Lead SOC Analyst (L3)
About This Role
Lead SOC Analyst (L3)
Role Overview
We are looking for an experienced L3 SOC Analyst who can take ownership of major incident response efforts. This senior role blends hands‑on expertise with leadership: you’ll guide SOC analysts, steer complex investigations, shape long‑term SOC strategy, and help drive the evolution toward AI‑enhanced security operations.
Key Responsibilities
- Oversee and support day‑to‑day SOC operations at the L3 level, ensuring rapid and accurate handling of advanced threats.
- Act as the Lead Incident Responder , directing major investigations from initial detection through containment, eradication, and recovery.
- Mentor and coach SOC analysts across all tiers, fostering technical growth and operational excellence.
- Identify opportunities to streamline SOC workflows, enhance automation, and improve detection and response capabilities.
- Develop and maintain a forward‑looking SOC roadmap aligned with business needs and emerging threat trends.
- Contribute to the design and implementation of AI‑driven SOC capabilities, enabling intelligent triage, automated response, and next‑generation detection.
- Collaborate with Threat Intelligence, Security Engineering, and DevOps teams to strengthen detection coverage and SOC readiness.
- Produce detailed incident documentation and drive continuous improvement through structured post‑incident reviews.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent hands‑on experience.
- 6+ years in SOC or security operations roles, including at least 1–2 years in a senior, L3, or leadership capacity.
- Demonstrated experience leading incident response efforts in high‑pressure environments.
Core Competencies
- Advanced incident handling, threat containment, and crisis coordination.
- Strong proficiency with SIEM platforms (Sentinel, Elastic) and EDR tools (Defender, CrowdStrike).
- Experience improving SOC performance through KPIs, coverage metrics, and quality assessments.
Preferred Certifications
- GIAC Incident Handler (GCIH)
- GIAC Intrusion Analyst (GCIA)
- CREST Registered Intrusion Analyst (CRIA)
- GIAC Network Forensic Analyst (GNFA)
- GIAC Certified Forensic Analyst (GCFA)
Similar Jobs
Lead SOC Engineer (OT Cybersecurity)
CPX · Abu Dhabi
Overview OT Detection is a senior technical and engineering leader role focused on designing and implementing advanced threat detection capabilities within OT environments. Operating within CPX’s hybrid Security Operati
1 weeks ago
Generate Resume ↗Lead SOC Engineer (SIEM)
CPX · Abu Dhabi
Overview The Lead Engineer – SOC (SIEM) is a critical role responsible for delivering SIEM management services, particularly focusing on Splunk SIEM and Splunk UEBA, within the Security Operations Center (SOC). Working
1 weeks ago
Generate Resume ↗Lead SOC Engineer (SIEM & SOAR)
CPX · Abu Dhabi
Overview The Lead Engineer – SOC (SIEM \& SOAR) is a critical role responsible for delivering SIEM /SOAR management services, particularly focusing on Splunk SIEM and SOAR, within the Security Operations Center (SOC). T
1 weeks ago
Generate Resume ↗Lead SOC Engineer (NDR and VM)
CPX · Abu Dhabi
Overview The Lead Engineer – SOC (NDR \& VM) will be a technically proficient Lead Engineer to join our Security Operations Center (SOC) team. This individual contributor role focuses on enhancing threat detection and r
1 weeks ago
Generate Resume ↗Lead SOC Engineer NDR And VM
TALENTMATE · Abu Dhabi
Overview Job Description The Lead Engineer – SOC (NDR \& VM) will be a technically proficient Lead Engineer to join our Security Operations Center (SOC) team. This individual contributor role focuses on enhanc
1 months ago
Generate Resume ↗Lead SOC Engineer SIEM
TALENTMATE · Abu Dhabi
Overview Job Description The Lead Engineer – SOC (SIEM) is a critical role responsible for delivering SIEM management services, particularly focusing on Splunk SIEM and Splunk UEBA, within the Security Operati
1 months ago
Generate Resume ↗Lead SOC Engineer SIEM And SOAR
TALENTMATE · Abu Dhabi
Overview Job Description The Lead Engineer – SOC (SIEM \& SOAR) is a critical role responsible for delivering SIEM /SOAR management services, particularly focusing on Splunk SIEM and SOAR, within the Security
1 months ago
Generate Resume ↗Stop applying blindly.
Start getting hired.
Base Career automates the hardest parts of job searching — apply smarter, not harder.
AI Resume in 60s
Your resume rewritten for this exact role using the job description as the brief.
ATS-Optimized
Get past automated screening filters with the right keywords matched to each job.
Application Tracker
Track every job, follow-up, and interview in one visual kanban board.
Free plan · No credit card required