The SOC Analyst Level 3 serves as the senior escalation point within the Security Operations Center, responsible for advanced threat detection, complex incident investigation, custom log parsing, and driving overall SOC maturity. This role leads high‑severity incident handling, develops advanced detection content, and mentors L1/L2 analysts while ensuring the SOC maintains a strong defensive posture against evolving threats.
Key Responsibilities
Incident Response & Threat Hunting
- Lead high‑severity and complex incident investigations, including full attack chain reconstruction and root‑cause analysis.
- Conduct proactive threat hunting across endpoint, network, cloud, identity, and application layers.
- Perform deep‑dive log analysis and handle escalations that require advanced analytical expertise.
Detection Engineering & SIEM Enhancement
- Develop and maintain use cases, correlation rules, and behavioral detections aligned with MITRE ATT&CK.
- Build custom log parsers for non‑standard log sources, ensuring accurate normalization and telemetry ingestion.
- Continuously fine‑tune detections to improve fidelity and reduce false positives.
SOC Process & Maturity Development
- Provide guidance, mentorship, and technical support to L1 and L2 SOC analysts.
- Contribute to playbook enhancement, automation recommendations, and SOC process improvements.
- Prepare detailed incident reports for both technical and executive audiences, along with remediation and hardening recommendations.
Required Skills & Competencies
- Strong hands‑on expertise with EDR, SIEM, SOAR, and multi‑source security telemetry analysis.
- Advanced knowledge of:
- Incident response & digital forensics
- Malware behavior and reverse engineering fundamentals
- Cloud security logs (Azure/AWS/GCP)
- Network forensics and packet analysis
- Identity security & authentication analytics
- Proficiency in creating and tuning detection logic using YARA, Sigma, KQL, SPL, or equivalent.
- Ability to correlate complex multi‑source logs and reconstruct sophisticated attack scenarios.
- Familiarity with regulatory and security frameworks such as NCA, SAMA, ISO 27001, and operational alignment with MITRE ATT&CK.
Preferred Experience & Certifications
- 5–8+ years of experience in SOC operations, DFIR, detection engineering, or advanced cyber defense roles.
- Relevant certifications such as:
- GIAC GCIA, GCIH, GCFA, GCTI
- CISSP
- CySA+
- Or equivalent advanced cybersecurity certifications.