FREE ACCESS
5,000–10,000 jobs/day

See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

L3 SOC Analyst, Incident Response Analyst
ProArchL3 SOC Analyst / Incident Response Analyst at ProArch tackling complex cybersecurity threats. Collaborating in Security Operations Center to improve security posture across diverse industries.
Tech Stack
Tools & technologiesCloudCyber SecurityPython
About the role
Key responsibilities & impact- **About ProArch:**
- At ProArch, we partner with businesses around the world to turn big ideas into better outcomes through IT services that span cybersecurity, cloud, data, AI, and app development.
- We’re 400+ team members strong across 3 countries (we call ourselves ProArchians)—and here’s what connects us all:
- - A love for solving real business problems
- - A belief in doing what’s right
- **What’s it like to work here?**
- - You’ll keep growing. You’ll work alongside domain experts who love to share what they know.
- - You’ll be supported, heard, and trusted to make an impact.
- - You’ll take on projects that touch industries, communities, and lives.
- - You’ll have the time to focus on what matters most in your life outside of work.
- At ProArch, you’ll be part of teams that design and deliver technology solutions solving real business challenges for our clients. With services spanning AI, Data, Application Development, Cybersecurity, Cloud & Infrastructure, and Industry Solutions, your work may involve building intelligent applications, securing business‑critical systems, or supporting cloud migrations and infrastructure modernization.
- Every role here contributes to shaping outcomes for global clients and driving meaningful impact. You’ll collaborate with experts across data, AI, engineering, cloud, cybersecurity, and infrastructure—solving complex problems with creativity, precision, and purpose. You’ll join a culture rooted in technology, curiosity, and continuous learning. A place where we move fast, trust you to make an impact, encourage innovation, and support your growth.
- **About Position:**
- At ProArch, a leader in IT security consulting with presence in the US, UK, and India, we are looking for a skilled L3 SOC Analyst / Incident Response Analyst to join our Security Operations Center (SOC) team. In this critical role, you will be responsible for advanced incident detection, investigation, and response to complex cybersecurity threats. Leveraging your extensive experience and expertise, you will lead incident response activities, perform deep-dive analysis, and coordinate with cross-functional teams to mitigate risks and strengthen our security posture. If you thrive in a dynamic, fast-paced environment and are passionate about defending organizations against sophisticated cyber threats, this position is ideal for you.Role Summary
- ProArch are seeking a highly skilled and technically strong L3 SOC Analyst / Incident Response Analyst to operate within a Managed Security Services Provider (MSSP) environment, supporting multiple customer environments across diverse industries.
- **This role is heavily focused on:**
- - Incident Response
- - Threat Investigation
- - Detection Engineering
- - DFIR Operations
- - SOC Automation
- - Threat Hunting
- - Security Platform Engineering
- - Response Workflow Optimization
- The ideal candidate combines strong incident response expertise, deep Microsoft security platform knowledge, hands-on detection engineering capability, and SOC automation experience within a fast-paced MSSP environment.
- This is not a traditional alert-monitoring SOC Analyst role. The position requires strong investigative, analytical, and response-oriented cybersecurity capabilities.
