Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Houston, TX, United States
Posted
23 hours ago
SplunkAzure
Job Description
Position: Cyber Security Analyst (SOC)
Location: Houston, TX (4 days hybrid onsite)
Job Description:
Tier 1 Cyber Security Analyst (SOC) Position Summary The Tier 1 Cyber Security Analyst is responsible for the initial monitoring, detection, triage, and escalation of security events within a 24/7 Security Operations Center (SOC). This role serves as the frontline of cyber defense, leveraging SIEM and SOAR platforms to identify potential threats, investigate alerts, and ensure timely escalation according to established incident response procedures. This position requires a highly motivated, curious, and analytically driven individual who can think critically, adapt quickly, and operate effectively in a fast-paced environment.
Key Responsibilities
Monitoring & Alert Triage:
Key Responsibilities
Monitoring & Alert Triage:
- Monitor security events and alerts from SIEM platforms (e.g., Splunk) and other security tools.
- Perform initial triage and investigation of alerts to determine severity, scope, and potential impact.
- Analyze logs, network activity, endpoint data, and email security alerts (e.g., Proofpoint).
- Enrich alerts with contextual data (threat intelligence, asset data, user behavior).
Incident Handling & Escalation:
- Follow defined escalation paths to Tier 2/3 analysts based on severity, confidence, and impact.
- Document incidents, findings, and actions taken in case management systems.
- Execute basic response actions using SOAR platforms (e.g., Splunk SOAR).
- Assist in containment actions under guidance.
SOC Operations:
- Support 24/7 SOC operations, including shift work.
- Participate in shift handoffs.
- Maintain situational awareness of threats.
Platform & Tool Usage:
- Utilize Splunk SIEM.
- Use Splunk SOAR for automation.
- Investigate email threats using Proofpoint.
- Work with Microsoft and Azure security tools.
Continuous Improvement:
- Improve alert fidelity and reduce false positives.
- Provide feedback for detection tuning.
- Stay current on emerging threats.
- Required Qualifications
Education & Experience:
- Minium 2 years of experience in 24/7 SOC environment preferred
- Associate degree in Cybersecurity, IT, or related field OR equivalent SOC experience.
- CompTIA Security+ Certification Required
Technical Skills:
- Experience with Splunk, Splunk SOAR, Proofpoint
- Experience triaging alerts and escalation processes
- Knowledge of networking fundamentals and log analysis
- Familiarity with Microsoft and Azure platforms
Preferred Certifications:
- CompTIA CySA+ (preferred)
- Splunk Core Certified User
- Microsoft Security certifications (e.g., SC-200, AZ-500)
Core Competencies:
- Analytical thinking
- Attention to detail
- Strong communication
- Adaptability
- Curiosity and initiative
- Team collaboration
Working Conditions:
- 24/7 SOC environment including nights, weekends, and holidays
- On-call or extended hours during incidents
Success Metrics:
- Mean Time to Triage (MTTT)
- Escalation accuracy
- False positive reduction
- Documentation quality
- SLA adherence
Similar jobs
- TG
Security Architect
NewTalent Groups
Boston, MA🇺🇸On-site23 hours agoSSOMFATechnology - AN
Cyber Security Analyst
NewAnveta Inc
Arlington, VA🇺🇸$145k/yrOn-site23 hours agoAWSEncryptionOAuth+4Technology - MA
Information Assurance Engineer with Security Clearance
NewMANTECH
Crane, IN🇺🇸On-site23 hours agoEngineering - CF
Information Security Analyst
Cherokee Federal
Washington, DC🇺🇸$95k/yrHybrid3 days agoTechnology - CF
Senior Cyber Analyst
Cherokee Federal
Quantico, VA🇺🇸$130k - $160k/yrOn-site4 days agoRESTTechnology - EJ
Senior Security Engineer - Cloud & SIEM
NewEdward Jones
Saint Louis, Missouri🇺🇸Hybrid37 minutes agoGCPShellAWS+2Technology