SOC Analyst
Core
Own alert triage during coverage hours, prioritizing and dispositioning security alerts to distinguish signal from noise and escalate incidents with actionable context.
Role type
SOC Analyst (Alert Triage & Incident Escalation)
Builds
Reliable, measurable alert handling and incident response workflows for enterprise AI infrastructure.
Domain
Cybersecurity (SOC/Blue Team) within AI Infrastructure and SaaS.
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
Alert triage, SIEM investigation, EDR investigation, Log analysis (cloud/identity/endpoint), MITRE ATT&CK framework, Incident escalation, Runbook execution, Technical writing
Preferred skills
Cloud console familiarity (AWS/Azure/GCP), Scripting (Python/Bash), Phishing analysis, Detection tuning
Technologies
SIEM, EDR, MITRE ATT&CK, AWS, Azure, GCP
Responsibilities
Triage and disposition alerts within SLA; Investigate logs across cloud, identity, and endpoint sources; Escalate incidents with clear context and recommendations; Flag and propose fixes for outdated runbooks; Provide feedback on detection logic to reduce false positives; Maintain documentation for audit readiness (SOC 2, ISO 27001).
Seniority
Mid-level, hands-on IC
