Haystack
← Back to Jobs
Technology

Information Security Analyst (SOC Analyst)

kjohn@samrusystems.comUnited States🇺🇸United StatesPosted 20 Jul 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Experience: 12+ years

Position Summary

The SOC Analyst is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the organization''s technology environment. This role serves as a frontline defender against cyber threats by analyzing security alerts, conducting incident investigations, and escalating security events as appropriate. The analyst works closely with IT, infrastructure, cloud, and application teams to protect organizational assets, maintain security monitoring capabilities, and strengthen the overall security posture.

 

Key Responsibilities

Security Monitoring & Detection

·         Monitor security events and alerts generated by SIEM, EDR, IDS/IPS, email security, cloud security, and other security tools.

·         Analyze and triage security alerts to determine legitimacy, severity, and business impact.

·         Identify indicators of compromise (IOCs), suspicious behavior, and emerging threats.

·         Perform continuous threat monitoring and situational awareness activities.

 

Incident Response

·         Investigate cybersecurity incidents including malware infections, phishing attacks, account compromises, insider threats, and unauthorized access attempts.

·         Execute incident response procedures and playbooks.

·         Document findings, actions taken, and lessons learned.

·         Coordinate containment, eradication, and recovery activities with appropriate stakeholders.

·         Escalate significant incidents according to established procedures.

 

Threat Hunting & Intelligence

·         Utilize threat intelligence feeds to enrich investigations.

·         Research emerging threats, vulnerabilities, and attack techniques.

·         Develop and refine detection use cases based on threat intelligence and incident trends.

Security Operations

·         Support vulnerability management efforts by validating findings and tracking remediation.

·         Assist with security tool administration and tuning.

·         Review and improve alerting logic to reduce false positives.

·         Participate in security assessments and operational readiness activities.

·         Support audit and compliance initiatives as required.

Documentation & Reporting

·         Maintain accurate incident records, investigation notes, and operational metrics.

·         Prepare reports on security incidents, trends, and findings.

·         Contribute to development and maintenance of standard operating procedures (SOPs).

·         Provide security recommendations to business and technical stakeholders.

Collaboration

Work closely with infrastructure, networking, cloud, and identity teams.

Participate in on-call rotations and after-hours incident response activities when required.

Support user awareness efforts through identification of phishing and social engineering trends.

 

 

Required Qualifications

Education

·         Bachelor''s degree in Cybersecurity, Information Security, Information Technology, Computer Science, or related field; or equivalent combination of education and experience.

 

Experience

·         1–3 years of cybersecurity, information security, IT operations, or SOC experience (Level I/II).

·         Experience investigating security alerts and incidents.

·         Familiarity with SIEM platforms and security monitoring tools.

 

 

Technical Skills Knowledge of:

·         (Preferred) Security Information and Event Management (SIEM) platforms (Splunk)

·         (Preferred) Endpoint Detection and Response (EDR) solutions (Crowdstrike)

·         (Preferred) Reliaquest managed detection and response (MDR) and Servicenow experience

·         Microsoft 365 and Azure security technologies

·         Network security concepts and protocols

·         Identity and Access Management (IAM)

·         Windows, Linux, and cloud environments

·         MITRE ATT&CK framework

·         Incident response methodologies

 

Analytical Skills

·         Strong troubleshooting and investigative abilities

·         Ability to prioritize multiple security events in a fast-paced environment

·         Excellent attention to detail

·         Strong written and verbal communication skills

 

 

Preferred Qualifications &Certifications

One or more of the following:

·         CompTIA Security+

·         CompTIA CySA+

·         GIAC Certified Incident Handler (GCIH)

·         GIAC Security Essentials (GSEC)

·         SSCP

·         Certified Ethical Hacker (CEH)

·         SC-200 Security Operations Analyst

·         CISSP

 

 

Preferred Experience

·         Experience with Splunk, Microsoft core infrastructure technologies (Entra/Active Directory, Sharepoint, Copilot, etc.), CrowdStrike, or similar platforms.

·         Experience with SOAR and security automation technologies.

·         Exposure to cloud security platforms (Azure, AWS, Google Cloud Platform).

·         Knowledge of NIST Cybersecurity Framework and incident response best practices.

 

Key Competencies

·         Critical Thinking

·         Problem Solving

·         Attention to Detail

·         Risk Awareness

·         Team Collaboration

·         Situational Awareness

·         Adaptability

·         Communication Skills

·         Customer Service Mindset

Success Metrics

The SOC Analyst will be evaluated on:

·         Mean Time to Detect (MTTD)

·         Mean Time to Respond (MTTR)

·         Alert triage accuracy

·         Incident documentation quality

·         Reduction of false positives

·         Adherence to incident response procedures

Contribution to security improvements and automation

Skills

AWS
Splunk
Active Directory
Azure
Google Cloud

Similar jobs