SOC Analyst
Early-career SOC Analyst monitoring and triaging security alerts with SIEM, EDR, and IDS/IPS tools in a cloud environment. Requires 1-2 years experience, foundational security knowledge, and strong analytical skills; preferred scripting and certifications.
About the job
Key Responsibilities
- Monitor and analyze security alerts using tools such as SIEM, IDS/IPS, and EDR.
- Perform initial triage and investigation of security incidents, escalating as needed.
- Assist in responding to threats such as phishing, malware, and suspicious network or cloud activity.
- Support incident response efforts, including containment and recovery activities.
- Conduct basic threat hunting and IOC analysis under senior analyst guidance.
- Help maintain and improve security documentation, playbooks, and SOPs.
- Collaborate with IT, Cloud, and DevOps teams to support security best practices.
- Participate in ongoing training and learning to build skills in incident response, threat intelligence, and detection engineering.
- Use AI-assisted tools (including LLMs) to support alert triage, investigation, and documentation.
- Assist in evaluating AI-driven detections and automations to improve SOC efficiency.
- Learn best practices for securely using generative AI in security operations.
Required Qualifications
- 1–2 years of experience in information security, IT, or a related field.
- Foundational understanding of security concepts such as threat detection, incident response, and networking.
- Familiarity with SIEM platforms (e.g., Splunk, Chronicle) and endpoint or network security tools.
- Basic knowledge of cloud environments (AWS, GCP, or Azure) is a plus.
- Strong analytical and problem-solving skills.
- Ability to work collaboratively and communicate clearly within a team.
Preferred Qualifications
- Exposure to scripting or automation (e.g., Python, Bash).
- Familiarity with threat intelligence, basic forensics, or vulnerability management.
- Security certifications such as Security+, CEH, or similar.
Skills
SIEM, Ids/Ips, Edr, Splunk, Chronicle, AWS, GCP, Azure, Python, Bash, Threat Intelligence, Incident Response
Similar jobs
Security Engineering jobsEarly-career cybersecurity professional implementing and monitoring security controls across Linux, Kubernetes, database, and AI infrastructure. Requires 1–3 years of hands-on technical experience, Linux and scripting skills, and interest in federal authorization and security engineering.
Build security into embedded vehicle platforms through security assessments, secure boot implementation, and HSM integration. This new-grad role requires a relevant computer or electrical engineering degree, foundational cryptography knowledge, and proficiency in C, C++, or Python.
Corporate Security Engineer responsible for identity, endpoint, SaaS, and security automation controls across the company. The role requires 2–5 years of security engineering experience, hands-on endpoint and EDR expertise, identity protocol knowledge, and scripting ability.
Own and operate Vertex Synapse, integrating and modeling threat intelligence while delivering it to detections, blocklists, data pipelines, and security workflows. Requires at least two years of production threat-intelligence platform or security data-pipeline experience and software development skills in Python, Go, or Storm.
Build foundational security services and automation protecting Hover’s applications, users, and cloud infrastructure. The role suits an early-career software engineer with strong programming fundamentals, a computer science background, and interest in secure development practices.