1

Principal Soc Analyst Jobs (NOW HIRING)

Job Summary The Lead SOC Analyst is responsible for leading the daily operations of the Security ... Location: this role must work on-site, full-time out of our Grand Rapids, MI office Principal ...

Lead SOC Analyst

Grand Rapids, MI · On-site

$100 - $125/hr

Job Summary The Lead SOC Analyst is responsible for leading the daily operations of the Security ... Principal Duties and ResponsibilitiesSOC Operations and Incident Response * Act as the senior ...

Job Summary The Lead SOC Analyst is responsible for leading the daily operations of the Security ... Location: this role must work on-site, full-time out of our Grand Rapids, MI office Principal ...

We are now looking for a Principal Hardware SoC Architect for our Tegra team. Do you want to be ... sq. mm modeling or analysis and track through design (where applicable) Architecture and ...

... SoC initiatives, delivering differentiated solutions that reinforce Marvell's position as a trusted ... Writing a verification test plan using random techniques and coverage analysis and working with ...

next page

Showing results 1-20

Principal Soc Analyst information

See salary details

$25K

$96.5K

$151.5K

How much do principal soc analyst jobs pay per year?

As of Sep 8, 2026, the average yearly pay for principal soc analyst in the United States is $96,525.00, according to ZipRecruiter salary data. Most workers in this role earn between $74,500.00 and $119,000.00 per year, depending on experience, location, and employer.

What is the difference between Principal Soc Analyst vs Security Analyst?

AspectPrincipal Soc AnalystSecurity Analyst
CredentialsOften requires CISSP, CISA, or GIAC certificationsTypically holds Security+, CISSP, or CEH certifications
Work EnvironmentLeads security operations, manages SOC teams, strategic planningMonitors security alerts, investigates incidents, supports security measures
Employer & Industry UsageUsed in large enterprises, government agencies, and security firmsCommon across various industries, including finance, healthcare, and tech

The Principal Soc Analyst focuses on leading security operations, strategic planning, and team management, often requiring advanced certifications. In contrast, the Security Analyst primarily monitors security alerts and investigates incidents. Both roles are vital in cybersecurity but differ in scope and seniority.

Do Principal SOC Analysts get paid well?

Principal SOC Analysts typically earn higher salaries due to their advanced skills, experience, and leadership responsibilities in cybersecurity operations. Compensation varies by industry and location but generally reflects the seniority and technical expertise required for the role, often including certifications like CISSP or CISM. They also benefit from additional perks such as bonuses and benefits packages.

Is Principal SOC analyst still in demand?

Principal SOC analysts are in high demand due to the increasing need for advanced cybersecurity defenses. They typically require strong skills in threat detection, incident response, and familiarity with security tools like SIEM systems, with certifications such as CISSP or GIAC often preferred. The role is critical in organizations aiming to strengthen their security posture amid evolving cyber threats.

What cities are hiring for Principal Soc Analyst jobs?

Cities with the most Principal Soc Analyst job openings:

What states have the most Principal Soc Analyst jobs?

States with the most job openings for Principal Soc Analyst jobs include:

What are popular job titles related to Principal Soc Analyst jobs?

For Principal Soc Analyst jobs, the most frequently searched job titles are:

Infographic showing various Principal Soc Analyst job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 88% Full Time, 5% Part Time, 1% Temporary, and 5% Contract. Highlights an 82% Physical, 7% Hybrid, and 11% Remote job distribution, with an average salary of $96,525 per year, or $46.4 per hour.

Lead SOC Analyst

Grand Rapids, MI

UFP Industries
Wood Product Manufacturing • 10K+ employees

Full-time

Re-posted 9 days ago


Key responsibilities

  • Lead and coordinate incident response activities, including threat detection, investigation, and containment.

  • Manage interactions with the MDR provider, review detections, and drive improvements in detection and response processes.

  • Provide technical leadership to SOC analysts, oversee daily operations, and develop SOC processes, playbooks, and documentation.


UFP Industries rating

7.3

Company rating: 7.3 out of 10

Based on 91 frontline employees who took The Breakroom Quiz

323rd of 547 rated manufacturers


Job description

Job Summary

The Lead SOC Analyst is responsible for leading the daily operations of the Security Operations Center (SOC) while actively participating in threat detection, investigation, and response activities. This role operates in a player/coach capacity, balancing hands-on incident response with team leadership, process development, and SOC maturity initiatives.

