SOC Analyst

<h5><span><strong id="docs-internal-guid-151c59da-7fff-edd5-0d14-5901bdd416ed">About Certora</strong></span></h5><p><span>Certora is the security assurance partner trusted by the most advanced teams in Web3. Founded in 2018 by pioneers in programming languages and formal methods, Certora helps leading protocols like Lido, Aave, Uniswap, and Compound secure billions in value with confidence.<br><br>But we’re not just another auditor. We’re a full-stack security assurance platform, combining best-in-class formal verification tools with expert advisory services, delivered on time and with zero compromise. Whether you’re launching a new protocol, upgrading core infrastructure, or securing a DeFi primitive, Certora doesn’t just look for vulnerabilities. We help you prove correctness, accelerate your development speed, and embed safety into your design from day one.<br><br>With Certora, you get:</span></p><p><span>- Proven, scalable tooling for checking real deployed code</span></p><p><span>- A deep partnership model with on-demand support</span></p><p><span>- Fast, responsive execution that helps you go-to-market faster</span></p><p><span>For us, security isn’t a checklist, it’s a continuous process. Certora is the most comprehensive and trusted platform to ensure your platform is protected, even under adversarial conditions. From testnet to mainnet, we’re with you.</span></p><p><strong id="docs-internal-guid-151c59da-7fff-edd5-0d14-5901bdd416ed"><br></strong><span><strong id="docs-internal-guid-151c59da-7fff-edd5-0d14-5901bdd416ed">About the Role</strong></span></p><p><span>Certora is looking for an experienced SOC Analyst to join our Security Operations team.</span></p><p><span>This role is centered around three core areas: SOC operations, incident response, and Web3 investigations. It is designed for a security professional who can take ownership of security events from initial triage through full investigation and response, while working effectively across internal teams and customer-facing situations.</span></p><p><span>This role goes beyond alert monitoring and triage. It requires strong investigative capabilities, including event research, enrichment, root-cause analysis, and building a clear operational understanding of incidents across multiple environments. We are looking for someone with strong Web2 security fundamentals and deep understanding of Web3 security investigations, attack patterns, and response workflows.</span></p><p><span>This is a non-shift position. However, availability outside business hours is required in the event of critical incidents.</span></p><p><strong id="docs-internal-guid-151c59da-7fff-edd5-0d14-5901bdd416ed"><br></strong><span><strong id="docs-internal-guid-151c59da-7fff-edd5-0d14-5901bdd416ed">Key Responsibilities</strong></span></p><ul><li><p><span>Perform day-to-day SOC operations, including alert handling, triage, escalation, and response coordination</span></p></li><li><p><span>Lead end-to-end security incident investigations and response activities</span></p></li><li><p><span>Handle containment, eradication, recovery, and post-incident follow-up</span></p></li><li><p><span>Investigate and analyze security events across SIEM, EDR, cloud, and Web3-related data sources</span></p></li><li><p><span>Conduct deep event research and enrichment to establish context, assess impact, and support decision-making during incidents</span></p></li><li><p><span>Perform root-cause analysis and build a clear operational understanding of incidents across multiple systems and environments</span></p></li><li><p><span>Produce clear investigation reports, technical findings, and executive-level summaries</span></p></li><li><p><span>Work directly with customers during active security events in a professional and structured manner</span></p></li><li><p><span>Develop and maintain playbooks, runbooks, and operational procedures</span></p></li><li><p><span>Build and maintain automations using SOAR platforms, scripting, and API-based workflows</span></p></li><li><p><span>Develop, tune, and optimize detection rules and correlation logic</span></p></li><li><p><span>Improve SOC operational effectiveness and KPIs such as MTTD, MTTR, automation coverage, and detection quality</span></p></li><li><p><span>Contribute to cross-functional security initiatives and continuous improvement of team processes</span></p></li><li><p><span>Fluent English, with the ability to communicate clearly and professionally in both written and verbal form</span></p></li></ul><p><span><strong id="docs-internal-guid-151c59da-7fff-edd5-0d14-5901bdd416ed"><br>Mandatory Requirements</strong></span></p><ul><li><p><span>3+ years of experience as a SOC Analyst, Incident Responder, or in a similar security operations role</span></p></li><li><p><span>Proven experience handling security incidents end-to-end</span></p></li><li><p><span>Strong hands-on experience in SOC operations, incident response, and security investigations</span></p></li><li><p><span>Strong knowledge of Web2 security fundamentals and deep understanding of Web3 security</span></p></li><li><p><span>Proven