Source description
About the role
Supervise and mentor SOC Analysts
Assign and balance workload across analysts and shifts
Monitor queue health, SLA compliance, and alert backlog
Conduct regular performance check-ins
Address quality gaps and provide corrective guidance
Reinforce adherence to documented playbooks and procedures
Primary Focus: Ensure consistent and effective analyst performance.
Hands-On Monitoring & Investigation
Perform daily alert triage alongside SOC Analysts
Conduct investigations on moderate to high-severity alerts
Lead or directly support complex or multi-system investigations
Validate alert classifications and case documentation
Participate in shift coverage as needed
Primary Focus: Maintain technical engagement and operational credibility.
Serve as the first escalation point for analysts
Lead investigations for high-severity incidents
Coordinate response actions with internal stakeholders
Ensure timely and accurate communication during incidents
Drive investigations to clear, defensible conclusions
Primary Focus: Maintain operational control during critical events.
Investigation Quality & Case Governance
Review analyst investigations for accuracy and completeness
Approve or return cases prior to closure
Ensure proper evidence collection and timeline documentation
Enforce consistent tagging, classification, and case hygiene
Primary Focus: Protect the integrity of SOC output.
Process & Continuous Improvement
Maintain and update SOC playbooks and workflows
Identify inefficiencies in monitoring or case handling
Provide feedback on alert tuning and automation improvements
Capture and integrate lessons learned
Stakeholder Coordination
Respond to formal information requests within defined SLAs
Serve as liaison between SOC analysts and leadership
Support audits, reporting, and compliance requirements
Participate in shift handoffs and operational planning
Primary Focus: Maintain trust and communication across teams.
Workload Segmentation (Approximate)
30% – Direct Monitoring & Investigation Work
25% – Escalation & High-Severity Incident Leadership
20% – Team Management & Performance Oversight
15% – Investigation Quality Review & Case Governance
10% – Process Improvement & Documentation
Percentages may shift during major incidents or staffing changes.
More at True Zero Technologies
Related open roles
Zero Trust Lead (R-00179)
New York · Washington DC · Hybrid
SIEM Analyst II (R-00173)
United States · Onsite
Cyber Security Analyst-Senior Level (R-00172)
United States · Onsite
ZScaler Engineer (R-00171)
Remote · United States
Cybersecurity Operations Analyst II (R-00170)
Washington DC · Onsite
Mid Cyber Security Analyst-Intermediate Level (R-00169)
United States · Hybrid
