1

Tier 3 Soc Analyst Jobs in Indiana (NOW HIRING)

Serve as the Tier 3 technical escalation point in the SOC. Take the incidents that Tier 2 cannot ... Analyze endpoint, identity, and network telemetry to identify suspicious activity, lateral movement ...

next page

Showing results 1-20

Tier 3 Soc Analyst information

See Indiana salary details

$33.8K

$94.4K

$120.8K

How much do tier 3 soc analyst jobs pay per year?

As of Sep 5, 2026, the average yearly pay for tier 3 soc analyst in Indiana is $94,355.00, according to ZipRecruiter salary data. Most workers in this role earn between $68,500.00 and $120,400.00 per year, depending on experience, location, and employer.

What is the difference between Tier 3 Soc Analyst vs Tier 2 Soc Analyst?

AspectTier 3 Soc AnalystTier 2 Soc Analyst
CertificationsSIEM, CISSP, GCIHSecurity+ or CEH
Work EnvironmentAdvanced threat analysis, incident response, escalationMonitoring, initial incident detection, triage
ResponsibilitiesHandling complex incidents, threat hunting, root cause analysisMonitoring alerts, basic incident investigation

Tier 3 Soc Analysts focus on advanced threat detection, incident escalation, and complex investigations, while Tier 2 Soc Analysts handle initial monitoring and basic incident response. Tier 3 roles require more specialized certifications and experience, making them suitable for more complex security challenges.

How much does a Tier 3 SOC analyst make?

A Tier 3 SOC analyst typically earns between $80,000 and $120,000 annually, depending on experience, certifications, and location. They are responsible for advanced threat detection, incident response, and often work with security tools like SIEMs and intrusion detection systems.

Is a Tier 3 SOC analyst still in demand?

Yes, Tier 3 SOC analysts are in high demand due to the increasing need for advanced cybersecurity threat detection and response. They typically require specialized skills, certifications, and experience with security tools, making them valuable in organizations focused on cybersecurity resilience.

What does a Tier 3 SOC analyst do?

A Tier 3 SOC analyst is responsible for handling advanced security incidents, performing in-depth threat analysis, and coordinating response efforts. They often investigate complex security breaches, develop mitigation strategies, and may mentor Tier 1 and Tier 2 analysts. Proficiency with security tools, incident response procedures, and relevant certifications like CISSP or GIAC are common requirements.

What are popular job titles related to Tier 3 Soc Analyst jobs in Indiana?

For Tier 3 Soc Analyst jobs in Indiana, the most frequently searched job titles are:

What job categories do people searching Tier 3 Soc Analyst jobs in Indiana look for?

The top searched job categories for Tier 3 Soc Analyst jobs in Indiana are:

Infographic showing various Tier 3 Soc Analyst job openings in Indiana as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $94,355 per year, or $45.4 per hour.

Cybersecurity Analyst III

EXOS (formerly Sondhi Solutions)

Indianapolis, IN • On-site

Full-time

Re-posted 7 days ago


Key responsibilities

  • Serve as the Tier 3 technical escalation point, drive complex incident investigations to resolution, and provide evidence-backed recommendations.

  • Lead confirmed true-positive incidents end to end, including scoping, containment, eradication, recovery, and client communication.

  • Own and run the proactive threat hunting program, developing hypotheses, conducting investigations, and feeding findings into detection engineering.


Job description

What You Will Do


The Cybersecurity Analyst III at EXOS CYBER is the senior technical escalation point of the SOC ? the final analyst-tier authority on the hardest, most ambiguous investigations before a case moves into engineering. When Tier 2 has driven an alert as far as standard playbooks and queries allow and still doesn't have a confident answer, it comes to you. You own confirmed, significant incidents end to end across our client environments. You will support day-to-day security operations for our clients with a primary focus on advanced detection, incident response, and threat hunting, working alongside our Cybersecurity Engineers, and Team Lead.


Beyond the queue, you set the bar for investigation quality across the SOC. You QA escalations, mentor and develop Tier 1 and Tier 2, build out the investigation curriculum, and partner with engineering on detection strategy at the program level, not just one noisy rule at a time. This is a hands-on, deeply technical role designed for analysts with 5+ years of experience (or 2+ years past Tier 2) who are ready to operate as the senior individual contributor in a real-world MSSP detection-and-response practice spanning across a diverse client environments. 


  • Serve as the Tier 3 technical escalation point in the SOC. Take the incidents that Tier 2 cannot fully resolve, drive them to a definitive answer, and hand only genuinely engineering-scoped or architecture-level problems to the Cybersecurity Engineers and Team Lead with a clear, evidence-backed recommendation and a proposed course of action. 
  • Lead confirmed true-positive incidents end to end across client environments including but not limited to ransomware, business email compromise, account takeover, lateral movement, and data exfiltration including scoping and impact assessment, containment orchestration via SentinelOne, account isolation and credential rotation in Entra ID, eradication and recovery guidance, evidence preservation, root-cause analysis, and client communication through resolution. 
  • Own and run the proactive threat hunting program: develop hypothesis-driven hunts across the client base using various queries, EDR telemetry, and indicators from CTI feeds; document findings; and feed confirmed patterns back into detection engineering as durable, reusable detections. 
  • Perform host, memory, and network forensics (Velociraptor, endpoint and identity artifacts, timeline reconstruction) to establish what happened, when, and how far it went, and to support breach-notification and legal/insurance coordination when an incident warrants it. 
  • Conduct phishing triage and support email-based threat investigations, including user impact assessment and remediation steps. 
  • Partner with the Cybersecurity Engineers and AI Automation Engineer on detection strategy at the program level coverage and gap analysis against MITRE ATT&CK, detection content design, and false-positive reduction across the fleet rather than one-off alert tuning. 
  • Apply offensive and adversary-emulation knowledge to inform detection coverage, and support purple team and adversary-emulation exercises by translating attacker TTPs into detections and validating that controls fire as expected. 
  • Analyze endpoint, identity, and network telemetry to identify suspicious activity, lateral movement, and persistence, and lead phishing and email-based threat investigations through full user-impact assessment and remediation.