Skip to content
HappyRobotHappyRobot

SOC Analyst

The SOC Analyst owns alert triage, investigates cloud, identity, and endpoint activity, and escalates incidents with actionable context. The role requires 2–3 years of SOC or blue-team experience, hands-on SIEM and EDR work, strong incident documentation, and English communication skills.

About the job

Responsibilities

Alert Triage

  • Own the alert queue during coverage hours.
  • Prioritize and disposition alerts accurately and quickly; acknowledge high-severity alerts within 15 minutes and disposition all alerts within SLA.
  • Distinguish true positives from noise and act accordingly.

Log and Threat Analysis

  • Analyze cloud, identity, and endpoint log sources to build timelines for alerts requiring deeper investigation.
  • Use MITRE ATT&CK to understand attack activity in context.

Incident Escalation and Communication

  • Escalate incidents with severity reasoning, timelines, affected systems, and recommended next steps.
  • Write clear incident notes and escalations in English.

Runbook Discipline and Improvement

  • Follow runbooks rigorously.
  • Identify incorrect steps, missing cases, and outdated assumptions, and propose fixes.

Tuning Feedback Loop

  • Participate in a weekly feedback cycle with the SOC Engineer.
  • Report false positives, noise patterns, and detection logic requiring adjustment.

Audit Readiness

  • Keep monitoring and response evidence current and organized for SOC 2, ISO 27001, and customer incident-response commitments.

Requirements

  • 2–3 years of experience as a SOC analyst or in a blue-team, detection, or response role.
  • Hands-on alert-triage experience with a SIEM and EDR, including investigation, disposition, and escalation.
  • Log-analysis experience across cloud, identity, and endpoint sources.
  • Working knowledge of MITRE ATT&CK and common attack patterns.
  • Clear written incident notes and escalations in English at B2+ level.
  • Ability to work a coverage-hours rotation.

Nice to Have

  • Familiarity with AWS, Azure, or Google Cloud consoles.
  • Basic Python or Bash scripting.
  • Phishing and email-threat analysis experience.
  • BTL1, GCIH, Security+, or CySA+ certification.
  • Exposure to detection tuning or writing simple detection rules.
  • Experience at a SaaS or technology startup.

Compensation and Benefits

  • Competitive salary and equity.
  • Healthcare, dental, and vision coverage.

Skills

SIEM, Edr, Mitre Att&Ck, Cloud Security, Identity Security, Endpoint Security, AWS, Azure, GCP, Python, Bash, Phishing Analysis, Detection Tuning, SOC 2, ISO 27001

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

Docker

Docker

United Kingdom
Senior Security Engineer, Offensive Security
€119k+/yrRemote5+ YOESecurity Engineering

Senior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Wiz

Wiz

Berlin, Germany
Security Engineer - Product
No salary listedOn-site7+ YOESecurity Engineering

Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.