Sorenson Communications
Overview
Senior SOC Analyst role at Sorenson Communications. The Senior SOC Analyst will serve as a senior lead responsible for monitoring, investigating, and responding to security threats. This role focuses on leading security investigations, incident response processes, threat detection, and security control validation to ensure a strong security posture across the organization. The position also involves assessing MSSP performance, tuning security controls, and validating security technologies such as firewalls, cloud security configurations, and endpoint security solutions. Essential Duties and Responsibilities
Oversee internal and external SOC resources (MSSP or internal teams), ensuring seamless collaboration, alignment and effective threat response. Define and manage SOC and Incident Response workflows, processes, and escalation procedures to maintain operational efficiency. Implement and maintain SOC and IR playbooks, runbooks, and automation to improve response times and reduce manual effort. Actively monitor security logs, SIEM alerts, and endpoint detections to identify potential threats. Lead and manage security investigations, ensuring accurate root cause analysis and timely mitigation. Manage and enhance incident response (IR) processes, including triage, containment, eradication, and recovery efforts. Leverage MITRE ATT&CK and similar frameworks to map incidents, assess gaps, and develop new detection logic. Conduct forensic analysis, malware investigations, and threat hunting to identify indicators of compromise (IOCs) and emerging threats. Utilize SOAR platforms to automate response actions and improve incident handling efficiency. Investigate security incidents and recommend remediation actions to IT and business units. Work with security engineers to fine-tune SIEM correlation rules and alerting logic. Threat Intelligence & Proactive Defense
Integrate external threat intelligence feeds into security monitoring tools and enhance threat detection and response capabilities. Conduct threat-hunting exercises to detect malicious activity not flagged by traditional monitoring. Track emerging threats, zero-day vulnerabilities, security advisories, adversary tactics, and security trends relevant to the environment. Provide executive reporting on incident trends, SOC effectiveness, and security improvements. Participate in red teaming and blue teaming and IR exercises. Vulnerability Management & Compliance
Support vulnerability scanning and analysis, ensuring full visibility into security gaps. Collaborate with IT teams to enforce patch compliance, particularly for critical and high-severity vulnerabilities. Provide reports on vulnerability trends, security risks, and remediation progress. Track and document compliance metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). Conduct firewall rule reviews, cloud security assessments, and network security testing. Evaluate SIEM rules, endpoint security configurations, and cloud security controls for misconfigurations. Support vulnerability management efforts, ensuring timely remediation of identified risks. Assist in evaluating and testing new security tools, integrating them into SOC workflows. MSSP Oversight & Performance Management
Act as a primary escalation point for MSSP investigations, ensuring appropriate response times and quality. Continuously assess MSSP effectiveness, ensuring SLAs and contractual obligations are met. Provide feedback on SOC detections, response procedures, and incident reporting from the MSSP. Partner with vendors to optimize security monitoring tools and improve detection logic. Education
Minimum of 4 Year / Bachelors Degree in related field Required Qualifications (Knowledge And Experience)
7+ years of experience in Security Operations, Incident Response, and Threat Detection. 3+ years leading cybersecurity investigations, incident handling, and response coordination. 3+ years of experience managing and working with MSSPs, ensuring effective threat monitoring and response. Certifications & Knowledge
CompTIA Security+, CEH (Certified Ethical Hacker), or GCIH (GIAC Certified Incident Handler), or GCIA (GIAC Certified Intrusion Analyst) CISSP or CISM or SOC Analyst-focused certifications AWS/Azure security certifications Knowledge, Skills, and Abilities
Extensive experience with SIEM solutions (e.g. DataSet, Splunk, Elastic). Extensive experience managing/EDR solutions (SentinelOne, CrowdStrike, Microsoft Defender ATP). Familiarity with Rapid7 or similar vulnerability management platforms. Basic scripting (Python, PowerShell, Bash) for security automation. Strong understanding of MITRE ATT&CK, NIST CSF, and incident response frameworks. Strong network security, system hardening, and vulnerability management knowledge. Hands-on experience with forensics, log analysis, and threat-hunting methodologies. Experience with firewall reviews, cloud security validation, and SIEM tuning. Strong analytical, investigative, and communication skills; ability to work with IT, legal, and executive teams. Ability to work independently and in a fast-paced environment; strong project management and leadership abilities. Team player with a positive attitude, self-motivated and detail-oriented. Benefits
Paid Vacation Time, Paid Sick Time, and Paid Holidays 401k 6% match with immediate vesting Nationwide Medical Insurance plans (Medical, Dental/Orthodontia, Vision) TeleDoc, HSA company match 3 Medical plan options including a Low Deductible PPO Employee Assistance Program Engaged Employee Resource Groups Learning and Career Development opportunities Pay & Miscellaneous
Pay range: Actual pay may vary based on job-related factors including knowledge, skills, experience, and location. Eligible for incentive compensation where applicable. Applicants must be legally eligible to work in the United States. Visa sponsorship is not available for this role. Equal Employment Opportunity
Sorenson Communications is an Equal Opportunity, Affirmative Action Employer. Company Summary
Our mission is to harness the power of language, connecting diverse people and enriching the human experience. Our vision is to provide global language services that expand opportunities, nurture belonging, and empower the world to connect beyond words. Sorenson supports accessibility and inclusion through its language services and technology solutions. The company emphasizes values such as Customer First, Can-Do Attitude, Collective Action, Growth Mindset, Ownership, and Connect Direct.
#J-18808-Ljbffr
Senior SOC Analyst role at Sorenson Communications. The Senior SOC Analyst will serve as a senior lead responsible for monitoring, investigating, and responding to security threats. This role focuses on leading security investigations, incident response processes, threat detection, and security control validation to ensure a strong security posture across the organization. The position also involves assessing MSSP performance, tuning security controls, and validating security technologies such as firewalls, cloud security configurations, and endpoint security solutions. Essential Duties and Responsibilities
Oversee internal and external SOC resources (MSSP or internal teams), ensuring seamless collaboration, alignment and effective threat response. Define and manage SOC and Incident Response workflows, processes, and escalation procedures to maintain operational efficiency. Implement and maintain SOC and IR playbooks, runbooks, and automation to improve response times and reduce manual effort. Actively monitor security logs, SIEM alerts, and endpoint detections to identify potential threats. Lead and manage security investigations, ensuring accurate root cause analysis and timely mitigation. Manage and enhance incident response (IR) processes, including triage, containment, eradication, and recovery efforts. Leverage MITRE ATT&CK and similar frameworks to map incidents, assess gaps, and develop new detection logic. Conduct forensic analysis, malware investigations, and threat hunting to identify indicators of compromise (IOCs) and emerging threats. Utilize SOAR platforms to automate response actions and improve incident handling efficiency. Investigate security incidents and recommend remediation actions to IT and business units. Work with security engineers to fine-tune SIEM correlation rules and alerting logic. Threat Intelligence & Proactive Defense
Integrate external threat intelligence feeds into security monitoring tools and enhance threat detection and response capabilities. Conduct threat-hunting exercises to detect malicious activity not flagged by traditional monitoring. Track emerging threats, zero-day vulnerabilities, security advisories, adversary tactics, and security trends relevant to the environment. Provide executive reporting on incident trends, SOC effectiveness, and security improvements. Participate in red teaming and blue teaming and IR exercises. Vulnerability Management & Compliance
Support vulnerability scanning and analysis, ensuring full visibility into security gaps. Collaborate with IT teams to enforce patch compliance, particularly for critical and high-severity vulnerabilities. Provide reports on vulnerability trends, security risks, and remediation progress. Track and document compliance metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). Conduct firewall rule reviews, cloud security assessments, and network security testing. Evaluate SIEM rules, endpoint security configurations, and cloud security controls for misconfigurations. Support vulnerability management efforts, ensuring timely remediation of identified risks. Assist in evaluating and testing new security tools, integrating them into SOC workflows. MSSP Oversight & Performance Management
Act as a primary escalation point for MSSP investigations, ensuring appropriate response times and quality. Continuously assess MSSP effectiveness, ensuring SLAs and contractual obligations are met. Provide feedback on SOC detections, response procedures, and incident reporting from the MSSP. Partner with vendors to optimize security monitoring tools and improve detection logic. Education
Minimum of 4 Year / Bachelors Degree in related field Required Qualifications (Knowledge And Experience)
7+ years of experience in Security Operations, Incident Response, and Threat Detection. 3+ years leading cybersecurity investigations, incident handling, and response coordination. 3+ years of experience managing and working with MSSPs, ensuring effective threat monitoring and response. Certifications & Knowledge
CompTIA Security+, CEH (Certified Ethical Hacker), or GCIH (GIAC Certified Incident Handler), or GCIA (GIAC Certified Intrusion Analyst) CISSP or CISM or SOC Analyst-focused certifications AWS/Azure security certifications Knowledge, Skills, and Abilities
Extensive experience with SIEM solutions (e.g. DataSet, Splunk, Elastic). Extensive experience managing/EDR solutions (SentinelOne, CrowdStrike, Microsoft Defender ATP). Familiarity with Rapid7 or similar vulnerability management platforms. Basic scripting (Python, PowerShell, Bash) for security automation. Strong understanding of MITRE ATT&CK, NIST CSF, and incident response frameworks. Strong network security, system hardening, and vulnerability management knowledge. Hands-on experience with forensics, log analysis, and threat-hunting methodologies. Experience with firewall reviews, cloud security validation, and SIEM tuning. Strong analytical, investigative, and communication skills; ability to work with IT, legal, and executive teams. Ability to work independently and in a fast-paced environment; strong project management and leadership abilities. Team player with a positive attitude, self-motivated and detail-oriented. Benefits
Paid Vacation Time, Paid Sick Time, and Paid Holidays 401k 6% match with immediate vesting Nationwide Medical Insurance plans (Medical, Dental/Orthodontia, Vision) TeleDoc, HSA company match 3 Medical plan options including a Low Deductible PPO Employee Assistance Program Engaged Employee Resource Groups Learning and Career Development opportunities Pay & Miscellaneous
Pay range: Actual pay may vary based on job-related factors including knowledge, skills, experience, and location. Eligible for incentive compensation where applicable. Applicants must be legally eligible to work in the United States. Visa sponsorship is not available for this role. Equal Employment Opportunity
Sorenson Communications is an Equal Opportunity, Affirmative Action Employer. Company Summary
Our mission is to harness the power of language, connecting diverse people and enriching the human experience. Our vision is to provide global language services that expand opportunities, nurture belonging, and empower the world to connect beyond words. Sorenson supports accessibility and inclusion through its language services and technology solutions. The company emphasizes values such as Customer First, Can-Do Attitude, Collective Action, Growth Mindset, Ownership, and Connect Direct.
#J-18808-Ljbffr