SOC Analyst & Incident Response Lead
$93k - $125.5kAvaya
SOC Analyst & Incident Response Lead
About Avaya Avaya is an enterprise software leader that helps the world's largest organizations and government agencies forge unbreakable connections. The Avaya Infinity™ platform unifies fragmented customer experiences, connecting the channels, insights, technologies, and workflows that together create enduring customer and employee relationships. We believe success is built through strong connections – with each other, with our work, and with our mission. At Avaya, you'll find a community that values your contributions and supports your growth every step of the way.
We are seeking a highly skilled and experienced Tier 3 SOC Analyst who will also function as the Incident Response Lead. This is a hybrid technical-leadership position focused on managing critical security events, conducting forensic investigations, and continuously enhancing the incident response program. As a senior member of the SOC, you will be the escalation point for complex and high-impact security incidents, support forensic analysis, lead root cause investigations, and contribute to detection engineering efforts.
Key Responsibilities
- Tier 3 SOC Analyst Duties
- Act as the final escalation point for complex security alerts and incidents identified through Azure Sentinel and other security monitoring tools.
- Conduct in-depth digital forensic investigations across endpoints, networks, and cloud infrastructure (Azure, M365, Microsoft Dynamics etc.).
- Perform malware analysis, reverse engineering, and memory/disk analysis to support incident triage and response.
- Provide expert-level guidance to Tier 1 and Tier 2 SOC analysts; coach and mentor to raise team capabilities.
- Correlate threat intelligence with incident data to understand adversary behavior and campaign objectives.
- Collaborate with SIEM engineers to tune, develop, and optimize detection use cases, particularly for emerging threats.
- Maintain documentation of playbooks, threat scenarios, and incident patterns.
- Assist in management of suite of security tools.
- Incident Response Lead Duties
- Lead and coordinate the end-to-end incident response lifecycle, from detection through containment, eradication, and recovery.
- Own and maintain IR documentation including incident tracking, timelines, RCA, and after-action reports.
- Liaise with the CSIRT team and relevant business stakeholders during critical incidents.
- Lead post-incident reviews and facilitate lessons learned workshops, contributing to policy, procedure, and control improvements.
- Drive continuous process improvement across SOC and IR operations, ensuring integration with change and problem management.
- Ensure executive-level incident reporting and briefings are prepared and delivered as needed.
Qualifications
Required
- 5+ years of experience in a Security Operations Center or Incident Response role.
- Proven experience leading major incident response efforts (e.g., ransomware, APT, data breaches).
- Strong forensic analysis skills (disk, memory, log, and network forensics).
- Advanced proficiency in SIEM platforms (preferably Microsoft Sentinel), EDR tools (Defender for Endpoint), and forensic toolsets.
- Understanding of attacker TTPs mapped to MITRE ATT&CK and threat hunting methodologies.
- Hands-on experience with scripting and automation (e.g., PowerShell, Python) to streamline investigations and response.
- Knowledge of security controls, network protocols, operating systems, and cloud environments (Azure).
- U.S. citizenship is required for this position.
- Strong communication skills and ability to present technical findings to non-technical stakeholders.
- Must be available to work outside of working hours when necessary.
Desirable
- GIAC Certified Forensic Analyst (GCFA) or GIAC Certified Incident Handler (GCIH)
- CISSP, OSCP, GCIA, or equivalent
- Microsoft certifications: SC-200, SC-300, AZ-500
Key Competencies
Calm and decisive under pressure Analytical and detail-oriented Strong leadership and collaboration skills Proactive approach to process optimization and threat mitigation Passion for continuous learning and capability development
The pay range for this opportunity is from $93,000 to $125,500 + bonus potential + benefits. This range represents the anticipated low and high end of the salary for this position. Actual salaries will vary and are based on factors such as a candidate's qualifications, skills, competencies.