- **Key Responsibilities**
- **1. Incident Response & Threat Investigation**
- Lead and support advanced security incident investigations across multiple customer environments
- **Perform:**
- - Threat triage and validation
- - IOC analysis and threat correlation
- - Endpoint and identity investigations
- - Email security investigations
- - Cloud security incident analysis
- - Root cause analysis
- **Investigate and respond to:**
- - Account compromise incidents
- - Business Email Compromise (BEC)
- - Malware and ransomware activity
- - Privilege escalation
- - Lateral movement activity
- - Suspicious cloud and identity-based attacks
- - Advanced phishing and social engineering campaigns
- - Coordinate containment, remediation, and recovery activities with customer and internal teams
- - Support high-severity incident escalation handling and response coordination
- - Provide detailed investigation findings, timelines, impact assessments, and response recommendations
- - Conduct proactive threat hunting and threat validation activities where required
- - Support digital forensics and evidence collection activities when applicable
- **2. Detection Engineering & SIEM Operations**
- Design, develop, and maintain advanced detection rules across:
- - Microsoft Sentinel
- - Microsoft Defender XDR
- Develop and optimize:
- - KQL queries
- - Analytics rules
- - Correlation logic
- - Detection use cases
- **Perform:**
- - Detection tuning
- - False positive reduction
- - Behavioral baselining
- - Threat-based detection improvements
- - Build and maintain reusable detection content and query libraries
- - Support proactive detection engineering initiatives aligned with emerging threats and attacker techniques
- - Leverage threat intelligence and MITRE ATT&CK mapping to improve detection coverage
- **3. SOC Automation & SOAR Engineering**
- Design and implement SOC automation workflows using:
- - Microsoft Sentinel Playbooks
- - Logic Apps
- - SOAR platforms
- - API-driven integrations
- **Build workflows for:**
- - Alert enrichment
- - Incident routing
- - Automated containment actions
- - Threat intelligence enrichment
- - Ticket synchronization
- - Investigation acceleration
- - Develop scalable automation frameworks to improve SOC operational efficiency
- - Support continuous optimization of SOC workflows and automation coverage
- - Create automation standards and reusable workflow templates across customer environments
- **4. Microsoft Security Platform Operations**
- **Provide hands-on operational support, investigation, tuning, administration, and engineering for:**
- - Microsoft Defender for Endpoint (MDE)
- - Microsoft Defender XDR
- - Microsoft Defender for Identity (MDI)
- - Microsoft Defender for Office 365 (MDO)
- - Microsoft Defender for Cloud Apps (MDCA)
- - Microsoft Purview
- - Microsoft Identity Protection / Entra ID
- - Microsoft Sentinel
- **5. AI Security & Modern Threat Operations**
- Support detection and response activities related to:
- - AI-orchestrated attacks
- - Identity-based attacks
- - Cloud-native threats
- - Advanced phishing and social engineering campaigns
- - Leverage AI-assisted SOC operations and automation capabilities where applicable
- - Support modern detection strategies aligned with evolving attacker techniques
- - Evaluate opportunities to integrate AI-driven efficiencies into detection, investigation, and response workflows
- **6. Client & Operational Support**
- - Participate in customer incident discussions and escalation calls when required
- - Support onboarding of new customer environments and security integrations
- - **Maintain:**
- - Investigation playbooks
- - SOPs
- - Workflow documentation
- - Operational runbooks
- - Detection documentation
- **Collaborate closely with:**
- - SOC Operations
- - Security Engineering
- - Vendors
- - Consulting teams
- - Customer stakeholders
- - Support operational improvement initiatives across SOC and DFIR functions
Requirements
What you’ll need- Required Qualifications
- **Education**
- - Bachelor’s Degree / Graduation in: Computer Science/Information Technology/Cybersecurity or related technical field is mandatory
- - Relevant cybersecurity and automation-focused certifications will be considered an added advantage.
- **Experience**
- - 6-9 years of overall cybersecurity experience
- **Strong hands-on experience in:**
- - Incident Response
- - Threat Investigation
- - SOC Operations
- - Detection Engineering
- - DFIR activities
- - Prior Incident Response Analyst experience is highly preferred
- - Experience working within MSSP environments preferred
- - Experience supporting or collaborating with US-based teams/vendors preferred
- - Proven hands-on experience with SOAR platforms in enterprise or MSSP environments
- - Strong experience designing and implementing SOC automation workflows from scratch
- - Experience supporting enterprise Security Operations Center (SOC) environments
- - Experience with detection engineering and SIEM rule development
- **Required Technical Skills**
- Security Platforms & Technologies
- **Strong hands-on experience with:**
- - Microsoft Defender for Endpoint (MDE)
- - Microsoft Defender XDR
- - Microsoft Defender for Identity (MDI)
- - Microsoft Defender for Office 365 (MDO)
- - Microsoft Defender for Cloud Apps (MDCA)
- - Microsoft Purview
- - Microsoft Identity Protection / Entra ID
- - CrowdStrike Falcon
- - Threat Intelligence platforms
- - Microsoft Sentinel (Mandatory)
- - Defender XDR SIEM operations (Mandatory)
- - Graph API
- - Datto Autotask or equivalent ticketing systems
- - Email security solutions
- - Endpoint Detection & Response (EDR) platforms
- - Identity and authentication platforms
- - Cloud security technologies
- - Detection Engineering & Automation
- **Strong experience creating:**
- - Detection rules
- - Analytics rules
- - KQL queries
- - Detection tuning and fine-tuning
- **Experience with:**
- - SOC workflow design
- - SOC automation
- - SOAR engineering
- - API integrations
- - Workflow orchestration
- **Understanding of:**
- MITRE ATT&CK
- - Threat detection methodologies
- - Threat hunting methodologies
- - AI-driven attack techniques
- - AI use cases in SOC operations
- **Scripting & Technical Skills**
- Preferred experience with:
- - PowerShell
- - Python
- - REST APIs
- - Logic Apps
- - KQL (Mandatory)
- **Preferred Certifications**
- - Microsoft SC-200
- - Microsoft SC-401
- - Microsoft AZ-500
- - Microsoft SC-900
- - Microsoft SC-100
- - CISSP
- - Security Automation / SOAR Automation / SOAR Certifications
- **Soft Skills & Work Style**
- - Strong verbal and written communication skills with the ability to work effectively across technical and non-technical teams
- - Excellent collaboration and stakeholder coordination skills across SOC Operations, Engineering, Consulting, Vendors, and Leadership teams
- - Strong documentation and technical writing capabilities for investigations, workflows, SOPs, and operational procedures
- - Ability to work independently in a remote-first, multicultural, and fast-paced MSSP environment
- - Self-driven, proactive, and highly organized with strong ownership and accountability
- - Strong analytical, troubleshooting, and problem-solving skills
- - Comfortable managing multiple projects, priorities, and operational initiatives simultaneously
- - Team-oriented mindset with the ability to operate effectively as an individual contributor
- - Professional communication and coordination skills for working with US-based teams and vendors
- - Adaptable and flexible to evolving operational and business requirements
- **Working Model**
- - Rotational Shift (US Business Hours or After Hours)
- - Remote-first operational model
- - Participation in on-call escalation rotation for critical incidents when required
Benefits
Comp & perks- 🌐 Worldwide ❌ Jobs You've Hidden ⭐️ Saved Jobs ✅ Applied Jobs ✉️ Email Alerts 👤 Account ProArch Website LinkedIn All Job Openings 201 - 500 employees 🤖 Artificial Intelligence 🔒 Cybersecurity Artificial Intelligence
- Cybersecurity
- Cloud ProArch is a technology company that specializes in providing digital engineering, cloud services, data and AI solutions, and cybersecurity measures. They help businesses unleash their full potential by modernizing operations, protecting assets, and delivering data-driven insights. ProArch works closely with clients to eliminate roadblocks to growth and aligns advanced technology solutions with business goals to empower organizational success. As an award-winning Microsoft Gold Partner, they offer a wide range of services including AI consulting, software development, quality assurance, infrastructure management, governance, risk, and compliance solutions, and operational technology services. Their expertise extends to industries such as credit unions, power generation, and manufacturing, providing tailored solutions to meet each sector's unique challenges. L3 SOC Analyst, Incident Response Analyst 🔥 0 minutes ago 🇨🇷 Costa Rica – Remote ⏰ Full Time 🟡 Mid-level 🟠 Senior 🛡️ Security Operations Apply Now Find Hiring Managers Customize resume + cover letter Report problem ☆ Save ☑️ Mark as applied ❌ Hide 📋 Description
- **About ProArch:**
- At ProArch, we partner with businesses around the world to turn big ideas into better outcomes through IT services that span cybersecurity, cloud, data, AI, and app development.
