Information Security Analyst (SOC Analyst)
Quick Overview
Job Description
Experience: 12+ years
Position Summary
The SOC Analyst is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the organization''s technology environment. This role serves as a frontline defender against cyber threats by analyzing security alerts, conducting incident investigations, and escalating security events as appropriate. The analyst works closely with IT, infrastructure, cloud, and application teams to protect organizational assets, maintain security monitoring capabilities, and strengthen the overall security posture.
Key Responsibilities
Security Monitoring & Detection
· Monitor security events and alerts generated by SIEM, EDR, IDS/IPS, email security, cloud security, and other security tools.
· Analyze and triage security alerts to determine legitimacy, severity, and business impact.
· Identify indicators of compromise (IOCs), suspicious behavior, and emerging threats.
· Perform continuous threat monitoring and situational awareness activities.
Incident Response
· Investigate cybersecurity incidents including malware infections, phishing attacks, account compromises, insider threats, and unauthorized access attempts.
· Execute incident response procedures and playbooks.
· Document findings, actions taken, and lessons learned.
· Coordinate containment, eradication, and recovery activities with appropriate stakeholders.
· Escalate significant incidents according to established procedures.
Threat Hunting & Intelligence
· Utilize threat intelligence feeds to enrich investigations.
· Research emerging threats, vulnerabilities, and attack techniques.
· Develop and refine detection use cases based on threat intelligence and incident trends.
Security Operations
· Support vulnerability management efforts by validating findings and tracking remediation.
· Assist with security tool administration and tuning.
· Review and improve alerting logic to reduce false positives.
· Participate in security assessments and operational readiness activities.
· Support audit and compliance initiatives as required.
Documentation & Reporting
· Maintain accurate incident records, investigation notes, and operational metrics.
· Prepare reports on security incidents, trends, and findings.
· Contribute to development and maintenance of standard operating procedures (SOPs).
· Provide security recommendations to business and technical stakeholders.
Collaboration
Work closely with infrastructure, networking, cloud, and identity teams.
Participate in on-call rotations and after-hours incident response activities when required.
Support user awareness efforts through identification of phishing and social engineering trends.
Required Qualifications
Education
· Bachelor''s degree in Cybersecurity, Information Security, Information Technology, Computer Science, or related field; or equivalent combination of education and experience.
Experience
· 1–3 years of cybersecurity, information security, IT operations, or SOC experience (Level I/II).
· Experience investigating security alerts and incidents.
· Familiarity with SIEM platforms and security monitoring tools.
Technical Skills Knowledge of:
· (Preferred) Security Information and Event Management (SIEM) platforms (Splunk)
· (Preferred) Endpoint Detection and Response (EDR) solutions (Crowdstrike)
· (Preferred) Reliaquest managed detection and response (MDR) and Servicenow experience
· Microsoft 365 and Azure security technologies
· Network security concepts and protocols
· Identity and Access Management (IAM)
· Windows, Linux, and cloud environments
· MITRE ATT&CK framework
· Incident response methodologies
Analytical Skills
· Strong troubleshooting and investigative abilities
· Ability to prioritize multiple security events in a fast-paced environment
· Excellent attention to detail
· Strong written and verbal communication skills
Preferred Qualifications &Certifications
One or more of the following:
· CompTIA Security+
· CompTIA CySA+
· GIAC Certified Incident Handler (GCIH)
· GIAC Security Essentials (GSEC)
· SSCP
· Certified Ethical Hacker (CEH)
· SC-200 Security Operations Analyst
· CISSP
Preferred Experience
· Experience with Splunk, Microsoft core infrastructure technologies (Entra/Active Directory, Sharepoint, Copilot, etc.), CrowdStrike, or similar platforms.
· Experience with SOAR and security automation technologies.
· Exposure to cloud security platforms (Azure, AWS, Google Cloud Platform).
· Knowledge of NIST Cybersecurity Framework and incident response best practices.
Key Competencies
· Critical Thinking
· Problem Solving
· Attention to Detail
· Risk Awareness
· Team Collaboration
· Situational Awareness
· Adaptability
· Communication Skills
· Customer Service Mindset
Success Metrics
The SOC Analyst will be evaluated on:
· Mean Time to Detect (MTTD)
· Mean Time to Respond (MTTR)
· Alert triage accuracy
· Incident documentation quality
· Reduction of false positives
· Adherence to incident response procedures
Contribution to security improvements and automation
Skills
Similar jobs
Senior Cybersecurity Engineer
Carnegie Mellon University · Pittsburgh, United States
2 hours agoPrincipal / Sr. Principal Cyber Systems Engineer with Security Clearance
Northrop Grumman · Fairfax, United States
2 hours ago$125.3k - $187.9k/yrSr Principal Cyber Systems Engineer with Security Clearance
Northrop Grumman · Aurora, United States
2 hours ago$156.4k - $234.6k/yrPrincipal Cyber Systems Engineer (S) with Security Clearance
Northrop Grumman · Jessup, United States
2 hours ago$125.3k - $187.9k/yrInformation Systems Security Engineer (ISSE) with Security Clearance
Abacus Technology Corporation · Hanscom AFB, United States
2 hours ago$180.7k - $210k/yrCyber Systems Engineer - Level 4 with Security Clearance
Northrop Grumman · Huntsville, United States
2 hours ago$149.3k - $223.9k/yr