2 часа назад
SOC Analyst I
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SOC Analyst I (Cybersecurity/SIEM): Monitoring and triaging security alerts for managed customer environments in a 24/7 Cyber Fusion Center with an accent on Tier 1 incident investigation, evidence gathering, and clear ticket documentation. Focus on following investigation playbooks, meeting SLA and quality targets, identifying false-positive patterns, and escalating incidents with accurate handoffs.
Location: Onsite in Overland Park, United States; assigned shifts include weekend and holiday coverage
Company
is a security operations and managed detection and response provider helping organizations protect against cyberattacks.
What you will do
- Monitor and triage security alerts across Google Security Operations (Chronicle), the SOAR platform, and the ticketing queue.
- Investigate Tier 1 incidents end-to-end by reviewing alert context, gathering Chronicle UDM and supporting-tool evidence, documenting dispositions, and escalating when necessary.
- Follow investigation playbooks and identify gaps, outdated guidance, noisy rules, false-positive patterns, and alert clusters for review.
- Communicate clear, accurate investigation findings in tickets for customers, analysts, and auditors.
- Support customers with routine investigations, information requests, and exclusion or suppression requests under Team Lead oversight.
- Meet SLA and quality targets, participate in shift handoffs, and brief incoming analysts on open investigations and anomalies.
Requirements
- 0–2 years of experience in a SOC, IT security, IT operations, helpdesk, or NOC role; recent cybersecurity graduates are encouraged to apply.
- Working knowledge of core security concepts, including the cyber kill chain or MITRE ATT&CK, phishing, credential abuse, malware delivery, and lateral movement.
- Ability to explain SIEM functionality, alert generation, and the process of pivoting from an alert to supporting log evidence.
- Strong written communication and close attention to detail.
- Ability to work an assigned shift onsite in Overland Park, including scheduled weekend and holiday coverage.
- Security+ certification, or an equivalent certification, within 90 days of hire if not already held.
Nice to have
- Experience with Google Security Operations (Chronicle), Splunk, Elastic, or Microsoft Sentinel.
- Degree or current studies in IT Security or Cybersecurity.
- Familiarity with endpoint detection and response tools such as CrowdStrike, SentinelOne, Defender for Endpoint, or Carbon Black.
- Basic scripting or query experience with Python, PowerShell, SQL, or SIEM query languages.
- MSSP or multi-tenant environment experience and additional security certifications.
Culture & Benefits
- Humans-first culture centered on radical transparency.
- Medical insurance options, employer-paid dental coverage, and short- and long-term disability insurance.
- Three weeks of paid vacation, additional sick leave, and paid company holidays.
- Training, mentorship, and support for technical or leadership career growth.
- Exposure to AI-enhanced security tools, Google Cloud native technologies, and global customer environments.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →