SOC Analyst L4

Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity

In short

Volvo Group seeks a Principal Cyber Security Analyst (SOC Analyst L4) in Göteborg, SE, to provide technical leadership in threat detection, analysis, and incident response. The role requires over 10 years of hands-on experience with SIEM and SOAR platforms, strong scripting skills, and a proven ability to lead high-severity security incidents and mentor analysts.

Responsibilities

  • Provide technical leadership for advanced threat detection, investigation and response within the SOC.
  • Lead high-severity security incidents investigations, including malware analysis and enterprise-wide investigations.
  • Drive real-time incident response, coordinating containment, remediation, and post-incident reviews.
  • Design, optimize, and maintain detection use cases, monitoring rules, and alert tuning to improve SOC effectiveness.
  • Perform deep analysis across networks, endpoints, and cloud environments to identify and mitigate security risks.
  • Lead and support proactive threat-hunting initiatives and vulnerability mitigation efforts.
  • Collaborate with IT, engineering, digital forensics, and external partners during incident response activities.
  • Develop, standardize, and continuously improve SOC playbooks, procedures, and automation workflows.
  • Mentor analysts, conduct training and incident response exercises, and perform quality reviews of investigations.
  • Act as a subject matter expert, contributing to broader cybersecurity initiatives and continuous improvement programs.

Requirements

  • 10+ years of progressive, hands-on experience in Security Operations, with deep expertise in SIEM and SOAR platforms within enterprise or large-scale SOC environments.
  • Proven technical leadership in incident response, advanced threat detection, and security operations, including ownership of complex and high-impact security incidents.
  • Expert-level experience with SIEM and SOAR technologies (e.g., Splunk, XSOAR), including detection engineering, use case development, and response automation.
  • Strong scripting and automation capabilities using languages such as Python and PowerShell to enhance SOC efficiency and response maturity.
  • In-depth knowledge of network and security protocols, firewalls, server and cloud environments, identity platforms (Active Directory, LDAP, Microsoft Entra ID), and modern attack techniques.
  • Demonstrated experience in continuous security monitoring, vulnerability management, threat hunting, and adversary-based testing activities.

Desired Qualifications

  • Experience with Purple Team operations, detection validation, and/or OT security environments is highly desirable.
  • Strong communication, presentation, and collaboration skills.
  • Analytical and critical thinking abilities.
  • Sense of urgency and effective prioritization in high-pressure situations.
  • Positive mindset and conflict resolution expertise.
  • ITIL Skills (Preferred): Incident Management, Problem Management, and Audit/Assessment Experience.

Benefits

  • Opportunity to work on cutting-edge cybersecurity initiatives.
  • Be part of a collaborative and forward-thinking team.
  • Continuous learning and career development opportunities in the cybersecurity domain.

Skills

PythonPowerShellSplunkXSOARActive DirectoryLDAPMicrosoft Entra ID
#cybersecurity#SOC#threat detection#incident response#SIEM#SOAR
Volvo Group Logo

About Volvo Group

The Volvo Group is one of the world’s leading manufacturers of trucks, buses, construction equipment and marine and industrial engines. The Group also provides complete solutions for financing and service. The Volvo Group, with its headquarters in Gothenburg, employs about 100,000 people, has production facilities in 18 countries and sells its products in more than 190 markets.\n\n

Volvo Group Logo

Company

Volvo Group

Job Posted

1 day ago

Employment Type

Full Time

Work mode

On Site

Experience Level

Senior

Locations

Göteborg, Sweden

Applicants

Be an early applicant