Cybersecurity Analyst III
On-siteIndianapolis, Indiana, United States
Job Summary
Serve as the Tier 3 technical escalation point, resolving confirmed incidents end-to-end across client environments including ransomware, business email compromise, and lateral movement. Lead forensic investigations using Velociraptor and SentinelOne, perform host and memory analysis, and conduct phishing triage with full user-impact assessment. Drive proactive threat hunting programs by developing hypothesis-driven hunts and converting findings into durable detections. Author analytical narratives for complex client deliverables, post-incident reports, and monthly client reporting. Mentor Tier 1 and Tier 2 analysts, QA escalations, and build investigation curricula to set quality standards. Partner with Cybersecurity Engineers on detection strategy, gap analysis against MITRE ATT&CK, and program-level coverage.
Required Qualifications
- 5+ years of experience in a SOC, incident response, MSSP, or security operations role, or 2+ years past a Tier 2 / Analyst II role in a comparable environment
- Demonstrated ability to independently lead complex investigations and confirmed incidents to resolution across endpoint, identity, email, and network telemetry
- Advanced command of an EDR (SentinelOne, CrowdStrike, or Defender for Endpoint) and a SIEM (Blumira, Sentinel, Splunk, or QRadar) at the query, pivot, and detection-authoring level
- Practical host and network forensics and evidence-preservation experience, including timeline reconstruction across Windows event logs, Active Directory, Entra ID, firewall, VPN, DNS, and email security logs
- Hands-on proactive threat hunting experience: building and executing hypothesis-driven hunts and converting findings into detections
- Proficient scripting in PowerShell and/or Python for investigation, log parsing, and automation
- Working fluency with the MITRE ATT&CK framework for both investigation and detection-coverage mapping
- Strong command of the incident response lifecycle, escalation criteria, and chain-of-custody / evidence-handling practices
- Ability to lead under pressure in a multi-client environment, prioritize across simultaneous active incidents, and maintain quality and clear documentation throughout
- Excellent written communication, with the ability to produce client-ready incident summaries, post-incident reports, and analytical narratives, and to mentor junior analysts effectively
- Solid fundamentals in TCP/IP, DNS, HTTP/S, Windows and Linux internals, and identity and access management
- Relevant certifications such as CompTIA CySA+, GIAC GCIH/GCIA/GCFA, BTL2, or equivalent demonstrated experience
Desired Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. Equivalent military training or certifications considered
- Advanced certifications such as GIAC GCIA, GCFA, GCFE, GNFA, GCTI, GREM, or BTL2; offensive-informed credentials (OSCP, CRTO) a strong plus given the role's detection and purple-team-support scope
- Prior MSSP experience in a multi-tenant model, including a multi-tenant PSA/ticketing platform (ConnectWise, Autotask, ServiceNow, or similar)
- Detection engineering experience: Sigma rules, KQL, and SentinelOne / Blumira query syntax, plus comfort building detections from hunt findings
- Experience with SOAR or rules-based automation and operationalizing playbooks alongside an AI Automation Engineer
- DFIR tooling depth (Velociraptor or comparable) and experience supporting legal, insurance, and breach-notification workflows during major incidents
- Vulnerability management and offensive-output review experience (ConnectSecure, Tenable, Qualys; NodeZero or comparable pentest/attack-path findings)
- Experience mentoring or formally developing junior analysts and building SOC training content
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.