Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

SOC Analyst & Incident Response Lead

$93k - $125.5k

Avaya

SOC Analyst & Incident Response Lead

About Avaya Avaya is an enterprise software leader that helps the world's largest organizations and government agencies forge unbreakable connections. The Avaya Infinity™ platform unifies fragmented customer experiences, connecting the channels, insights, technologies, and workflows that together create enduring customer and employee relationships. We believe success is built through strong connections – with each other, with our work, and with our mission. At Avaya, you'll find a community that values your contributions and supports your growth every step of the way.

We are seeking a highly skilled and experienced Tier 3 SOC Analyst who will also function as the Incident Response Lead. This is a hybrid technical-leadership position focused on managing critical security events, conducting forensic investigations, and continuously enhancing the incident response program. As a senior member of the SOC, you will be the escalation point for complex and high-impact security incidents, support forensic analysis, lead root cause investigations, and contribute to detection engineering efforts.

Key Responsibilities
  • Tier 3 SOC Analyst Duties
    • Act as the final escalation point for complex security alerts and incidents identified through Azure Sentinel and other security monitoring tools.
    • Conduct in-depth digital forensic investigations across endpoints, networks, and cloud infrastructure (Azure, M365, Microsoft Dynamics etc.).
    • Perform malware analysis, reverse engineering, and memory/disk analysis to support incident triage and response.
    • Provide expert-level guidance to Tier 1 and Tier 2 SOC analysts; coach and mentor to raise team capabilities.
    • Correlate threat intelligence with incident data to understand adversary behavior and campaign objectives.
    • Collaborate with SIEM engineers to tune, develop, and optimize detection use cases, particularly for emerging threats.
    • Maintain documentation of playbooks, threat scenarios, and incident patterns.
    • Assist in management of suite of security tools.
  • Incident Response Lead Duties
    • Lead and coordinate the end-to-end incident response lifecycle, from detection through containment, eradication, and recovery.
    • Own and maintain IR documentation including incident tracking, timelines, RCA, and after-action reports.
    • Liaise with the CSIRT team and relevant business stakeholders during critical incidents.
    • Lead post-incident reviews and facilitate lessons learned workshops, contributing to policy, procedure, and control improvements.
    • Drive continuous process improvement across SOC and IR operations, ensuring integration with change and problem management.
    • Ensure executive-level incident reporting and briefings are prepared and delivered as needed.
Qualifications

Required

  • 5+ years of experience in a Security Operations Center or Incident Response role.
  • Proven experience leading major incident response efforts (e.g., ransomware, APT, data breaches).
  • Strong forensic analysis skills (disk, memory, log, and network forensics).
  • Advanced proficiency in SIEM platforms (preferably Microsoft Sentinel), EDR tools (Defender for Endpoint), and forensic toolsets.
  • Understanding of attacker TTPs mapped to MITRE ATT&CK and threat hunting methodologies.
  • Hands-on experience with scripting and automation (e.g., PowerShell, Python) to streamline investigations and response.
  • Knowledge of security controls, network protocols, operating systems, and cloud environments (Azure).
  • U.S. citizenship is required for this position.
  • Strong communication skills and ability to present technical findings to non-technical stakeholders.
  • Must be available to work outside of working hours when necessary.

Desirable

  • GIAC Certified Forensic Analyst (GCFA) or GIAC Certified Incident Handler (GCIH)
  • CISSP, OSCP, GCIA, or equivalent
  • Microsoft certifications: SC-200, SC-300, AZ-500
Key Competencies

Calm and decisive under pressure Analytical and detail-oriented Strong leadership and collaboration skills Proactive approach to process optimization and threat mitigation Passion for continuous learning and capability development

The pay range for this opportunity is from $93,000 to $125,500 + bonus potential + benefits. This range represents the anticipated low and high end of the salary for this position. Actual salaries will vary and are based on factors such as a candidate's qualifications, skills, competencies.

Experience 3 - 6 Years of Experience Education Bachelor degree or equivalent experience

Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future. Avaya is an Equal Opportunity employer and a U.S. Federal Contractor. Our commitment to equality is a core value of Avaya. All qualified applicants and employees receive equal treatment without consideration for race, religion, sex, age, sexual orientation, gender identity, national origin, disability, status as a protected veteran or any other protected characteristic.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the SOC Analyst & Incident Response Lead in United States vacancy
  •  ...player is seeking a skilled Security Operations Center (SOC) Analyst to join their dynamic team. This role requires...  ...capabilities, and effective communication skills. You will be responsible for analyzing security incidents, creating automations for security operations tools,... 
    Suggested

    TechDigital Group

    Bellevue, WA
    2 days ago
  • A global cybersecurity consultancy is looking for a Senior Cybersecurity Analyst (SOC) to lead their SOC services. This role involves incident response, threat detection, and mentoring junior analysts within a hybrid working environment. Candidates should possess substantial... 
    Suggested
    Remote job

    S-RM Intelligence and Risk Consulting

    Seattle, WA
    4 days ago
  •  ...leader in Wilmington, MA, is seeking a Senior SOC Analyst with expertise in Cyber Threat Intelligence. This role involves leading investigations into advanced threats,...  ...Candidates should have a strong background in incident response and detection engineering with at least 5... 
    Suggested

    Analog Devices

    Wilmington, MA
    2 days ago
  •  ...KPMG Careers in Miami is seeking a Senior Specialist, SOC Analyst Level II to lead advanced security investigations and mentor junior analysts. The role requires strong knowledge of Information Security and network security fundamentals. Applicants should possess extensive... 
    Suggested

    KPMG Careers

    Doral, FL
    2 days ago
  • RadNet, Inc. is seeking a SOC Tier 3 Analyst in Portland, OR. The role involves leading complex incident analysis and coordinating responses in a dynamic cybersecurity environment. The ideal candidate will have over 5 years of experience and a strong understanding of threat... 
    Suggested

    RadNet

    Portland, OR
    2 days ago
  •  ...Trace3 is seeking a SOC Analyst to monitor, detect, analyze, and respond to cybersecurity incidents in Fargo, North Dakota. The ideal candidate will have a Bachelor'...  ...experience in a SOC or IT security operations role. Responsibilities include monitoring security alerts,... 

    Trace3

    Fargo, ND
    5 days ago
  •  ...cybersecurity solutions provider is seeking a Remote SOC Analyst to join their team in Atlanta, Georgia. The...  ...and hold relevant security certifications. Responsibilities include investigating alerts, conducting incident response, and correlating data to identify threats... 
    Remote work

    Global Channel Management

    Atlanta, GA
    3 days ago
  •  ...Trace3 is looking for a SOC Analyst located in Kansas City, KS. In this role, you will be responsible for monitoring, detecting, and responding to cybersecurity incidents. Key tasks include analyzing security events from various technologies, documenting incidents, and... 

    Trace3

    Kansas City, KS
    5 days ago
  •  ...As a SOC Analyst (m/f/d), you will strengthen our clients’ information security through...  ...experience in analyzing security-critical incidents but also helping to further develop...  ...Operations Center. With a sense of personal responsibility and team spirit, you will be an... 
    Work from home
    Flexible hours

    Possehl Secure

    New Bremen, OH
    1 day ago
  • 6AM City, LLC in False Pass, Alaska is looking for a SOC Analyst to assist in the detection, response, and remediation of cyber attacks. This role involves participating in incident response and forensic activities and working with a managed security service provider (... 

    6AM City, LLC

    False Pass, AK
    1 day ago
  • $110k - $170k

    Zachary Piper Solutions is looking for a SOC Analyst in McLean, VA to support a critical intelligence...  ...experience in cyber threat detection and incident analysis and must possess an active TS/SCI Full Scope Polygraph. Responsibilities include detecting cyber-attacks,... 

    Zachary Piper Solutions

    Mc Lean, VA
    4 days ago
  • Valid8 Financial, Inc. is urgently seeking SOC Analysts for positions at the Drug Enforcement Administration Security...  ...and at least 3 years of experience in Cyber Security. Responsibilities include monitoring incidents, investigating alerts, and coordinating responses to... 
    Immediate start

    VALID8 Financial

    Fairfax, VA
    1 day ago
  •  ...is seeking a Senior Security Operations Center (SOC) Analyst to lead investigations and mitigate security incidents. This role involves triaging alerts, performing...  ...teams and aims to strengthen the organization’s response capabilities. #J-18808-Ljbffr Zelis Healthcare... 

    Zelis Healthcare Inc.

    New York, NY
    3 days ago
  • Hyland is seeking a Senior Cyber Security Analyst (SOC) responsible for maintaining a secure computing environment. The role involves designing solutions, responding to incidents, and driving best practices across the organization. The ideal candidate will possess significant... 
    Remote job

    Hyland

    New York, NY
    3 days ago
  • ActiveSoft, Inc. is seeking a mid-level or senior SOC Analyst to join their Cyber Defense team in Atlanta, GA. This hybrid role allows...  ...to strategic transformations, with a focus on improving incident response workflows and collaborating closely with engineers. The ideal... 
    Remote work

    Itlearn360

    Atlanta, GA
    4 days ago
  • A cybersecurity firm is looking for a Tier 2 Incident Response Analyst to support law enforcement in Washington, DC. You will monitor security tools...  ...have six years in cybersecurity, preferably three in SOC or IR roles. Key responsibilities include analyzing high-priority... 

