Crane Company is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, gender, sexual orientation, general identity, national origin, disability or veteran status.
SOC Lead
Location
United States
Posted
6 days ago
Salary
0
Seniority
Lead
Job Description
SOC Lead
Crane Company
Role Description Crane Co is looking for outstanding information security professionals to join the Crane Co. Global Information Security Team! Do you possess a strong security operations center background and want to lead others while working on interesting problems and helping to advance incident response capabilities? Have you always wanted to make a real impact on effective delivery of security operations at scale? We have an exciting opportunity helping to lead our blue-team operations using proven and emerging solutions in a comprehensive portfolio for our next-generation security operations center. You are passionate about leading incidents, performing threat hunting, and have a clear vision about next-gen SOCs and SOAR? Do you enjoy digging deep to find the threats everything else missed? This role will provide opportunities to advance our global security operations and incident response program by applying cool and interesting security technologies, processes, and techniques to support SOC and IR for a global organization. This position will provide exposure to best-of-breed security solutions in a challenging and rewarding enterprise setting. You’ll lead other responders and analysts as part of our tight-knit security team and be the escalation path within the global SOC for truly interesting attacks. As the ideal candidate, you will have solid proficiency in security incident and event management solutions, using modern IR approaches and tools, and have a proven track record implementing and honing a myriad of detective and preventive controls and processes in an enterprise setting. You must have a desire to lead others while furthering your own development, contributing to continuous improvement initiatives, and have a genuine passion for infosec! Previous security operations center experience, threat hunting prowess, and endless curiosity required. Responsibilities and Duties - Ensure the timely identification, response, investigation, and remediation of all security events and incidents. - Lead daily work of security operations center team members and provide support to teams in other geographies and time zones as required. - Develop standard work and processes, build playbooks, and implement analysis logic supporting automation efforts using various techniques including scripting and coding within platforms, APIs, and related technologies. - Enrich and implement additional detective capabilities to enhance or improve incident identification and response. - Using SOAR techniques, automate and integrate workflows between SIEM, various IR platforms, and other solutions and technologies. - Work closely with the broader global security team, supporting the analysis and tuning of the effectiveness of solutions, configurations, and processes. - Work closely with Information Technology to identify risks and weaknesses as a component of our vulnerability management program. - Provide input to the maintenance and enhancement of related policies, documentation, and procedures. - Contribute to the broader program to ensure best practices are identified and integrated into our approach and methodologies. - Support the security infrastructure administration and operations function as required. - Ensure all security incidents for self and team are fully and accurately investigated with comprehensive and effective remediations clearly defined and communicated to stakeholders. Qualifications - Senior level experience in security operation center function supporting medium to large enterprises performing incident response. - Prior responsibilities performing triage, assignment, and closed-loop investigations for a team of SOC analysts and/or incident responders. - Proven results developing and implementing methods, processes, and procedures for detecting, responding, and resolving computer security incidents. - Deep understanding of present-day cyber-threats, attacker techniques and behaviors, and effective methods to both detect & repel these threats for a global organization with a distributed enterprise IT environment. - Prior experience using automation tools leveraging custom development, scripting, and solution platforms. - Prior experience writing tools to automate tasks and integrate various systems in Python, Powershell, and other scripting languages. - Experience with writing interfaces utilizing JSON, XML, and REST APIs. - Experience performing data normalization, correlations, and visualizations. - Experience with supporting security technologies such as EDR, firewalls, proxies, web and email filters, application allow-listing, sandboxing, SIEM, threat intelligence, vulnerability scanning, syslog, IDS/IPS, DLP, etc. - Broad technology experience with enterprise-level IT technologies including networks, endpoints, virtualization, cloud, operating systems, email, storage, databases, etc. - Familiarity with relevant multi-national financial, privacy, and governmental regulatory requirements. - Highly motivated and self-directed with a passion for solving complex problems. - Excellent verbal and written communication skills. - Must be able to prioritize based on risk, schedule and track to deadlines for self and team members. - Ability to cope well with pressure and make sound decisions in uncertain situations. - Flexibility to work outside regularly scheduled/normal business hours. - Ability to travel both domestically and internationally, with little notice (as required). Requirements - 5 years relevant professional experience in Security Operations and Incident Response Management. - 2 years supervisory experience leading SOC/IR analysts. - Technical professional security certifications in Incident Response, Digital Forensics, or Malware Analysis, such as GCIH, GCFA, GNFA, GCTI or similar. Benefits - Exciting opportunity to grow and make a positive impact on a global program alongside other passionate infosec professionals.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Security Analyst II
ConnectWiseConnectWise is a software managed services platform designed to support technology solution providers. The unified ConnectWise platform helps clients secure customers, manage busin
• The Security Analyst II is responsible for performing necessary operations activities, including assisting with the notification, identification, escalation, and remediation of security related threats and breaches. • This role works in partnership with cross-functional teams to provide timely support on threats, vulnerabilities, and exploits across the industry.