- We’re 400+ team members strong across 3 countries (we call ourselves ProArchians)—and here’s what connects us all:
- - A love for solving real business problems
- - A belief in doing what’s right
- **What’s it like to work here?**
- - You’ll keep growing. You’ll work alongside domain experts who love to share what they know.
- - You’ll be supported, heard, and trusted to make an impact.
- - You’ll take on projects that touch industries, communities, and lives.
- - You’ll have the time to focus on what matters most in your life outside of work.
- At ProArch, you’ll be part of teams that design and deliver technology solutions solving real business challenges for our clients. With services spanning AI, Data, Application Development, Cybersecurity, Cloud & Infrastructure, and Industry Solutions, your work may involve building intelligent applications, securing business‑critical systems, or supporting cloud migrations and infrastructure modernization.
- Every role here contributes to shaping outcomes for global clients and driving meaningful impact. You’ll collaborate with experts across data, AI, engineering, cloud, cybersecurity, and infrastructure—solving complex problems with creativity, precision, and purpose. You’ll join a culture rooted in technology, curiosity, and continuous learning. A place where we move fast, trust you to make an impact, encourage innovation, and support your growth.
- **About Position:**
- At ProArch, a leader in IT security consulting with presence in the US, UK, and India, we are looking for a skilled L3 SOC Analyst / Incident Response Analyst to join our Security Operations Center (SOC) team. In this critical role, you will be responsible for advanced incident detection, investigation, and response to complex cybersecurity threats. Leveraging your extensive experience and expertise, you will lead incident response activities, perform deep-dive analysis, and coordinate with cross-functional teams to mitigate risks and strengthen our security posture. If you thrive in a dynamic, fast-paced environment and are passionate about defending organizations against sophisticated cyber threats, this position is ideal for you.Role Summary
- ProArch are seeking a highly skilled and technically strong L3 SOC Analyst / Incident Response Analyst to operate within a Managed Security Services Provider (MSSP) environment, supporting multiple customer environments across diverse industries.
- **This role is heavily focused on:**
- - Incident Response
- - Threat Investigation
- - Detection Engineering
- - DFIR Operations
- - SOC Automation
- - Threat Hunting
- - Security Platform Engineering
- - Response Workflow Optimization
- The ideal candidate combines strong incident response expertise, deep Microsoft security platform knowledge, hands-on detection engineering capability, and SOC automation experience within a fast-paced MSSP environment.
- This is not a traditional alert-monitoring SOC Analyst role. The position requires strong investigative, analytical, and response-oriented cybersecurity capabilities.
- **Key Responsibilities**
- **1. Incident Response & Threat Investigation**
- Lead and support advanced security incident investigations across multiple customer environments
- **Perform:**
- - Threat triage and validation
- - IOC analysis and threat correlation
- - Endpoint and identity investigations
- - Email security investigations
- - Cloud security incident analysis
- - Root cause analysis
- **Investigate and respond to:**
- - Account compromise incidents
- - Business Email Compromise (BEC)
- - Malware and ransomware activity
- - Privilege escalation
- - Lateral movement activity
- - Suspicious cloud and identity-based attacks
- - Advanced phishing and social engineering campaigns
- - Coordinate containment, remediation, and recovery activities with customer and internal teams
- - Support high-severity incident escalation handling and response coordination
- - Provide detailed investigation findings, timelines, impact assessments, and response recommendations
- - Conduct proactive threat hunting and threat validation activities where required
- - Support digital forensics and evidence collection activities when applicable
- **2. Detection Engineering & SIEM Operations**
- Design, develop, and maintain advanced detection rules across:
- - Microsoft Sentinel
- - Microsoft Defender XDR
- Develop and optimize:
- - KQL queries
