Senior SOC Analyst leading incident triage and coordinating responses for BNY's global Security Operations Center. Mentoring junior analysts and improving operational resilience in the financial services sector.
Responsibilities
Lead triage and investigation of security alerts, escalating and coordinating incident response as needed.
Perform root cause analysis, scope affected assets, and drive containment, eradication, and recovery.
Correlate events across SIEM, EDR, IDS/IPS, firewalls, cloud logs, and identity platforms to identify true positives and reduce false positives.
Develop, refine, and maintain SOC playbooks, runbooks, and detection logic aligned to the MITRE ATT&CK framework.
Mentor junior analysts and provide guidance on investigation techniques, documentation standards, and operational best practices.
Coordinate with Threat Intelligence to enrich investigations, track adversary TTPs, and proactively hunt for indicators of compromise.
Partner with Engineering teams to tune detections, improve log fidelity, and strengthen preventive controls.
Create clear, actionable incident reports and executive summaries; contribute to metrics and trend analysis.
Support purple team exercises and post-incident reviews to capture lessons learned and drive continuous improvement.
Ensure adherence to regulatory and security policies; maintain audit-ready documentation for investigations and incidents.
Requirements
8+ years of experience in a SOC, incident response, or threat detection role, including Tier 2/3 investigations.
Advanced proficiency with SIEM (e.g., Splunk, QRadar, Sentinel), EDR (e.g., CrowdStrike, Microsoft Defender), and SOAR platforms.
Strong knowledge of network security, Windows/Linux, identity systems, and common cloud logging sources.
Hands-on experience with the MITRE ATT&CK framework, threat hunting, IOC/IOA development, and detection tuning.
Demonstrated ability to lead complex incidents, coordinate stakeholders, and communicate clearly under time pressure.
Scripting or automation experience (e.g., Python, PowerShell) for investigation enrichment and workflow improvements.
Familiarity with NIST CSF/800-61, CIS Controls, and common regulatory requirements impacting incident response.
Excellent documentation skills and an evidence-driven approach to investigations.
Benefits
BNY offers highly competitive compensation, benefits, and wellbeing programs rooted in a strong culture of excellence and our pay-for-performance philosophy. We provide access to flexible global resources and tools for your life’s journey. Focus on your health, foster your personal resilience, and reach your financial goals as a valued member of our team, along with generous paid leaves, including paid volunteer time, that can support you and your family through moments that matter.
Cyber Operations Lead ensuring coordination of cyber operations between the Security Operations Center and internal business units. Enhancing security through effective incident response and threat management initiatives.
Solution Sales Manager enhancing revenue in financial services, focusing on ServiceNow IRM and Tanium solutions. Collaborating with teams and engaging C - level executives in Austria and Switzerland.
Senior Internal SOC Analyst leading security triage and investigations for Darktrace, utilizing AI - driven cybersecurity technology. Collaborating on incident response and mentorship within a hybrid work environment.
Security Operations Intern responsible for security monitoring at Paddy Power Betfair. Involves data loss prevention investigations and content filtering analysis with a commitment to improving security posture.
SOC Analyst L2 responsible for managing and analyzing security incidents in digital transformation. Contributing directly to the protection of companies and infrastructures.
Senior Manager leading global IT security operations to protect company data and assets at Keenova. Overseeing incident response, monitoring, and cybersecurity capabilities with strategic oversight.
Security Operations Center leader at Woven by Toyota, managing triage and response to security alerts in Japan. Collaborating with global SOCs to ensure 24/7 operations.
GSOC Analyst responsible for security operations at Paramount Studios. Developing workflows, incident response, and risk monitoring in a dynamic team environment.