spectrum of services to help our clients assess their risks, develop strategies to...Full timeWork experience placementLocal areaWorldwide$50 - $60 per hour
DescriptionKforce has a client that is seeking a Senior SOC Analyst in Miami, FL.Responsibilities:* Lead investigations of complex, high severity security incidents from detection through containment, remediation, and recovery, coordinating across internal teams and the...- ...while having Fun truly makes FlexTrade a wonderful place to work.The Team:We are looking for a technically sharp and driven Senior SOC Analyst to join our cybersecurity team. You will serve as a key individual contributor within the Security Operations Center, owning day-...Remote workFlexible hours1 day per week
- A cybersecurity service provider is looking for a SOC Analyst to monitor and respond to security incidents while collaborating with various teams. The candidate will support essential cybersecurity services within a Managed Security Services environment. Ideal applicants...Remote work
- ...Senior Soc Analyst Ciklum is looking for a Senior SOC Analyst to join our team full-time in the Czech Republic. We are a custom product engineering company that supports both multinational organizations and scaling startups to solve their most complex business challenges...Full timeSummer workWork at officeRemote workHome officeFlexible hours
- ...agility, and competitive offerings to customers in the intelligence community, defense, civil, and commercial markets. Senior SOC Analyst Location: Client site Boston, MA Position Overview The Senior SOC Analyst is responsible for advanced threat detection,...Full timeWork at office
- ...Role- SOC Analyst Location - Lawrenceville, GA 30043 Either web cam or in person Interview Required skills Microsoft Defender for Identity (Threat Explorer, Tenant Block/Allow Lists, Incidents and Alerts, etc.) - Required (3+ Years...
$110k - $120k
...you want to be a part of one of the fastest-growing and largest global security operations centers? We are in search of a talented SOC Analyst to join Cegeka's Modern SOC As SOC Analyst you are a key player in investigating and responding to security threats in the...Local areaWork from homeFlexible hours$95k - $125k
...Job Title: Senior SOC Analyst Location: Cincinnati, OH (Hybrid / Remote eligible based on experience) Position Type: Full-Time Salary: $95,000 - $125,000 / year (dependent on experience) Company Overview IronRoad is conducting a confidential search...Full timeWork at officeRemote workFlexible hours- ...Job Title: Senior SOC Analyst Location: Lawrenceville, GA 30043 Duration: 4 Months Interview Mode: Either Web Cam or In Person Work Permit: USC or Green Card/Permanent Resident Job Description: Job Summary: ~ An ideal candidate will have experience...Permanent employment
- We are looking for a SOC Analyst to support ongoing security operations. This position is centered on investigating security events, coordinating response actions, and driving each assigned alert through to a complete resolution. The role will work closely with monitoring...
- ...SOAR solutionsKnowledge of deploying, developing, and maintaining SOC oriented services and systems within a hybrid on premise and... ...problems.Assist in documenting incidents and actions taken by the SOC analyst teamPrepare, provide, and discuss detailed reports with other...Temporary workWork at officeRemote work
$87.1k - $157.45k
Leidos' Digital sector has frequent opportunities available for SOC Analysts to join our team in Alexandria, VA. We recruit for these positions on a regular basis, and our recruiting team will contact candidates as positions become available.Applicants must be comfortable...Full timeWork experience placementAll shiftsShift work- ...performance culture is what allows us to drive sustained growth. Stronger together, we promote an environment where individuals can thrive.SOC Analyst IIILocation: San José, Costa RicaWorld Fuel is seeking an experienced SOC Analyst III to join our global Cybersecurity Operations...Full time
$96.09k - $111.68k
...be appropriately used during your application and interviews which can be found here.Role OverviewID.me is seeking a developing SOC Analyst to join our growing Security Operations team. This role is ideal for an early-career cybersecurity professional who wants hands-on...Full timeTemporary workWork at officeRemote workFlexible hours- ...are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference. We’re currently seeking a skilled SOC Analyst with an active Secret or Top Secret clearance to support our on-site team. Location DetailsThis is a full time on site position with...Full timeLocal areaFlexible hours
$100k - $115k
SOC Analyst Hybrid-- 2 days a week onside in Bethesda, MDThe Security Operations Center Analyst will be responsible for monitoring and analyzing security threats and implementing appropriate countermeasures to protect the organization's information assets. Key Responsibilities...2 days per week$85k - $115k
..., By Light supports defense, civilian, and commercial IT customers worldwide.Position OverviewBy Light has an opening for a CND Analyst - SOC supporting the Army National Guard (ARNG) in Falls Church, VA. This is an IT Service Management contract in support of the operation...Contract workWork experience placementRemote workWorldwideRelocationShift work$90k - $158.4k
...on a global scale, come make a difference at Fiserv.Job TitleSOC Analyst - Tier 2SOC Analyst - Tier 2 Calling all innovators - find your... ...About your role: This role is a Tier 2 Security Operations Center (SOC) analyst position on Fiserv's Cyber Threat Management team,...Full timeTemporary workCasual workH1bRemote workMonday to Friday
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to L3 SOC Analyst. Be the first to apply!
- entry level program analyst United States
- merchandising analyst United States
- accessibility analyst United States
- hybrid analyst United States
- video analyst United States
- back office analyst United States
- operational due diligence analyst United States
- integration analyst United States
- ar analyst United States
- summer analyst internship United States


