
Security Operations Center (SOC) Analyst
Posted 20 hours ago

Posted 20 hours ago
This is a fully remote position, open to applicants in Maryland.
• Continuously monitor client environments for cybersecurity threats utilizing SIEM, endpoint detection and response, identity protection, and email security platforms.
• Manage the live alert queue during each shift; triage detections, assess scope and severity, and execute or authorize suitable responses.
• Conduct structured handoffs at the end of each shift, ensuring every detection, investigation, and client commitment has a designated owner.
• Investigate incidents related to account compromise, business email compromise, social engineering, malware, and ransomware.
• Analyze potentially compromised assets including servers, workstations, and identities.
• Contain and remediate confirmed threats through automation workflows, scripts, policies, playbooks, and platform controls.
• Escalate incidents per the incident response plan when they surpass the analyst’s authority or expertise.
• Deliver timely and professional incident communications to clients and internal stakeholders.
• Conduct scheduled vulnerability scans across client environments.
• Assist in meeting CMMC and NIST SP 800-171 compliance objectives by generating necessary monitoring evidence, logs, and reports.
• Review overnight Tines automation logs, validate automated actions, and address or escalate any exceptions.
• Respond to overnight escalations while on call and document all actions taken.
• Identify repetitive manual tasks and false positives for potential automation or detection tuning.
• Test and provide structured feedback on new detections and automation workflows.
• Track and document all activities in the ticketing system.
• Meet key performance indicators (KPIs), support colleagues across both shifts, and escalate assignments when necessary.
• A minimum of two years of experience in security operations, incident response, or systems administration with a clear security focus.
• Proven experience in investigating and responding to identity, endpoint, and email-based threats within Microsoft 365 environments.
• Proficient understanding of SIEM operations, log analysis, and alert triage methodologies.
• Familiarity with common attack techniques and the MITRE ATT&CK framework.
• Knowledge of endpoint detection and response, identity protection, and email security controls and remediation strategies.
• Ability to conduct disciplined, well-documented investigations.
• Strong understanding of Microsoft 365 and Entra ID administration, including conditional access, authentication methods, and audit logging.
• Working knowledge of Windows server and workstation operating systems, Active Directory, TCP/IP, DNS, firewalls, and VPN.
• Familiarity with vulnerability scanning platforms and remediation processes.
• Comfort with validating and troubleshooting automated playbooks, including Tines or similar SOAR tools.
• Basic scripting or querying skills in PowerShell, KQL, or equivalent.
• Consistent ticket hygiene and documentation practices.
• Ability to craft clear, professional communications directed at clients.
• Reliability and self-management suitable for a remote, shift-based role.
• CompTIA Security+ certification, or the ability to obtain it within the first six months.
• CompTIA Network+ certification, or the ability to obtain it within the first six months.
• Availability to work EST hours is required.
• Experience in a managed service provider environment is highly preferred.
• Experience supporting CMMC, NIST SP 800-171, or similar regulatory frameworks is advantageous.
• Prior experience in detection engineering or automation playbook development is desirable.
• Experience in a 24x7 or shift-based security operations setting is preferred.
• Medical Insurance — OSIbeyond covers 75% of the premium for the Employee's base medical plan.
• Vision and Dental Insurance — OSIbeyond pays 75% of the premium for the Employee's plans.
• Life Insurance — OSIbeyond covers 100% of the premium for the Employee's plans.
• Short Term Disability Insurance — OSIbeyond pays 100% of the premium for the Employee's plans.
• 401K with employer matching up to 4%.
• Nine paid holidays.
• Accrual-based PTO that increases with tenure; new hires begin with two weeks.
It4us Cyber Security
CFA Institute
Invicti
Get handpicked remote jobs straight to your inbox weekly.