Experience 3 - 6 Years of Experience Education Bachelor degree or equivalent experience
Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future. Avaya is an Equal Opportunity employer and a U.S. Federal Contractor. Our commitment to equality is a core value of Avaya. All qualified applicants and employees receive equal treatment without consideration for race, religion, sex, age, sexual orientation, gender identity, national origin, disability, status as a protected veteran or any other protected characteristic.
- ...player is seeking a skilled Security Operations Center (SOC) Analyst to join their dynamic team. This role requires... ...capabilities, and effective communication skills. You will be responsible for analyzing security incidents, creating automations for security operations tools,...Suggested
- A global cybersecurity consultancy is looking for a Senior Cybersecurity Analyst (SOC) to lead their SOC services. This role involves incident response, threat detection, and mentoring junior analysts within a hybrid working environment. Candidates should possess substantial...SuggestedRemote job
- ...leader in Wilmington, MA, is seeking a Senior SOC Analyst with expertise in Cyber Threat Intelligence. This role involves leading investigations into advanced threats,... ...Candidates should have a strong background in incident response and detection engineering with at least 5...Suggested
- ...KPMG Careers in Miami is seeking a Senior Specialist, SOC Analyst Level II to lead advanced security investigations and mentor junior analysts. The role requires strong knowledge of Information Security and network security fundamentals. Applicants should possess extensive...Suggested
- RadNet, Inc. is seeking a SOC Tier 3 Analyst in Portland, OR. The role involves leading complex incident analysis and coordinating responses in a dynamic cybersecurity environment. The ideal candidate will have over 5 years of experience and a strong understanding of threat...Suggested
- ...Trace3 is seeking a SOC Analyst to monitor, detect, analyze, and respond to cybersecurity incidents in Fargo, North Dakota. The ideal candidate will have a Bachelor'... ...experience in a SOC or IT security operations role. Responsibilities include monitoring security alerts,...
- ...cybersecurity solutions provider is seeking a Remote SOC Analyst to join their team in Atlanta, Georgia. The... ...and hold relevant security certifications. Responsibilities include investigating alerts, conducting incident response, and correlating data to identify threats...Remote work
- ...Trace3 is looking for a SOC Analyst located in Kansas City, KS. In this role, you will be responsible for monitoring, detecting, and responding to cybersecurity incidents. Key tasks include analyzing security events from various technologies, documenting incidents, and...
- ...As a SOC Analyst (m/f/d), you will strengthen our clients’ information security through... ...experience in analyzing security-critical incidents but also helping to further develop... ...Operations Center. With a sense of personal responsibility and team spirit, you will be an...Work from homeFlexible hours
- 6AM City, LLC in False Pass, Alaska is looking for a SOC Analyst to assist in the detection, response, and remediation of cyber attacks. This role involves participating in incident response and forensic activities and working with a managed security service provider (...
$110k - $170k
Zachary Piper Solutions is looking for a SOC Analyst in McLean, VA to support a critical intelligence... ...experience in cyber threat detection and incident analysis and must possess an active TS/SCI Full Scope Polygraph. Responsibilities include detecting cyber-attacks,...- Valid8 Financial, Inc. is urgently seeking SOC Analysts for positions at the Drug Enforcement Administration Security... ...and at least 3 years of experience in Cyber Security. Responsibilities include monitoring incidents, investigating alerts, and coordinating responses to...Immediate start
- ...is seeking a Senior Security Operations Center (SOC) Analyst to lead investigations and mitigate security incidents. This role involves triaging alerts, performing... ...teams and aims to strengthen the organization’s response capabilities. #J-18808-Ljbffr Zelis Healthcare...
- Hyland is seeking a Senior Cyber Security Analyst (SOC) responsible for maintaining a secure computing environment. The role involves designing solutions, responding to incidents, and driving best practices across the organization. The ideal candidate will possess significant...Remote job
- ActiveSoft, Inc. is seeking a mid-level or senior SOC Analyst to join their Cyber Defense team in Atlanta, GA. This hybrid role allows... ...to strategic transformations, with a focus on improving incident response workflows and collaborating closely with engineers. The ideal...Remote work
- A cybersecurity firm is looking for a Tier 2 Incident Response Analyst to support law enforcement in Washington, DC. You will monitor security tools... ...have six years in cybersecurity, preferably three in SOC or IR roles. Key responsibilities include analyzing high-priority...
