Description
We are seeking a Cybersecurity Analyst to join our SOC. You will participate in the execution of incident detection, containment, and remediation activities across Windows, Linux, and cloud environments. This role blends hands-on technical response, threat hunting, network analysis, and cross-functional coordination to reduce risk and improve security posture.
Responsibilities
- Incident Response and Network Forensics: Triage, containment, eradication, and recovery for security incidents; perform network-based forensics.
- Detection and Monitoring: Operate and tune SIEM, EDR/XDR, and network detection tools; develop and maintain detection rules, alerts, and dashboards.
- Threat Hunting and Analysis: Proactively hunt for threats using telemetry from endpoints, network devices, cloud services, and logs; map activity to MITRE ATT&CK techniques.
- Malware Analysis: Perform static and dynamic analysis of suspicious binaries and scripts.
- Vulnerability Management: Support vulnerability scanning, prioritize findings, and coordinate remediation with engineering teams.
- Cloud and Identity Security: Investigate incidents in Azure/VMware; analyze identity and access events; support Zero Trust and IAM controls.
- Automation and Playbooks: Create and maintain incident response playbooks and SOAR workflows; automate repetitive tasks with scripting (Python, PowerShell, Bash).
- Logging and Telemetry: Analyze logs from systems and applications.
- Collaboration and Communication: Coordinate with system/network administrators, developers, and external stakeholders; prepare incident reports and brief leads.
- On-call and Emergency Response: On-call for emergencies and respond effectively under pressure to meet critical deadlines.
Qualifications
- Experience: Minimum 5 years working in Windows and Linux environments with hands-on incident response or SOC experience.
- Certifications: CCNA, GCIH, GCIA, OSCP, CEH, Security+ or equivalent.
- Cloud Certifications: AWS/Azure/Oracle security certifications or hands-on cloud security experience.
- Technical Knowledge: Strong understanding of TCP/IP, DNS, SMTP, HTTPS, and other Internet protocols.
- Security Technologies: Practical experience with SIEM, EDR/XDR, firewalls, IDS/IPS, anti-malware, vulnerability scanners, and encryption technologies.
- Network Forensics and Log Analysis: Ability to collect, parse, and interpret logs and artifacts from endpoints, servers, network devices, and cloud services.
- Threat and Exploit Knowledge: Familiarity with common exploitation techniques, software vulnerabilities (e.g., input validation flaws), and attacker tradecraft.
- Scripting and Tools: Proficiency in at least one scripting language (Python, PowerShell, Bash) and experience with forensic and analysis tools (Wireshark, Sysinternals).
- Incident Handling: Familiar with incident response lifecycle, containment/isolation techniques, evidence collection, and chain-of-custody practices.
- Communication: Excellent written and verbal communication skills; able to explain technical decisions clearly to technical and non-technical stakeholders.
- Soft Skills: Strong prioritization, organization, analytical reasoning, attention to detail, and ability to perform under stress.
- Teamwork: Proven ability to collaborate in tightly coordinated teams during emergencies and mentor junior staff.
- Security Mindset: High integrity and ability to handle confidential and sensitive information appropriately.
Benefits InformationRegular - The company offers a comprehensive benefits program, including medical, dental, vision, life insurance, 401(k) and a range of other voluntary benefits. Paid Time Off (PTO) is offered to regular full-time and part-time employees.
Pay Range$80,000 -$90,000
Job ID2026-24382
Work TypeOn-Site