SOC Analyst
Core
Monitor, detect, and respond to security events using SIEM platforms in a high-scale, cloud-native environment to proactively find and fix exploitable attack vectors.
Role type
Mid-level SOC Analyst (hands-on IC)
Builds
Production security detection and response capabilities, threat intelligence, and automated SOC workflows
Domain
Cybersecurity, Cloud Security, Security Operations
Deliverable
production ML models | dashboards & analysis | client delivery
Required skills
SIEM operations, log analysis, alert triage, incident response, detection rule tuning, query languages (KQL, Lucene, SPL), scripting (Python, Bash, PowerShell), cloud security (AWS/GCP/Azure), MITRE ATT&CK frameworks, SOAR automation, LLM/AI tooling
Preferred skills
EDR/XDR platform experience, agentic workflow design, mentoring junior analysts, high-growth SaaS experience
Technologies
Elastic SIEM, Splunk, Microsoft Sentinel, QRadar, Tines, AWS, GCP, Azure, Claude, Gemini, AWS Bedrock
Responsibilities
Monitor SIEM health and effectiveness, triage and investigate security alerts, tune detection rules to reduce false positives, build dashboards and KPIs, perform root cause analysis and attack-chain mapping, contribute to SOAR automation, participate in proactive threat hunting, document response playbooks
Seniority
Mid-level, hands-on IC