- - Analytics rules
- - Correlation logic
- - Detection use cases
- **Perform:**
- - Detection tuning
- - False positive reduction
- - Behavioral baselining
- - Threat-based detection improvements
- - Build and maintain reusable detection content and query libraries
- - Support proactive detection engineering initiatives aligned with emerging threats and attacker techniques
- - Leverage threat intelligence and MITRE ATT&CK mapping to improve detection coverage
- **3. SOC Automation & SOAR Engineering**
- Design and implement SOC automation workflows using:
- - Microsoft Sentinel Playbooks
- - Logic Apps
- - SOAR platforms
- - API-driven integrations
- **Build workflows for:**
- - Alert enrichment
- - Incident routing
- - Automated containment actions
- - Threat intelligence enrichment
- - Ticket synchronization
- - Investigation acceleration
- - Develop scalable automation frameworks to improve SOC operational efficiency
- - Support continuous optimization of SOC workflows and automation coverage
- - Create automation standards and reusable workflow templates across customer environments
- **4. Microsoft Security Platform Operations**
- **Provide hands-on operational support, investigation, tuning, administration, and engineering for:**
- - Microsoft Defender for Endpoint (MDE)
- - Microsoft Defender XDR
- - Microsoft Defender for Identity (MDI)
- - Microsoft Defender for Office 365 (MDO)
- - Microsoft Defender for Cloud Apps (MDCA)
- - Microsoft Purview
- - Microsoft Identity Protection / Entra ID
- - Microsoft Sentinel
- **5. AI Security & Modern Threat Operations**
- Support detection and response activities related to:
- - AI-orchestrated attacks
- - Identity-based attacks
- - Cloud-native threats
- - Advanced phishing and social engineering campaigns
- - Leverage AI-assisted SOC operations and automation capabilities where applicable
- - Support modern detection strategies aligned with evolving attacker techniques
- - Evaluate opportunities to integrate AI-driven efficiencies into detection, investigation, and response workflows
- **6. Client & Operational Support**
- - Participate in customer incident discussions and escalation calls when required
- - Support onboarding of new customer environments and security integrations
- - **Maintain:**
- - Investigation playbooks
- - SOPs
- - Workflow documentation
- - Operational runbooks
- - Detection documentation
- **Collaborate closely with:**
- - SOC Operations
- - Security Engineering
- - Vendors
- - Consulting teams
- - Customer stakeholders
- - Support operational improvement initiatives across SOC and DFIR functions 🎯 Requirements
- Required Qualifications
- **Education**
- - Bachelor’s Degree / Graduation in: Computer Science/Information Technology/Cybersecurity or related technical field is mandatory
- - Relevant cybersecurity and automation-focused certifications will be considered an added advantage.
- **Experience**
- - 6-9 years of overall cybersecurity experience
- **Strong hands-on experience in:**
- - Incident Response
- - Threat Investigation
- - SOC Operations
- - Detection Engineering
- - DFIR activities
- - Prior Incident Response Analyst experience is highly preferred
- - Experience working within MSSP environments preferred
- - Experience supporting or collaborating with US-based teams/vendors preferred
- - Proven hands-on experience with SOAR platforms in enterprise or MSSP environments
- - Strong experience designing and implementing SOC automation workflows from scratch
- - Experience supporting enterprise Security Operations Center (SOC) environments
- - Experience with detection engineering and SIEM rule development
- **Required Technical Skills**
- Security Platforms & Technologies
- **Strong hands-on experience with:**
- - Microsoft Defender for Endpoint (MDE)
- - Microsoft Defender XDR
- - Microsoft Defender for Identity (MDI)
- - Microsoft Defender for Office 365 (MDO)
- - Microsoft Defender for Cloud Apps (MDCA)
- - Microsoft Purview
- - Microsoft Identity Protection / Entra ID
- - CrowdStrike Falcon
- - Threat Intelligence platforms
- - Microsoft Sentinel (Mandatory)
- - Defender XDR SIEM operations (Mandatory)
- - Graph API
- - Datto Autotask or equivalent ticketing systems
- - Email security solutions
- - Endpoint Detection & Response (EDR) platforms
- - Identity and authentication platforms
- - Cloud security technologies
- - Detection Engineering & Automation