Senior Cybersecurity Analyst
UnitedHealth GroupUnitedHealth Group is a healthcare and well-being company that’s dedicated to improving the health outcomes of millions around the world. We are comprised of
Title: Senior Cybersecurity Analyst Location: Eden Prairie United States Requisition number: 2352925 Job category: Technology Primary location: Eden Prairie, MN Overtime status: Exempt Travel: No Job Description: Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. Purpose of Job: This role is an individual contributor for the Security Incident Response Team. As the team has developed into a 24/7 365 operation, we require strong individual contributors that will investigate, analyze and contain security incidents. Schedule: This role is Wednesday to Saturday 8am CST to 6pm CST If you are located in MN or DC, you will have the flexibility to work remotely* as you take on some tough challenges. Primary Responsibilities: - Critical severity security incident management - Monitor security intake technologies for reports of security incidents - Perform analysis on cybersecurity alerts in both On-Premises or Cloud environments - Provide engineering consulting and implementation expertise in support of new initiatives - Solid ability to collaborate, delegate tasks and drive deadline compliance in a highly regulated, time sensitive environment - Identify deficiencies in processes and tools, recommend security controls and/or corrective actions for mitigating technical and business risk. Contribute to Lessons Learned Meetings - Review security tools for opportunities to improve alerting for the SOC team - Produce detailed incident reports and security recommendations - Mentor analysts, providing training and guidance through complex incidents - Lead security, policy and privacy related events and incidents - Manage containment and remediation efforts of affected assets, IOCs, and TTPs - Produce detailed incident reports and security recommendations - Hold stakeholders accountable for remediation actions - Providing training and guidance through complex incidents - Integrate and collaborate with other subject matter experts throughout the organization - Liaison with Cyber Defense, Privacy, Compliance, Legal, and Architecture teams - Influence the creation and/or adoption of new standards and procedures - On-Call duties may be required You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in. Required Qualifications: - High School Diploma/GED (or higher) - Information Technology Industry Certification: Willingness to obtain information/cybersecurity certification within nine (9) months of hire - Advanced level of experience analyzing attack vectors, current threats, and security remediation strategies - Advanced level of experience with SIEM technologies, EDR technologies, and/or Asset isolation tools - Intermediate level of experience in public cloud platforms, including Azure, AWS, and Google Cloud Platform - Intermediate level of experience with high level familiarity of global privacy regulations (NY Cyber, GDPR, LGPD, CERT-In) - Willing or ability to work off shift hours if needed (e.g. Nights and Weekends) Preferred Qualifications: - Undergraduate degree or equivalent experience - CISSP, CISA, GCIH, CEH, CHFI, CCSP, SEC+, Net+, A+ - PowerShell, KQL, or Python scripting experience - Understanding of NIST 800-61, Cyber Kill Chain, and MITRE ATT&CK framework - Networking experience (including the OSI Model, TCP/IP, DNS, HTTP, SMTP), System Administration, and Security Architecture - Proven Spanish Language skills - 6+ years of Cyber Security Analyst experience in any of the following areas: - Security Incident Response - Email Security - Cybersecurity threat detection, monitoring and reporting - Cyber Intelligence and Threat Hunting - Vulnerability Management - All Telecommuters will be required to adhere to UnitedHealth Group's Telecommuter Policy. Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $91,700 to $163,700 annually based on full-time employment. We comply with all minimum wage laws as applicable. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants. At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location, and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups, and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission. UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.
