Senior SOC Analyst

Nassau Airport Development Company · Nassau, Bahamas · Full-time · Data & Analytics

On-site

Posted 18d ago · Expires 9/19/2026

Role description

Hiring company: Nassau Airport Development Company Source: LinkedIn Bahamas The Senior SOC Analyst is a hands-on, senior-level member of NAD's Security Operations Center (SOC), responsible for advanced threat detection, investigation, and incident response across NAD's enterprise IT, operational technology (OT), and airport systems environments. This role serves as a technical escalation point for junior analysts, leads investigations into complex security events, and drives continuous improvement of detection and response capabilities using NAD's security tool stack, including Tenable Vulnerability Management, Tenable Patch Management, ManageEngine, Rapid7 SIEM/SOAR, and Darktrace. The Senior SOC Analyst works closely with the SOC Manager to strengthen NAD's security posture and ensure compliance with aviation industry security and regulatory requirements Reports To: Assistant Director of Information Technology & Electronics Responsibilities: • Perform advanced Tier 2/3 monitoring, triage, and analysis of security alerts generated across Rapid7 SIEM (InsightIDR), Darktrace, Tenable, and ManageEngine platforms. • Lead end-to-end incident response activities, including detection, containment, eradication, recovery, and post-incident root cause analysis, in accordance with NAD's incident response plan. • Conduct proactive threat hunting using Darktrace's AI-based anomaly detection and Rapid7 SIEM data to identify indicators of compromise (IOCs) and advanced persistent threats (APTs) not surfaced by automated alerting. • Design, build, and maintain automated detection rules, correlation searches, and SOAR playbooks in Rapid7 Insight Connect to reduce mean time to detect (MTTD) and mean time to respond (MTTR). • Oversee vulnerability management operations in Tenable Vulnerability Management, including scan scheduling, false-positive tuning, risk-based prioritization, and coordination of remediation with IT and OT teams. • Manage and validate patch deployment cycles through Tenable Patch Management, ensuring critical and high-risk vulnerabilities are remediated within defined SLAs. • Administer and monitor endpoint, asset, and configuration data within ManageEngine to support accurate asset inventory and vulnerability correlation. • Serve as a technical mentor to Tier 1/2 SOC Analysts, guiding investigation techniques, tool usage, and escalation procedures. • Act as a shift or incident lead in the absence of the SOC Manager, coordinating analyst activities and communicating status to stakeholders during active incidents. • Produce detailed technical incident reports, threat intelligence briefs, and metrics dashboards for SOC leadership and airport stakeholders. • Support security assessments, penetration test remediation, and internal/external audits related to aviation cybersecurity requirements (e.g., TSA Security Directives, ICAO Annex 17, PCI DSS where applicable). • Maintain and continuously tune security tool configurations (Tenable, Rapid7, Darktrace, ManageEngine) to reduce alert fatigue and improve detection fidelity. • Contribute to and maintain SOC documentation, including runbooks, standard operating procedures (SOPs), and escalation matrices. • Participate in a 24/7 on-call rotation and respond to after-hours security incidents affecting critical airport operations. • Stay current on emerging threats, vulnerabilities, and attack techniques relevant to critical infrastructure and the aviation sector. Qualifications: • Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field; equivalent professional experience will be considered in lieu of a degree. • Minimum of 5 years of experience in a Security Operations Center (SOC), incident response, or cybersecurity analyst role, with at least 2 years in a senior or lead analyst capacity. • Demonstrated hands-on experience with SIEM platforms (Rapid7 InsightIDR or equivalent), SOAR/automation platforms, and network detection and response (NDR) tools such as Darktrace. • Practical experience with vulnerability management and patch management tools (Tenable or equivalent), including scan configuration and remediation tracking. • Strong understanding of the MITRE ATT&CK framework, cyber kill chain, and common attack techniques (phishing, malware, lateral movement, privilege escalation, ransomware). • Solid working knowledge of networking fundamentals (TCP/IP, DNS, firewalls, VPNs) and Windows/Linux operating system internals relevant to investigation and forensics. • Experience writing or tuning detection rules, correlation searches, or automation playbooks. • Excellent written and verbal communication skills, with the ability to translate technical findings for non-technical stakeholders. Preferred Qualifications: • Industry certifications such as GCIH, GCIA, GCFA, CySA+, CEH, or equivalent. • Prior experience in critical infrastructure, aviation, transportation, or another highly regulated industry. • Familiarity with aviation-specific regulatory frameworks (TSA Security Directives, ICAO Annex 17, national civil aviation cybersecurity requirements). • Experience with cloud security monitoring (AWS, Azure, or Google Cloud) and OT/ICS security concepts. • Scripting or automation experience (Python, PowerShell, or similar) to support SOAR playbook development. Core Competencies: • Analytical thinking and structured problem-solving under pressure. • Sound judgement and decisiveness during active security incidents. • High attention to detail and commitment to data integrity and confidentiality. • Collaborative mindset with the ability to mentor and support junior team members. • Adaptability in a fast-paced, mission-critical operational environment. • Work Environment & Physical Requirements • Primarily office/SOC-based environment within a secured airport facility, requiring compliance with all airport access, badging, and security clearance procedures. • Extended periods of computer-based work; occasional need to be on-site outside normal hours during active incidents. • Must be able to obtain and maintain any required airport security clearances and background checks in accordance with Bahamian civil aviation security regulations. Working Conditions: • Full-time position with occasional travel required. • Ability to work in a fast-paced, dynamic environment. • Respond promptly and resolve all business-critical system outages promptly • Ability to work extended hours Resumes and relevant certificates should be forwarded via email to people@nas.bs on or before August 26th, 2026. Please indicate the position you are applying for in the subject field.

Want to apply?

Sign in or create a free account.