- ...A leading consulting firm is seeking a Security Operations Lead to oversee SOC functions and manage a team of Analysts and Engineers in Washington, DC. The ideal candidate will have... ...experience with specific expertise in incident response, threat hunting, and SIEM...
$47.5k - $68k
...Itlearn360 is seeking a Junior SOC Analyst for cybersecurity operations in Montgomery, AL. This role involves leading threat monitoring and managing incident response activities. Candidates should possess a Bachelor's degree or equivalent experience and have Top Secret...- ...Digital Management Llc is seeking a Security Operations Center (SOC) Analyst in Crownsville, MD. The role involves monitoring, detecting... ...Analyst will defend internal networks and contribute to incident response. DMI offers various benefits including health coverage,...Shift workNight shift
- Eliassen Group is seeking a SOC Analyst to join their team in Washington, DC. This role involves... ...monitoring, detection, analysis, and response to cybersecurity events across hybrid... ...experience with security monitoring and incident response, proficiency with SIEM tools like...Remote work
- ...cybersecurity firm located in Falls Church, Virginia, seeks a Security Operations Center (SOC) Lead to manage daily security operations, coordinate incident response activities, and oversee SOC analysts. Candidates should have over 12 years of experience in cybersecurity...
- Deepwatch is seeking an Incident Response Analyst to join their cybersecurity team in Boston, MA. This role requires proven experience in incident response investigations, leading engagements in high-pressure environments. Responsibilities include analyzing threats, conducting...Remote job
$127k - $140k
Deepwatch is hiring an Incident Response Analyst in Austin, TX to drive investigations and handle complex cybersecurity threats. This role requires... ...will thrive in high-pressure situations and be capable of leading clients through the incident response lifecycle. Offering a...Remote job$82k - $92k
WTW is seeking a professional in the United States for Incident & Crisis Management Support. The ideal candidate will have 4-7 years... ...in Operational Resilience and Business Continuity. Responsibilities include coordinating response activities, maintaining documentation...Temporary work$127k - $140k
Deepwatch is looking for an Incident Response Analyst located in the United States, Colorado. This mission-critical role requires a candidate proficient in leading incident response investigations and operating in high-pressure environments to defend organizations against...Remote job- ...professional to manage and enhance the security of data and systems. This role requires overseeing threat monitoring, coordinating responses to incidents, and collaborating with various teams to improve security measures. Ideal candidates will possess a bachelor's degree in a...
- ...A national financial institution is seeking an Intermediate SOC Analyst for a remote night shift position to perform security event triage and manage incidents. Ideal candidates will understand information technologies and security threats, with opportunities to develop...Remote workNight shift
- ...Corinth is seeking a SADOM Analyst to enhance security operations through expert maintenance of tools in a remote environment. The... ...7 availability of security applications, optimizing security incident response capabilities, and requires a Bachelor's degree along with relevant...Remote work
- Chenega Corporation is seeking a qualified Security Operations Center Analyst (SOC) in Arlington, Virginia. The role involves monitoring security systems, managing incidents, and utilizing various security tools to protect networks. Ideal candidates should have a Bachelor...
- Leidos is seeking a Mid‑Level Cyber Security Analyst to provide comprehensive cyber security services. This full-time position in Baltimore, MD, includes responsibilities such as incident response, malicious activity hunting, and threat analysis. Candidates should have...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to SOC Analyst & Incident Response Lead. Be the first to apply!
- bsa analyst United States
- construction analyst United States
- paid search analyst United States
- remediation analyst United States
- entry level program analyst United States
- noc analyst United States
- ehr analyst United States
- accessibility analyst United States
- carbon analyst United States
- health analyst United States

