
SOC Analyst
Posted Sep 2

Posted Sep 2
This is a fully remote position, open to applicants in United States.
• Oversee security alerts and events across enterprise systems, networks, endpoints, and applications.
• Examine and investigate potential security incidents and suspicious behaviors.
• Conduct initial triage, validation, and categorization of security alerts.
• Elevate confirmed or high-severity incidents in accordance with established protocols.
• Assist in incident response, containment, and remediation efforts.
• Review and analyze logs from firewalls, IDS/IPS, EDR, servers, applications, and various security controls.
• Collaborate with SIEM platforms to identify threats, correlations, and anomalies.
• Carry out basic threat intelligence and investigative tasks.
• Document security incidents, investigations, findings, and suggested actions.
• Support vulnerability and security monitoring initiatives as needed.
• Contribute to the enhancement of detection rules, alert tuning, and SOC procedures.
• Stay updated on emerging cybersecurity threats, attack methodologies, and industry best practices.
• Candidates may be considered for relevant roles as opportunities arise via the Ready-to-Hire Portal.
• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related discipline, or equivalent practical experience.
• Experience in a SOC, cybersecurity, IT security, or a similar role.
• Solid understanding of networking concepts, TCP/IP, DNS, HTTP/HTTPS, VPNs, firewalls, and standard network protocols.
• Familiarity with security monitoring and incident response protocols.
• Practical experience with SIEM, EDR, IDS/IPS, or other security monitoring technologies.
• Knowledge of Windows and Linux operating systems and their respective security logs.
• Awareness of common cyber threats, attack strategies, malware, phishing, and credential-based attacks.
• Strong analytical, troubleshooting, and problem-solving abilities.
• Effective written and verbal communication skills.
• Preferred: Experience with platforms like Microsoft Sentinel, Splunk, IBM QRadar, Elastic, or similar SIEM solutions.
• Preferred: Knowledge of MITRE ATT&CK and common threat-hunting methodologies.
• Preferred: Relevant certifications such as Security+, CySA+, CEH, GCIH, or equivalent.
• Preferred: Experience with EDR/XDR solutions and endpoint investigations.
• Preferred: Basic scripting or automation skills using Python, PowerShell, or similar technologies.
• Experience in a 24/7 SOC environment is a plus.
• Remote work arrangement.
• 8 working hours per day plus a 1-hour break.
• 2 days off per week (to be determined).
Capgemini
Teamified
Get handpicked remote jobs straight to your inbox weekly.