Senior SOC Analyst - Incident Response & Threat Hunting
Senior SOC Analyst – Incident Response & Threat Hunting
Auckland CBD | Permanent | Hybrid – two office days | No on-call
Take the technical lead when it matters most.
We are looking for an experienced Senior Security Operations Centre (SOC) Analyst to join a well-established security operations environment. This is a hands-on technical leadership role where you will lead high-severity incidents, guide other analysts and influence how the SOC detects, investigates and responds to threats.
You will be the trusted technical authority and escalation point-not a people manager. This is an excellent opportunity for an experienced SOC professional who enjoys leading from the front, mentoring others and improving security operations without the politics of formal team management.
The opportunity
You will take ownership of complex security incidents from initial investigation through containment, remediation and review. Alongside incident response, you will conduct proactive threat hunting, support the development of other analysts and help strengthen SOC workflows, playbooks and detection capabilities.
You will work closely with technical teams and business stakeholders, providing clear advice and maintaining calm, decisive leadership during critical incidents.
Key responsibilities
- Lead the investigation and resolution of high-severity security incidents
- Act as a technical escalation point for SOC analysts
- Perform proactive threat hunting and identify emerging security risks
- Analyse network activity, alerts and security events
- Use SIEM and EDR/XDR platforms to investigate and respond to threats
- Support the development and improvement of SOAR processes and playbooks
- Mentor analysts and promote effective knowledge sharing
- Contribute to detection engineering and broader SOC capability uplift
- Communicate incident impact, risk and recommended actions to technical and non-technical stakeholders
- Identify opportunities to improve operational processes and response effectiveness
What you will bring
- At least five years of dedicated Security Operations Centre experience
- Previous senior, lead or technical escalation responsibilities
- Advanced experience with SIEM platforms such as Microsoft Sentinel or Splunk
- Strong knowledge of EDR/XDR technologies such as Microsoft Defender
- Demonstrated ownership of complex security incident response
- Practical threat-hunting experience
- Strong understanding of network analysis and intrusion detection
- Experience working with SOAR technologies and security playbooks
- The ability to remain calm and make pragmatic decisions under pressure
- Clear communication skills across technical and business audiences
- A genuine interest in mentoring others and sharing knowledge
Experience improving SOC processes, detection capability, playbooks or team maturity would be particularly valuable.
What is on offer
- Hybrid working with two days per week in the Auckland CBD office
- No on-call requirement
- Southern Cross UltraCare 400 health insurance
- Life, trauma, income protection and permanent disability insurance
- Employer KiwiSaver contribution grossed up so eligible employees receive the full 3%
- Monthly fitness reimbursement of up to $100
- Additional wellbeing initiatives and employee benefits
- A supportive culture with flexible working arrangements
- Genuine influence over SOC processes and capability development
Earlier-career SOC opportunities
We are also interested in hearing from developing SOC Analysts with approximately one to three years of relevant, hands-on Security Operations and incident-response experience. If you are earlier in your SOC career but have practical SIEM and security investigation experience, we encourage you to apply.
Apply now
If you are an experienced SOC professional who wants to remain technically hands-on while leading incidents, mentoring others and improving operational capability, we would like to hear from you.
Applicants must be based in New Zealand and hold a valid work visa to be considered for this role. Due to the high volume of applications, only shortlisted candidates will be contacted.