Security Analyst (SOC)
Core
Frontline responder in the Security Operations Center (SOC) identifying, triaging, and remediating security detections and anomalies.
Role type
Security Analyst (SOC)
Builds
Detection capabilities and incident response playbooks
Domain
Cybersecurity / Information Security
Deliverable
client delivery
Required skills
OS auditing (Linux, Windows, macOS), network and host-based collection tools, incident response processes, scripting for automation, reverse engineering, C2 exploitation, system/network forensics, cloud security
Preferred skills
Understanding of threat actor TTPs, SIEM usage (Elastic, Splunk), security community contributions, SANS/GIAC/OSCP certifications
Responsibilities
Identify, triage, and remediate security detections and anomalies; investigate security incidents from detection through root cause; collect evidence and collaborate with engineering teams to secure systems; enhance endpoint and network visibility; contribute to detection capabilities targeting sophisticated attacker TTPs
Seniority
Individual Contributor (IC), entry to mid-level