experience investigating Web3 attacks, including areas such as smart contracts, wallet abuse, transaction analysis, and on-chain activity investigation</span></p></li><li><p><span>Experience working directly with customers during security incidents or security operations engagements</span></p></li><li><p><span>Advanced hands-on experience with Splunk, including:</span></p><ul><li><p><span>Writing and tuning detection rules</span></p></li><li><p><span>Parsing and data onboarding</span></p></li><li><p><span>Understanding Splunk architecture</span></p></li><li><p><span>Detection optimization and correlation logic</span></p></li></ul></li><li><p><span>Experience working with EDR solutions such as SentinelOne, CrowdStrike, Microsoft Defender, or similar</span></p></li><li><p><span>Strong threat hunting and complex query-writing capabilities</span></p></li><li><p><span>Experience building automations and writing scripts using Python, Bash, and APIs</span></p></li><li><p><span>Ability to work independently, take ownership, and drive tasks through to completion</span></p></li><li><p><span>Strong written and verbal communication skills in English</span></p></li><li><p><span>Ability to work effectively in a remote environment while maintaining clear, proactive, and structured communication with the team lead and the rest of the team</span></p></li></ul><p><span><strong id="docs-internal-guid-151c59da-7fff-edd5-0d14-5901bdd416ed">Nice to Have</strong></span></p><ul><li><p><span>Experience with Detection-as-Code methodologies</span></p></li><li><p><span>Experience with SOAR platforms</span></p></li><li><p><span>Cloud security experience in AWS / Azure / GCP</span></p></li><li><p><span>Experience working in a startup or high-growth environment</span></p></li><li><p><span>Strong incident response methodology knowledge, including root-cause analysis and lessons-learned processes</span></p></li></ul><p><span><strong id="docs-internal-guid-151c59da-7fff-edd5-0d14-5901bdd416ed">Who You Are</strong></span></p><ul><li><p><span>Independent, accountable, and comfortable taking ownership end-to-end</span></p></li><li><p><span>Proactive, hands-on, and solution-oriented</span></p></li><li><p><span>A strong communicator and team player, with the ability to work remotely while maintaining clear and structured reporting</span></p></li><li><p><span>Fast learner, able to quickly ramp up on new technologies, domains, and attack patterns</span></p></li><li><p><span>Analytical and methodical, with strong investigative and root-cause analysis skills</span></p></li><li><p><span>Able to communicate technical findings clearly to both technical and non-technical stakeholders</span></p></li><li><p><span>Process-oriented, with a continuous improvement mindset</span></p></li><li><p><span>Automation-driven and focused on operational efficiency</span></p></li></ul><p><strong id="docs-internal-guid-151c59da-7fff-edd5-0d14-5901bdd416ed"><br></strong><span><strong id="docs-internal-guid-151c59da-7fff-edd5-0d14-5901bdd416ed">Certora People</strong></span></p><p><span>We are Customer Centric, when we commit, the customer knows we will deliver in a quality and timely manner.</span></p><p><span>We Move Fast - we’re looking for people with a bias for action and a sense of urgency to achieve quick results while we also Break Nothing – we have high-quality standards, we are looking for people who are professional and hold themselves accountable.</span></p><p><span>We win as a Team – our teams are distributed around the world. We understand our individual roles and commit to the team's goals.</span></p><p><span>We have a positive “can do” attitude. We support each other and are encouraged to ask for help and advice. We enable people to grow by clarifying expectations and giving candid feedback and on-the-job development opportunities. We welcome collaboration both internally and externally for outstanding delivery.</span></p><p><span>We are Pioneers in DeFi security. We are one of the best companies to help developers and security researchers secure Web3, but we try to stay humble and are always eager to learn more.</span></p><h6><span><strong id="docs-internal-guid-151c59da-7fff-edd5-0d14-5901bdd416ed">Why join Certora?</strong></span></h6><p><span>Certora provides you a wonderful opportunity to:</span></p><ul><li><p><span>Work on cutting-edge technology and challenging problems at the forefront of Web3 applications and technologies</span></p></li><li><p><span>Contribute to securing the web3 ecosystem with the leading provider of end-to-end security for blockchain-based applications</span></p></li><li><p><span>Experience a friendly creative start-up environment with top talent in the domain</span></p></li><li><p><span>Work in a fast-paced and supportive culture: we move fast and break nothing!</span></p></li><li><p><span>Enjoy flexible work (remote / hybrid)</span></p></li><li><p><span>Get competitive compensation & benefits (including equity)</span></p></li></ul><p><strong id="docs-internal-guid-151c59da-7fff-edd5-0d14-5901bdd416ed"><br><br></strong></p>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...