
SOC Analyst I
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in United States.
• Oversee security events and alerts utilizing SIEM tools and various security technologies.
• Evaluate and prioritize security alerts to assess their severity and potential consequences.
• Conduct initial incident response activities and escalate issues as needed.
• Record and monitor security incidents along with their resolutions.
• Aid in the creation and upkeep of security documentation and procedures.
• Contribute to the enhancement and development of security metrics and reporting.
• Collaborate with colleagues and departments to address security issues.
• Partner with SOC Analyst II to create and refine SIEM correlation rules.
• Remain updated on emerging threats and trends in security.
• Complete onboarding for Apollo's SOC tool stack.
• Shadow senior analysts during monitoring shifts to learn alert triage, escalation thresholds, severity classifications, and incident documentation standards.
• Monitor and triage low-complexity alerts under supervision, then independently during designated shifts.
• Engage in shift handoffs and report emerging patterns to Analyst IIs.
• Independently manage a full monitoring workload across assigned shifts.
• Draft or enhance a SOC procedure document, runbook, or triage playbook adopted by the team.
• Exhibit working proficiency with at least one SIEM platform beyond basic alert consumption.
• Fundamental understanding of networking concepts, protocols, and security principles.
• Familiarity with common security tools and technologies, including firewalls, IDS/IPS, and SIEM.
• Strong analytical and problem-solving abilities.
• Excellent written and verbal communication skills.
• Capacity to work in a fast-paced environment and manage multiple priorities.
• Basic scripting or programming knowledge, such as Python or PowerShell.
• Availability to work shifts, including swings, nights, weekends, and holidays.
• Experience with CrowdStrike, Sophos, and/or SentinelOne platforms is preferred.
• Familiarity with SIEM platforms such as Stellar, Splunk, Exabeam, LogRhythm, or Elastic is preferred.
• Experience with cloud security concepts and technologies is preferred.
• Familiarity with threat intelligence platforms and processes is preferred.
• Understanding of the MITRE ATT&CK framework is preferred.
• Familiarity with network infrastructure and security concepts is preferred.
• Experience with enterprise firewall platforms such as Sophos, Fortinet, Cisco, or Check Point is preferred.
• Must complete a background check and obtain CJIS certification.
• Must be legally authorized to work in the United States.
• Must be willing and able to work shifts, including swings, nights, weekends, and holidays.
• Comprehensive medical, dental, and vision coverage; the company pays 100% of employee premiums and 90% of dependent premiums on base plans.
• Unlimited PTO.
• 7 paid sick days.
• 11 paid holidays.
• 401(k) with a 4% company match after 90 days, with immediate vesting.
• Company-paid life insurance at 1x annual salary.
• Company-paid Short-Term Disability (STD) coverage.
• Company-paid Long-Term Disability (LTD) coverage.
• $125 monthly home-office tech stipend for internet, equipment, and other technology needs.
• Collaborative, supportive, growth-focused culture.
• Primarily remote work with a Denver hub.
Talan
Pragmatike
Supply Chimp
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.