SOC Analyst
Core
Monitor, triage, and investigate security alerts and incidents across SIEM, EDR, and cloud environments to protect systems and users.
Role type
SOC Analyst (Security Operations)
Builds
Security operations, incident response, and vulnerability management processes
Domain
Cyber Security / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security alert triage, incident investigation, SIEM/EDR/XDR usage, vulnerability management, networking fundamentals, Windows/Linux administration, cloud platform knowledge (AWS/Azure/GCP), analytical troubleshooting, technical documentation
Preferred skills
CrowdStrike Falcon, Microsoft Defender, Google Chronicle, Microsoft Sentinel, Splunk, MITRE ATT&CK, IoC analysis, security automation/SOAR, KQL, PowerShell, Python scripting, CompTIA Security+, CySA+
Technologies
SIEM, EDR, XDR, CrowdStrike, Microsoft Defender, Google Chronicle, Microsoft Sentinel, Splunk, AWS, Azure, GCP, KQL, PowerShell, Python
Responsibilities
Monitor and triage security alerts across security platforms; Investigate suspicious endpoint, email, identity, and cloud activity; Analyze security logs and indicators of compromise; Support vulnerability management and remediation tracking; Maintain investigation records, security tickets, and runbooks; Collaborate with IT, Engineering, and Cloud teams to resolve security issues
Seniority
Junior to Mid-level, hands-on IC