The Lead SOC Analyst serves as the primary point of coordination between the internal SOC and external managed detection and response (MDR) provider, ensuring effective monitoring, escalation, and response to security events. This role is also responsible for developing and maintaining SOC processes, playbooks, and documentation to improve the organization's overall security posture.

This role reports to the Manager of Cyber Defense.

Location: this role must work on-site, full-time out of our Grand Rapids, MI office

Principal Duties and Responsibilities

SOC Operations and Incident Response

  • Act as the senior escalation point for security incidents, providing hands-on investigation and response.
  • Perform advanced threat hunting, incident analysis, and root cause determination.
  • Lead and coordinate incident response activities across IT, infrastructure, and application teams.
  • Validate and enrich alerts generated by internal tools and external MDR provider.
  • Ensure timely containment, remediation, and closure of security incidents.

MDR Vendor Management

  • Serve as the primary operational liaison with our MDR provider.
  • Manage day-to-day interactions including alert triage alignment, escalation handling, and service quality.
  • Review MDR detections, investigations, and recommendations for accuracy and relevance.
  • Identify and drive improvements in detection coverage, alert fidelity, and response processes.
  • Participate in regular service reviews and ensure deliverables meet organizational expectations.

SOC Leadership and Team Development

  • Provide technical leadership and guidance to SOC analysts.
  • Lead daily SOC operations including prioritization of alerts, workload management, and escalation decisions.
  • Mentor and develop analysts through coaching, training, and knowledge sharing.
  • Establish expectations for investigation quality, documentation, and response timelines.
  • Support hiring, onboarding, and skill development of SOC team members.

SOC Maturity and Process Development

  • Develop, document, and maintain SOC standard operating procedures (SOPs), playbooks, and runbooks.
  • Identify gaps in SOC processes and implement improvements to increase consistency and effectiveness.
  • Define and track SOC metrics and KPIs (e.g., MTTR, alert volume, false positives, escalation rates).
  • Standardize incident documentation and evidence collection to support audit and compliance requirements.
  • Drive continuous improvement initiatives aligned to industry best practices and organizational goals.

Detection Engineering and Monitoring

  • Collaborate with engineering and security teams to improve detection logic and use cases.
  • Develop and tune detection rules within SIEM, XDR, and MDR platforms.
  • Identify gaps in logging and telemetry and work with teams to onboard required data sources.
  • Ensure monitoring coverage for systems handling sensitive or critical data.
  • Contribute to threat modeling and detection strategy development.

Communication and Stakeholder Engagement

  • Communicate security incidents, risks, and trends to technical and non-technical stakeholders.
  • Provide clear and concise reporting on incident outcomes and lessons learned.
  • Partner with infrastructure, application, and business teams to improve security practices.
  • Support audit, compliance, and risk management activities as needed.

Qualifications

  • Bachelor's degree in computer science, information security, or equivalent experience.
  • 7+ years of experience in a SOC, incident response, or cybersecurity operations role.
  • Proven experience leading incident investigations and managing escalations.
  • Experience working with a managed detection and response (MDR) provider (preferred).
  • Strong understanding of security operations tools (SIEM, XDR, EDR, SOAR platforms).
  • Experience with detection tuning, threat hunting, and log analysis.
  • Demonstrated ability to develop SOC processes, playbooks, and operational documentation.
  • Strong leadership, mentoring, and team development skills.
  • Excellent analytical, problem-solving, and decision-making capabilities.
  • Strong written and verbal communication skills.

Preferred Qualifications

  • Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms.
  • Experience working in a hybrid SOC model (internal + MDR).
  • Familiarity with compliance frameworks (e.g., NIST, CMMC).
  • Relevant certifications such as CISSP, GCIA, GCIH, or equivalent.

The Company is an Equal Opportunity Employer.




What UFP Industries employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


UFP Industries logo

About UFP Industries

Sourced by ZipRecruiter

Universal Forest Products, Inc., is a U.S.-based global corporation that finds reward in its roots and its hard-earned success. Founded in 1955 as a supplier of lumber to the manufactured housing industry, Universal today is a multibillion-dollar holding company with subsidiaries around the globe that serve three robust markets: retail, industrial and construction. Since 1993, Universal has been publicly traded (Nasdaq: UFPI). We re headquartered in Grand Rapids, Michigan.

Industry

Wood product manufacturing

Company size

10,000+ Employees

Headquarters location

Grand Rapids, MI, US

Year founded

1955

Social media