Senior Security Operations Analyst - Onsite
-
We are seeking a Senior SOC Analyst (Level 2/3) to join our Security Operations Center team onsite (Monday through Friday) within our Cincinnati office (this is NOT a hybrid or remote role).
This role is pivotal in advanced threat detection, incident analysis, response coordination, and automation development.
Acting as an escalation point for L1 analysts, you will lead investigations into complex security incidents, mentor junior team members, and drive improvements in detection and response capabilities within a fast-paced, 24/7 operational setting.
Key Accountabilities/Deliverables:
* Investigate escalated alerts, validate threats, and perform deep-dive forensic analysis using SIEM, EDR, and threat intelligence tools.
* Lead containment and remediation efforts for escalated incidents across multiple environments.
* Develop and tune SIEM use cases, correlation rules, and EDR detection logic to improve SOC efficiency.
* Design and implement automation workflows to enhance incidents response and investigation efforts.
* Leverage AI platforms to assist with automation of SOC processes.
* Conduct proactive hunts leveraging behavioral analytics and intelligence feeds to identify emerging threats.
* Work closely with IT, network, and security engineering teams to contain incidents and strengthen defenses.
* Maintain and enhance SOC playbooks, runbooks, and standard operating procedures (SOPs).
* Assist with preparation of detailed incident reports, root cause analyses, and recommendations for preventive measures.
* Train and guide L1 analysts, fostering a culture of continuous learning and operational excellence.
* Assess and recommend new security technologies or security measures to enhance SOC capabilities.
* Maintain endpoint security baselines aligned with CIS benchmarks.
* Support integration and operations of a new primary EDR/SIEM platform.
* Partner with IT operations to safely test and deploy endpoint security changes.
* Act as a senior technical escalation point during security incidents.
* Contribute to incident response playbooks and post‑incident reviews.
* Produce high‑quality technical documentation, including:
+ Security architecture diagrams
+ SOPs and runbooks
+ Policy rationale and audit artifacts
+ Incident timelines
Technical Knowledge and Understanding:
* Strong understanding of SIEM platforms, EDR tools, and network monitoring solutions; including the maintenance and tuning of security tools and alert logic, security settings, and IOC blocks.
* Proven experience designing and implementing security automation workflows.
* Strong SQL/KQL query capabilities.
* Deep knowledge of attack lifecycle frameworks (MITRE ATT&CK, Cyber Kill Chain).
* Proven ability to analyze network traffic, logs, and host-based artifacts.
* Ability to work in a fast-paced 24x7 environment ...
- Rate: Not Specified
- Location: Cincinnati, US-OH
- Type: Permanent
- Industry: Medical
- Recruiter: Core Specialty Insurance Services, Inc.
- Contact: Not Specified
- Email: to view click here
- Reference: JR101557
- Posted: 2026-09-17 08:47:35 -
- View all Jobs from Core Specialty Insurance Services, Inc.
More Jobs from Core Specialty Insurance Services, Inc.
- Medication Technician
- Home Care Aide
- Certified Nursing Assistant CNA
- Nurse Supervisor- LPN/LVN
- Senior Living Advisor - Remote
- Cook
- Executive Director - Assisted Living Director
- Wellness Director - Resident Care Director
- Driver
- Dining Services Manager
- Server
- Hire Ahead Executive Director-Phoenix Market
- Certified Medication Technician
- Medication Technician
- LPN or LVN
- Caregiver
- Cook $1,500.00 SIGN ON BONUS!
- Caregiver
- Memory Care CNA
- Maintenance Technician