Senior SOC Analyst (Cloud, Endpoint, Network, and Edge Security)
by Salla in Cybersecurity
The Senior SOC Analyst will lead advanced security monitoring, investigation, and response across cloud, endpoint, network, and edge environments at L2/L3 level. The role encompasses incident escalation, detection engineering, root cause analysis, and continuous improvement of detection coverage aligned with MITRE ATT&CK framework. The analyst will work with SIEM platforms such as Splunk or Graylog, handle AWS security logs including CloudTrail, CloudWatch, and VPC Flow Logs, manage container and Kubernetes security including Amazon EKS, and monitor edge security events with Cloudflare WAF, DDoS, Bot Management, and Zero Trust tools. The role involves developing and tuning detection rules, conducting threat investigations, performing post-incident reviews, mentoring junior SOC analysts, creating and maintaining playbooks, and collaborating with SOC leadership, Cloud Security, and DevOps teams to improve overall security posture. Knowledge of IDS/IPS, firewalls, proxies, DLP technologies, scripting (Python, PowerShell, Bash), and foundational AI/ML security concepts is required. Relevant certifications like GCIA, GCIH, CompTIA CySA+, and AWS Security Specialty are preferred.