
SOC Analyst
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in United States.
• Oversee, identify, and act upon security events throughout enterprise environments utilizing the SIEM.
• Assist in log ingestion, parsing, normalization, and health monitoring across AWS, Okta, endpoints, firewalls, and SaaS sources.
• Collaborate with system owners to address telemetry gaps.
• Develop and sustain dashboards, visualizations, and KPIs that illustrate SIEM effectiveness and security visibility.
• Triage, investigate, and validate alerts, escalating confirmed or ambiguous incidents with comprehensive context.
• Refine and test behavioral, heuristic, and signature-based detection rules.
• Utilize MITRE ATT&CK to provide context for detections and recognize coverage gaps.
• Analyze logs from cloud, endpoints, networks, and applications to detect anomalies and potential threats.
• Conduct structured investigations and root-cause analyses, including attack-chain mapping and remediation guidance.
• Adhere to and enhance response playbooks for phishing, suspicious logins, endpoint malware, privilege escalation, and cloud misconfigurations.
• Record lessons learned and improve detection logic.
• Contribute to SOAR automation efforts to minimize manual labor and enhance MTTD and MTTR.
• Employ LLM/AI-assisted tools for triage, log summarization, and investigation enrichment, ensuring verification of model output before proceeding.
• Engage in proactive threat hunting activities.
• Contribute to weekly and monthly reports on threat trends, false-positive reduction, and detection efficiency.
• Maintain communication with shift peers and stakeholders.
• Assist in training and onboarding junior analysts as growth occurs.
• Report to the SOC Manager and operate within a SOC shift.
• Practical SOC or security analyst experience encompassing SIEM monitoring, alert triage, detection tuning, and incident response.
• Proficient experience with an enterprise SIEM such as Elastic SIEM, Splunk, Microsoft Sentinel, QRadar, or similar platforms.
• Strong understanding of log analysis, security telemetry, and event correlation.
• Proficiency in KQL, Lucene, or SPL, along with scripting in Python, Bash, or PowerShell.
• Familiarity with AWS, GCP, or Azure and their associated security tools.
• Working knowledge of MITRE ATT&CK, NIST, and CIS frameworks.
• Practical experience using LLMs/AI tools in a professional setting, including prompting, grounding responses in reliable data, recognizing model limitations, and validating output.
• Excellent analytical and problem-solving abilities, capable of prioritizing and managing tasks with minimal supervision.
• Proficient written and verbal communication skills, with the ability to document processes and findings clearly.
• Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field, or equivalent hands-on security operations experience.
• 3–6 years of experience in a SOC or security analyst position.
• Proven hands-on experience managing an enterprise SIEM within a cloud environment.
• Experience with SOAR/automation platforms such as Tines or similar solutions.
• Familiarity with enterprise LLM/AI platforms like Claude, Gemini, AWS Bedrock, or similar.
• Only U.S. persons are eligible for interviews due to security clearance requirements.
• Must qualify for and successfully obtain a U.S. Federal Security Clearance as a condition of employment.
• Certifications such as Security+, CySA+, GCIA, GCIH, or Elastic Certified Analyst are preferred qualifications.
• Hands-on experience with EDR or XDR, agent-based workflows, mentoring/onboarding, and experience in a rapidly growing SaaS or cybersecurity company are preferred qualifications.
• Equity package in the form of stock options available for all full-time positions.
• Health, vision, and dental insurance coverage for you and your family.
• Flexible vacation policy to promote work-life balance.
• Generous parental leave policy.
• Opportunities for career development and advancement.
• An inclusive and collaborative workplace culture.
• Fully remote work arrangements available.
• Up to 5% travel required.
NBCUniversal
NBCUniversal
GuidePoint Security
Huntress
Get handpicked remote jobs straight to your inbox weekly.