• The Senior IT Security Compliance Analyst provides support for technology compliance programs, including leading and executing functions and duties that may include: consulting and collaborating with business and technology stakeholders at all levels on control design and remediation to mitigate technology risks; participating on large-scale projects; maintaining IT control library/testing general computer and application controls; coordinating and supporting technology components of onsite and virtual audits/assessments, NCUA examinations, and client due diligence reviews; • Performing segregation of duties reviews and user attestations; documenting process flows and compliance-related deliverables; assisting with the creation and maintenance of IT and information security policies and standards required to maintain company certifications (e.g., PCI DSS, NIST CSF); • Coaching and cross-training technology compliance staff. The individual will execute assigned duties to meet stated priorities and SLAs. The individual plays a critical role in driving technology control and compliance practices and adoption across the company. • This role directs and advises technical SMEs in the design, implementation, monitoring and reporting of technology control and compliance processes and documentation on-premise and in the Cloud.
Junior Cyber Security Analyst
American Oncology NetworkRemote Position Pay Range: $25.19 - $44.31 Travel: 0-25% #LI-Remote
Role Description The Junior IT Cyber Security Analyst assists in safeguarding the organization’s systems, data, and networks across both corporate and clinical environments. This role supports core cybersecurity operations, including: - Threat monitoring - Incident response - Vulnerability management - Compliance activities Under the direction of senior cybersecurity professionals, the position contributes foundational cybersecurity expertise while contributing to day-to-day security operations. The Junior Analyst helps maintain and strengthen the organization’s overall security posture through active participation in monitoring, analysis, and risk mitigation efforts. Key Performance Areas - KPA 1 – Threat Monitoring & Initial Response (Support Role) - Monitor security alerts from SIEM, EDR, email security, and network tools. - Perform initial triage and escalate suspicious activity to senior analysts. - Follow established incident response playbooks for basic investigations. - Document incidents, actions taken, and outcomes. - KPA 2 – Vulnerability & Patch Support - Assist with vulnerability scans and review scan results. - Track remediation progress and follow up with system owners. - Support patching efforts by validating updates and documenting status. - Help maintain asset and vulnerability inventories. - KPA 3 – Compliance & Documentation - Support collection of evidence for audits (HIPAA, SOC 2, etc.). - Maintain documentation for policies, procedures, and controls. - Assist with periodic access reviews and data protection checks. - Help track remediation of audit findings. - KPA 4 – Cyber Awareness, Training, and Culture - Assist in coordinating phishing simulations and training campaigns. - Help distribute cybersecurity communications (e.g., tips, alerts). - Promote secure behaviors across staff through basic guidance. - Support onboarding security training for new employees. - KPA 5 – Clinic Onboarding and Operational Support - Assist senior analysts with clinic onboarding security tasks. - Support inventory collection (devices, users, systems). - Help validate baseline security controls during integrations. - Participate in remote or occasional on-site support activities. - KPA 6 – Learning & Continuous Improvement - Participate in cybersecurity projects and tool implementations. - Develop knowledge of security technologies and best practices. - Track and report basic metrics (e.g., ticket resolution, alert volumes). - Continuously improve technical and analytical skills. Qualifications - Associate or Bachelor’s degree in Information Technology, Cybersecurity, or related field (or equivalent experience). - High school education required. - 0–2 years of IT or cybersecurity-related experience. - Internship, lab, or hands-on training experience preferred. - CompTIA Security+ (or actively pursuing). - Other entry-level certifications (e.g., Network+, ISC2 CC). Requirements - Analytical & Problem-Solving: Applies foundational analysis to investigate alerts, review data, and identify issues; follows established processes with attention to detail and appropriate escalation. - Interpersonal Effectiveness: Communicates professionally, builds collaborative relationships, maintains confidentiality, and responds constructively to feedback. - Communication: Demonstrates clear written and verbal communication; documents incidents and findings effectively; conveys basic technical information to non-technical audiences. - Customer Focus & Organizational Awareness: Supports internal users and clinical staff with a service-oriented approach; aligns work with organizational priorities and healthcare standards. - Self-Management & Accountability: Manages time and priorities effectively; demonstrates reliability, initiative, and adaptability in a structured environment. - Adaptability: Thrives in a fast-paced, multi-site healthcare setting; manages competing priorities and collaborates across distributed teams. - Technical Proficiency: Proficient in Microsoft Office (Word, Excel, PowerPoint, Outlook); able to learn and utilize cybersecurity tools (e.g., SIEM, EDR, vulnerability scanners) with training. Benefits - Flexible hours - Ergonomic home office guidance - Communication software accessibility

