A

ASM Research

·3 days ago

Security operations center (soc) analyst i

Apply now

Location

remote, United States

Commitment

Full Time

Level

Junior (<2 years)

Required skills

SIEMLog AnalysisIncident ResponseThreat DetectionVulnerability ScanningNetwork SecurityEndpoint ProtectionCloud SecurityCase DocumentationRisk PrioritizationFirewall AnalysisIDS/IPSRule TuningPhishing AnalysisMalware AnalysisSecurity Frameworks

Job Description

The Security Operations Center (SOC) Analyst I is a frontline cyber defender responsible for monitoring security tools and dashboards to identify indicators of compromise across networks, endpoints, and cloud‑hosted systems in mission‑critical environments. The role focuses on triaging and analyzing alerts from SIEM and other monitoring platforms, distinguishing true incidents from benign activity and escalating confirmed threats to senior analysts or incident responders. SOC Analyst I staff support basic threat detection, documentation of security events, and coordination with IT and security teams for initial containment, while contributing to tuning rules, improving playbooks, and maintaining awareness of common attack techniques and vulnerabilities.

Key Responsibilities

  • Monitor SIEM platforms and log analysis tools to triage security alerts across network, system, and application layers, identifying potential indicators of compromise.
  • Investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services to identify potential threats and determine whether escalation is warranted.
  • Apply standard incident response playbooks and procedures, including initial containment steps, evidence preservation, and effective handoff to Tier II or incident response teams.
  • Review vulnerability scanning outputs and apply basic risk prioritization concepts to recognize misconfigurations and exploitable weaknesses in enterprise environments.
  • Document security events and incidents with accurate case records and concise reports that support post‑incident review and continuous improvement activities.
  • Follow security frameworks and best practices relevant to highly regulated government or enterprise environments, including access control, monitoring, and logging requirements for mission‑critical systems.
  • Participate in rule tuning and playbook improvements, providing feedback on false positives, emerging patterns, and common attack vectors, malware behaviors, and phishing techniques.

Required Qualifications

  • Bachelor’s Degree in Computer Science, Information Assurance, Cybersecurity, or a related field, or equivalent relevant experience (aligned to Operations Security Planner I standard).
  • Typically 1–3 years of hands‑on experience in IT support, networking, or cybersecurity operations roles, including exposure to security monitoring or incident response.
  • Proficiency with SIEM platforms and log analysis tools for monitoring and triaging security alerts across multiple layers (network, system, application).
  • Ability to investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services, with foundational knowledge of common attack vectors and malware behaviors.
  • Familiarity with basic incident response processes, including initial containment, evidence preservation, and structured escalation to Tier II or incident response teams.
  • U.S. Citizenship required, with ability to satisfy background investigation requirements appropriate to a federal IT environment.
  • Strong written and verbal communication skills, with attention to detail in documenting incidents and maintaining accurate case records.

Preferred Qualifications

  • Experience with at least one enterprise SIEM (e.g., Splunk, QRadar, Azure Sentinel) and creation or tuning of correlation rules.
  • Foundational cybersecurity certification such as CompTIA Security+, CySA+, or equivalent vendor‑neutral credential.
  • Exposure to 24x7 operations or shift‑based monitoring environments supporting large, complex networks.
  • Familiarity with vulnerability scanning tools and outputs, and with standard security frameworks used in highly regulated government or enterprise environments.

Ready to join the team?

Apply now