Haystack
← Back to Jobs
Technology
KI

Cyber Security Analyst (SOC)

Kainos Innovative Solutions IncHouston, TX🇺🇸United StatesPosted Oct 6, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Houston, TX, United States
Posted
23 hours ago
SplunkAzure

Job Description

Position: Cyber Security Analyst (SOC)
Location: Houston, TX (4 days hybrid onsite)
Job Description:
Tier 1 Cyber Security Analyst (SOC) Position Summary The Tier 1 Cyber Security Analyst is responsible for the initial monitoring, detection, triage, and escalation of security events within a 24/7 Security Operations Center (SOC). This role serves as the frontline of cyber defense, leveraging SIEM and SOAR platforms to identify potential threats, investigate alerts, and ensure timely escalation according to established incident response procedures. This position requires a highly motivated, curious, and analytically driven individual who can think critically, adapt quickly, and operate effectively in a fast-paced environment.
Key Responsibilities
Monitoring & Alert Triage:
  • Monitor security events and alerts from SIEM platforms (e.g., Splunk) and other security tools.
  • Perform initial triage and investigation of alerts to determine severity, scope, and potential impact.
  • Analyze logs, network activity, endpoint data, and email security alerts (e.g., Proofpoint).
  • Enrich alerts with contextual data (threat intelligence, asset data, user behavior).

Incident Handling & Escalation:
  • Follow defined escalation paths to Tier 2/3 analysts based on severity, confidence, and impact.
  • Document incidents, findings, and actions taken in case management systems.
  • Execute basic response actions using SOAR platforms (e.g., Splunk SOAR).
  • Assist in containment actions under guidance.

SOC Operations:
  • Support 24/7 SOC operations, including shift work.
  • Participate in shift handoffs.
  • Maintain situational awareness of threats.

Platform & Tool Usage:
  • Utilize Splunk SIEM.
  • Use Splunk SOAR for automation.
  • Investigate email threats using Proofpoint.
  • Work with Microsoft and Azure security tools.

Continuous Improvement:
  • Improve alert fidelity and reduce false positives.
  • Provide feedback for detection tuning.
  • Stay current on emerging threats.
  • Required Qualifications

Education & Experience:
  • Minium 2 years of experience in 24/7 SOC environment preferred
  • Associate degree in Cybersecurity, IT, or related field OR equivalent SOC experience.
  • CompTIA Security+ Certification Required

Technical Skills:
  • Experience with Splunk, Splunk SOAR, Proofpoint
  • Experience triaging alerts and escalation processes
  • Knowledge of networking fundamentals and log analysis
  • Familiarity with Microsoft and Azure platforms

Preferred Certifications:
  • CompTIA CySA+ (preferred)
  • Splunk Core Certified User
  • Microsoft Security certifications (e.g., SC-200, AZ-500)

Core Competencies:
  • Analytical thinking
  • Attention to detail
  • Strong communication
  • Adaptability
  • Curiosity and initiative
  • Team collaboration
Working Conditions:
  • 24/7 SOC environment including nights, weekends, and holidays
  • On-call or extended hours during incidents
Success Metrics:
  • Mean Time to Triage (MTTT)
  • Escalation accuracy
  • False positive reduction
  • Documentation quality
  • SLA adherence

Similar jobs