    Tyto Athene, LLC

    Washington DC
    3 days ago
  •  ...A leading consulting firm is seeking a Security Operations Lead to oversee SOC functions and manage a team of Analysts and Engineers in Washington, DC. The ideal candidate will have...  ...experience with specific expertise in incident response, threat hunting, and SIEM... 

    Accenture

    Washington DC
    5 days ago
  • $47.5k - $68k

     ...Itlearn360 is seeking a Junior SOC Analyst for cybersecurity operations in Montgomery, AL. This role involves leading threat monitoring and managing incident response activities. Candidates should possess a Bachelor's degree or equivalent experience and have Top Secret... 

    Itlearn360

    Montgomery, AL
    1 day ago
  •  ...Digital Management Llc is seeking a Security Operations Center (SOC) Analyst in Crownsville, MD. The role involves monitoring, detecting...  ...Analyst will defend internal networks and contribute to incident response. DMI offers various benefits including health coverage,... 
    Shift work
    Night shift

    Digital Management

    Crownsville, MD
    5 days ago
  • Eliassen Group is seeking a SOC Analyst to join their team in Washington, DC. This role involves...  ...monitoring, detection, analysis, and response to cybersecurity events across hybrid...  ...experience with security monitoring and incident response, proficiency with SIEM tools like... 
    Remote work

    Eliassen Group

    Washington DC
    2 days ago
  •  ...cybersecurity firm located in Falls Church, Virginia, seeks a Security Operations Center (SOC) Lead to manage daily security operations, coordinate incident response activities, and oversee SOC analysts. Candidates should have over 12 years of experience in cybersecurity... 

    ZTI Solutions LLC

    Falls Church, VA
    2 days ago
  • Deepwatch is seeking an Incident Response Analyst to join their cybersecurity team in Boston, MA. This role requires proven experience in incident response investigations, leading engagements in high-pressure environments. Responsibilities include analyzing threats, conducting... 
    Remote job

    Deepwatch

    Boston, MA
    4 days ago
  • $127k - $140k

    Deepwatch is hiring an Incident Response Analyst in Austin, TX to drive investigations and handle complex cybersecurity threats. This role requires...  ...will thrive in high-pressure situations and be capable of leading clients through the incident response lifecycle. Offering a... 
    Remote job

    Deepwatch

    Austin, TX
    6 days ago
  • $82k - $92k

    WTW is seeking a professional in the United States for Incident & Crisis Management Support. The ideal candidate will have 4-7 years...  ...in Operational Resilience and Business Continuity. Responsibilities include coordinating response activities, maintaining documentation... 
    Temporary work

    WTW

    New York, NY
    4 days ago
  • $127k - $140k

    Deepwatch is looking for an Incident Response Analyst located in the United States, Colorado. This mission-critical role requires a candidate proficient in leading incident response investigations and operating in high-pressure environments to defend organizations against... 
    Remote job

    Deepwatch

    Denver, CO
    4 days ago
  •  ...professional to manage and enhance the security of data and systems. This role requires overseeing threat monitoring, coordinating responses to incidents, and collaborating with various teams to improve security measures. Ideal candidates will possess a bachelor's degree in a... 

    Kaiser Permanente

    Renton, WA
    3 days ago
  •  ...A national financial institution is seeking an Intermediate SOC Analyst for a remote night shift position to perform security event triage and manage incidents. Ideal candidates will understand information technologies and security threats, with opportunities to develop... 
    Remote work
    Night shift

    Federal Reserve

    Oklahoma City, OK
    1 day ago
  •  ...Corinth is seeking a SADOM Analyst to enhance security operations through expert maintenance of tools in a remote environment. The...  ...7 availability of security applications, optimizing security incident response capabilities, and requires a Bachelor's degree along with relevant... 
    Remote work

    Corinth

    New York, NY
    4 days ago
  • Chenega Corporation is seeking a qualified Security Operations Center Analyst (SOC) in Arlington, Virginia. The role involves monitoring security systems, managing incidents, and utilizing various security tools to protect networks. Ideal candidates should have a Bachelor... 

    Chenega Corporation

    Arlington, VA
    2 days ago
  • Leidos is seeking a Mid‑Level Cyber Security Analyst to provide comprehensive cyber security services. This full-time position in Baltimore, MD, includes responsibilities such as incident response, malicious activity hunting, and threat analysis. Candidates should have... 
    Full time

    Leidos

    Bethesda, MD
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to SOC Analyst & Incident Response Lead. Be the first to apply!