Security Operations Analyst
Core
Hands-on Security Operations Center (SOC) analyst monitoring alerts, investigating security events, supporting incident response, and applying threat intelligence/hunting to strengthen detection capabilities.
Role type
Senior IC Security Operations Analyst (SOC)
Builds
SOC alert triage, incident response workflows, threat detections, and security playbooks
Domain
Cybersecurity / Threat Intelligence / Incident Response
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Security monitoring, alert triage, incident investigation, SIEM/EDR platform usage, network/OS/cloud security fundamentals, cyber threat intelligence concepts, technical writing
Preferred skills
Threat hunting, detection engineering, SOAR platforms, scripting (PowerShell/Python/KQL/SPL), relevant security certifications
Technologies
SIEM, EDR, SOAR, MITRE ATT&CK, PowerShell, Python, KQL, SPL
Responsibilities
Monitor and manage SOC alert queue across endpoint, identity, network, email, cloud, and log platforms; Independently triage and investigate security alerts distinguishing threats from benign activity; Support full incident lifecycle including investigation, escalation, containment, remediation, and closure; Apply playbooks/runbooks and identify opportunities for automation and improvement; Analyze threat intelligence to identify threats, campaigns, and adversary behaviors; Enrich investigations with context on threat actors, malware, and vulnerabilities; Assist with threat hunts across various telemetry sources; Partner with engineers to convert intelligence into detections and response improvements
Seniority
Mid-level, hands-on IC