- **Strong experience creating:**
- - Detection rules
- - Analytics rules
- - KQL queries
- - Detection tuning and fine-tuning
- **Experience with:**
- - SOC workflow design
- - SOC automation
- - SOAR engineering
- - API integrations
- - Workflow orchestration
- **Understanding of:**
- MITRE ATT&CK
- - Threat detection methodologies
- - Threat hunting methodologies
- - AI-driven attack techniques
- - AI use cases in SOC operations
- **Scripting & Technical Skills**
- Preferred experience with:
- - PowerShell
- - Python
- - REST APIs
- - Logic Apps
- - KQL (Mandatory)
- **Preferred Certifications**
- - Microsoft SC-200
- - Microsoft SC-401
- - Microsoft AZ-500
- - Microsoft SC-900
- - Microsoft SC-100
- - CISSP
- - Security Automation / SOAR Automation / SOAR Certifications
- **Soft Skills & Work Style**
- - Strong verbal and written communication skills with the ability to work effectively across technical and non-technical teams
- - Excellent collaboration and stakeholder coordination skills across SOC Operations, Engineering, Consulting, Vendors, and Leadership teams
- - Strong documentation and technical writing capabilities for investigations, workflows, SOPs, and operational procedures
- - Ability to work independently in a remote-first, multicultural, and fast-paced MSSP environment
- - Self-driven, proactive, and highly organized with strong ownership and accountability
- - Strong analytical, troubleshooting, and problem-solving skills
- - Comfortable managing multiple projects, priorities, and operational initiatives simultaneously
- - Team-oriented mindset with the ability to operate effectively as an individual contributor
- - Professional communication and coordination skills for working with US-based teams and vendors
- - Adaptable and flexible to evolving operational and business requirements
- **Working Model**
- - Rotational Shift (US Business Hours or After Hours)
- - Remote-first operational model
- - Participation in on-call escalation rotation for critical incidents when required Apply Now 📊 Check your resume score for this job Improve your chances of getting an interview by checking your resume score before you apply. Check Resume Score 🌐 Worldwide Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or support@remoterocketship.com Search Search Jobs by country Search jobs by city Search jobs by job title Search entry-level jobs Search junior-level jobs Search senior-level jobs Search jobs by tech stack Search jobs by contract type Search remote internships Search remote part-time jobs Remote jobs Anywhere in the World Companies Hiring Anywhere in the World Companies Hiring Sales People Anywhere in the World Companies Hiring Software Engineers Anywhere in the World Resources Advice Tips for finding remote jobs Interview questions and answers Resume examples Cover letter examples Post a job Affiliates Privacy policy Terms of service Job board SEO course AI Apply Copilot OpenClaw job finder Jobs by Country Remote jobs anywhere in the world (Worldwide remote jobs) Remote jobs United States Remote jobs Australia Remote jobs Brazil Remote jobs Canada Remote jobs France Remote jobs Ireland Remote jobs Germany Remote jobs Netherlands Remote jobs Spain Remote jobs UK Popular Jobs Remote data analyst jobs Remote customer support jobs Remote executive assistant jobs Remote marketing jobs Remote product designer jobs Remote product manager jobs Remote project manager jobs Remote recruiter jobs Remote sales jobs Remote software engineer jobs Jobs by Type Remote full-time jobs Remote part-time jobs Remote contract jobs Remote internship jobs Remote entry-level jobs Remote jobs with no experience required Remote junior jobs (1-3 years of experience) Digital nomad jobs Remote jobs with no degree required Freelance remote jobs Temporary remote jobs Remote jobs hiring now Stay at home mom jobs
ATS Keywords
✓ Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
Incident ResponseThreat InvestigationDetection EngineeringDFIR OperationsSOC AutomationThreat HuntingSecurity Platform EngineeringKQLSOAR EngineeringCloud Security
Soft Skills
Verbal CommunicationWritten CommunicationCollaborationStakeholder CoordinationDocumentationAnalytical SkillsProblem-SolvingOrganizational SkillsAdaptabilityTeamwork
Certifications
Microsoft SC-200Microsoft SC-401Microsoft AZ-500Microsoft SC-900Microsoft SC-100CISSPSecurity Automation CertificationSOAR Automation Certification