AI summary: L3 SOC analyst leads incident detection, investigation, and response to complex cybersecurity threats while coordinating cross-functional teams.
About ProArch:
At ProArch, we partner with businesses around the world to turn big ideas into better outcomes through IT services that span cybersecurity, cloud, data, AI, and app development.
We’re 400+ team members strong across 3 countries (we call ourselves ProArchians)—and here’s what connects us all:
What’s it like to work here?
At ProArch, you’ll be part of teams that design and deliver technology solutions solving real business challenges for our clients. With services spanning AI, Data, Application Development, Cybersecurity, Cloud & Infrastructure, and Industry Solutions, your work may involve building intelligent applications, securing business‑critical systems, or supporting cloud migrations and infrastructure modernization.
Every role here contributes to shaping outcomes for global clients and driving meaningful impact. You’ll collaborate with experts across data, AI, engineering, cloud, cybersecurity, and infrastructure—solving complex problems with creativity, precision, and purpose. You’ll join a culture rooted in technology, curiosity, and continuous learning. A place where we move fast, trust you to make an impact, encourage innovation, and support your growth.
About Position:
At ProArch, a leader in IT security consulting with presence in the US, UK, and India, we are looking for a skilled L3 SOC Analyst / Incident Response Analyst to join our Security Operations Center (SOC) team. In this critical role, you will be responsible for advanced incident detection, investigation, and response to complex cybersecurity threats. Leveraging your extensive experience and expertise, you will lead incident response activities, perform deep-dive analysis, and coordinate with cross-functional teams to mitigate risks and strengthen our security posture. If you thrive in a dynamic, fast-paced environment and are passionate about defending organizations against sophisticated cyber threats, this position is ideal for you.Role Summary
ProArch are seeking a highly skilled and technically strong L3 SOC Analyst / Incident Response Analyst to operate within a Managed Security Services Provider (MSSP) environment, supporting multiple customer environments across diverse industries.
This role is heavily focused on:
The ideal candidate combines strong incident response expertise, deep Microsoft security platform knowledge, hands-on detection engineering capability, and SOC automation experience within a fast-paced MSSP environment.
This is not a traditional alert-monitoring SOC Analyst role. The position requires strong investigative, analytical, and response-oriented cybersecurity capabilities.
Key Responsibilities
1. Incident Response & Threat Investigation
• Lead and support advanced security incident investigations across multiple customer environments
Perform:
Investigate and respond to:
Account compromise incidents
Business Email Compromise (BEC)
Malware and ransomware activity
Privilege escalation
Lateral movement activity
Suspicious cloud and identity-based attacks
Advanced phishing and social engineering campaigns
Coordinate containment, remediation, and recovery activities with customer and internal teams
Support high-severity incident escalation handling and response coordination
Provide detailed investigation findings, timelines, impact assessments, and response recommendations
Conduct proactive threat hunting and threat validation activities where required
Support digital forensics and evidence collection activities when applicable
2. Detection Engineering & SIEM Operations
Design, develop, and maintain advanced detection rules across:
Develop and optimize:
Perform:
Detection tuning
False positive reduction
Behavioral baselining
Threat-based detection improvements
Build and maintain reusable detection content and query libraries
Support proactive detection engineering initiatives aligned with emerging threats and attacker techniques
Leverage threat intelligence and MITRE ATT&CK mapping to improve detection coverage
3. SOC Automation & SOAR Engineering
Design and implement SOC automation workflows using:
Build workflows for:
Alert enrichment
Incident routing
Automated containment actions
Threat intelligence enrichment
Ticket synchronization
Investigation acceleration
Develop scalable automation frameworks to improve SOC operational efficiency
Support continuous optimization of SOC workflows and automation coverage
Create automation standards and reusable workflow templates across customer environments
4. Microsoft Security Platform Operations
Provide hands-on operational support, investigation, tuning, administration, and engineering for:
5. AI Security & Modern Threat Operations
Support detection and response activities related to:
AI-orchestrated attacks
Identity-based attacks
Cloud-native threats
Advanced phishing and social engineering campaigns
Leverage AI-assisted SOC operations and automation capabilities where applicable
Support modern detection strategies aligned with evolving attacker techniques
Evaluate opportunities to integrate AI-driven efficiencies into detection, investigation, and response workflows
6. Client & Operational Support
Participate in customer incident discussions and escalation calls when required
Support onboarding of new customer environments and security integrations
Maintain:
Investigation playbooks
SOPs
Workflow documentation
Operational runbooks
Detection documentation
Collaborate closely with:
SOC Operations
Security Engineering
Vendors
Consulting teams
Customer stakeholders
Support operational improvement initiatives across SOC and DFIR functions
Required Qualifications
Education
Experience
Strong hands-on experience in:
Incident Response
Threat Investigation
SOC Operations
Detection Engineering
DFIR activities
Prior Incident Response Analyst experience is highly preferred
Experience working within MSSP environments preferred
Experience supporting or collaborating with US-based teams/vendors preferred
Proven hands-on experience with SOAR platforms in enterprise or MSSP environments
Strong experience designing and implementing SOC automation workflows from scratch
Experience supporting enterprise Security Operations Center (SOC) environments
Experience with detection engineering and SIEM rule development
Required Technical Skills
Security Platforms & Technologies
Strong hands-on experience with:
Strong experience creating:
Experience with:
Understanding of:
MITRE ATT&CK
Scripting & Technical Skills
Preferred experience with:
Preferred Certifications
Soft Skills & Work Style
Working Model
What Success Looks Like
Life @ ProArch