Qualis1 Inc.

SOC Senior Analyst - Night Shift

⭐ - Featured Role | Apply direct with Data Freelance Hub
This role is for a SOC Senior Analyst - Night Shift, a 6+ month remote contract position. Requires 7–10+ years in SOC operations, expertise in SIEM/EDR, threat hunting, and incident response, along with relevant certifications and strong scripting skills.
🌎 - Country
United States
💱 - Currency
$ USD
-
💰 - Day rate
Unknown
-
🗓️ - Date
July 24, 2026
🕒 - Duration
More than 6 months
-
🏝️ - Location
Remote
-
📄 - Contract
Unknown
-
🔒 - Security
Unknown
-
📍 - Location detailed
United States
-
🧠 - Skills detailed
#Cybersecurity #Azure #Splunk #Bash #Scala #Python #Network Security #Quality Assurance #AWS (Amazon Web Services) #Defender #KQL (Kusto Query Language) #Computer Science #GCP (Google Cloud Platform) #PCI (Payment Card Industry) #Automation #Scripting #Documentation #Leadership #Linux #Cloud #Security
Role description
Job Title: SOC Senior Analyst Location: REMOTE Mode : Contract (6+ Months) Shift timing - 1am to 10am EST The SOC Senior Analyst / Incident Response Specialist is a senior-level cybersecurity expert responsible for advanced incident investigation, threat hunting, digital forensic analysis, and incident response leadership within HCLTech’s managed Security Operations Center (SOC) – MDR model. This role is pivotal in defending customer environments from evolving cyber threats, ensuring robust detection coverage, and mentoring the next generation of cyber defenders, thus directly contributing to the organization’s security posture and client trust. Key Responsibilities • Lead deep-dive investigations of escalated security incidents, reconstructing attack chains and correlating multi-source telemetry. • Execute forensic triage of hosts, memory, disks, and logs, preserving evidence and providing comprehensive analysis for legal or regulatory needs. • Design and conduct hypothesis-driven and intelligence-led threat hunts using frameworks such as MITRE ATT&CK. • Act as incident commander for high-severity events, coordinating containment, eradication, and recovery efforts with customer and internal teams. • Develop and tune SIEM/EDR/XDR detections, authoring advanced use cases that improve detection efficacy and reduce false positives. • Define, review, and validate SOAR (Security Orchestration, Automation, and Response) playbooks and automation workflows. • Integrate threat intelligence into SOC operations, contextualizing incidents and managing the IOC lifecycle. • Produce detailed root-cause analysis and lessons-learned reports, driving continuous improvement in detection and response processes. • Audit L1/L2 analyst work, provide targeted coaching, and uphold quality assurance standards across the SOC. • Mentor junior analysts, deliver knowledge transfer sessions, and contribute to internal training and capability building. • Represent the SOC in customer governance and post-incident review forums, presenting incident trends and improvement actions. • Participate in adversary emulation and purple-team exercises, translating findings into actionable detection and response enhancements. Required Skills & Experience • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Engineering, or equivalent practical experience; Master’s preferred. • 7–10+ years of hands-on experience in SOC/Cyber Defense operations, with at least 3–4 years at L2/L3, incident response, or threat hunting depth. • Expertise across the incident lifecycle: detection, triage, investigation, containment, eradication, recovery, and post-incident review. • Deep proficiency in SIEM technologies (e.g., Splunk, Microsoft Sentinel), EDR/XDR platforms (e.g., CrowdStrike, Microsoft Defender), and forensic tools (e.g., Volatility, KAPE, Autopsy). • Advanced knowledge of Windows and Linux internals, identity security (AD, Entra ID), cloud security (Azure, AWS, GCP), and network security telemetry. • Experience designing and executing threat hunts mapped to MITRE ATT&CK and related frameworks. • Strong scripting and data querying skills (Python, PowerShell, KQL, SPL, Bash). • Familiarity with security standards such as NIST 800-61, NIST CSF, ISO 27001, PCI-DSS, and HIPAA. • Excellent written and verbal communication skills for executive briefings, documentation, and customer engagement. • Availability for on-call rotation and ability to lead response during major incidents across time zones. Preferred / Additional Requirements • Preferred certifications: GIAC (GCIA, GCIH, GCFA, GCFE, GNFA, GCTI, GDAT), Microsoft SC-200 / SC-100, Splunk Certified Analyst, CrowdStrike CCFA/CCFR/CCFH, Offensive Security (OSCP/OSDA), CISSP, CISM, CCSP, EC-Council CHFI/CTIA, cloud security certifications (AZ-500, AWS Security Specialty, GCP Professional). • Experience with SOAR platforms (Cortex XSOAR or equivalent), ITSM tools (ServiceNow SecOps), and advanced threat intelligence platforms. • Exposure to purple teaming, adversary emulation, and regulatory-driven incident response.