Security Operations Center (SOC) Analyst

Posted 20 hours ago

This is a fully remote position, open to applicants in Maryland.

📋 Description

• Continuously monitor client environments for cybersecurity threats utilizing SIEM, endpoint detection and response, identity protection, and email security platforms.

• Manage the live alert queue during each shift; triage detections, assess scope and severity, and execute or authorize suitable responses.

• Conduct structured handoffs at the end of each shift, ensuring every detection, investigation, and client commitment has a designated owner.

• Investigate incidents related to account compromise, business email compromise, social engineering, malware, and ransomware.

• Analyze potentially compromised assets including servers, workstations, and identities.

• Contain and remediate confirmed threats through automation workflows, scripts, policies, playbooks, and platform controls.

• Escalate incidents per the incident response plan when they surpass the analyst’s authority or expertise.

• Deliver timely and professional incident communications to clients and internal stakeholders.

• Conduct scheduled vulnerability scans across client environments.

• Assist in meeting CMMC and NIST SP 800-171 compliance objectives by generating necessary monitoring evidence, logs, and reports.

• Review overnight Tines automation logs, validate automated actions, and address or escalate any exceptions.

• Respond to overnight escalations while on call and document all actions taken.

• Identify repetitive manual tasks and false positives for potential automation or detection tuning.

• Test and provide structured feedback on new detections and automation workflows.

• Track and document all activities in the ticketing system.

• Meet key performance indicators (KPIs), support colleagues across both shifts, and escalate assignments when necessary.


⛳️ Requirements

• A minimum of two years of experience in security operations, incident response, or systems administration with a clear security focus.

• Proven experience in investigating and responding to identity, endpoint, and email-based threats within Microsoft 365 environments.

• Proficient understanding of SIEM operations, log analysis, and alert triage methodologies.

• Familiarity with common attack techniques and the MITRE ATT&CK framework.

• Knowledge of endpoint detection and response, identity protection, and email security controls and remediation strategies.

• Ability to conduct disciplined, well-documented investigations.

• Strong understanding of Microsoft 365 and Entra ID administration, including conditional access, authentication methods, and audit logging.

• Working knowledge of Windows server and workstation operating systems, Active Directory, TCP/IP, DNS, firewalls, and VPN.

• Familiarity with vulnerability scanning platforms and remediation processes.

• Comfort with validating and troubleshooting automated playbooks, including Tines or similar SOAR tools.

• Basic scripting or querying skills in PowerShell, KQL, or equivalent.

• Consistent ticket hygiene and documentation practices.

• Ability to craft clear, professional communications directed at clients.

• Reliability and self-management suitable for a remote, shift-based role.

• CompTIA Security+ certification, or the ability to obtain it within the first six months.

• CompTIA Network+ certification, or the ability to obtain it within the first six months.

• Availability to work EST hours is required.

• Experience in a managed service provider environment is highly preferred.

• Experience supporting CMMC, NIST SP 800-171, or similar regulatory frameworks is advantageous.

• Prior experience in detection engineering or automation playbook development is desirable.

• Experience in a 24x7 or shift-based security operations setting is preferred.


🏝️ Benefits

• Medical Insurance — OSIbeyond covers 75% of the premium for the Employee's base medical plan.

• Vision and Dental Insurance — OSIbeyond pays 75% of the premium for the Employee's plans.

• Life Insurance — OSIbeyond covers 100% of the premium for the Employee's plans.

• Short Term Disability Insurance — OSIbeyond pays 100% of the premium for the Employee's plans.

• 401K with employer matching up to 4%.

• Nine paid holidays.

• Accrual-based PTO that increases with tenure; new hires begin with two weeks.

People also viewed

It4us Cyber Security1 day ago

SOC Analyst N2/N3

BR flagBrazil OnlyFreelanceSecurity Operations
ApplyView job
Magna51 day ago

Senior SOC Analyst

US flagUnited States OnlyFull-timeSecurity Operations
ApplyView job
CFA Institute1 day ago

Security Operations Analyst II

US flagFlorida, +3 more statesFull-timeSecurity Operations$83k – $110k/year
ApplyView job
Invicti1 day ago

Senior Security Operations Engineer – Europe

RO flagRomania OnlyFull-timeSecurity Operations
ApplyView job
Proofpoint1 day ago

Senior SOC Engineer

AR flagArgentina OnlyFull-timeSecurity Operations
ApplyView job
Ralliant1 day ago

Privacy and Cyber Operations Specialist

SK flagSlovakia OnlyFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers