Назад
Company hidden
9 дней назад

Security Operations Center (SOC) Analyst (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Operations Center (SOC) Analyst (Cybersecurity): Monitoring, investigating, and responding to security activity across endpoints, identity, cloud services, networks, and mission-support environments with an accent on SIEM, EDR, incident triage, and vulnerability management. Focus on analyzing suspicious activity, preserving evidence, escalating incidents with CUI impact, and documenting investigations across aerospace infrastructure.

Location: Los Angeles, CA, USA; in-person collaboration at the Playa Vista office.

Company

hirify.global manufactures satellite buses at scale by combining software, vertical integration, and manufacturing-focused hardware for commercial spacecraft platforms.

What you will do

  • Monitor and triage security alerts from CrowdStrike, Elastic SIEM, Microsoft Identity, AWS, and Palo Alto.
  • Investigate suspicious logins, phishing emails, privilege changes, and unusual network events across endpoints, identity, cloud, and network environments.
  • Scope and escalate incidents based on affected systems, severity, and CUI impact.
  • Collaborate with IT, Cybersecurity, and Network teams to resolve security findings.
  • Document incidents, resolutions, affected assets, evidence, and vulnerability-management findings.
  • Maintain recurring logging reviews and incident-response documentation.

Requirements

  • Active TS/SCI clearance and US citizenship are required at the time of hire.
  • At least 2 years of experience in SOC operations, incident response, threat detection, endpoint security, vulnerability management, or hands-on cybersecurity operations.
  • Experience investigating events with EDR, SIEM, identity, cloud, or network telemetry.
  • Working knowledge of Windows, Linux, authentication, endpoint behavior, networking fundamentals, attacker techniques, and cloud logging.
  • Ability to write SIEM or log-analysis queries and document investigations for continued work by other analysts.
  • Understanding of incident triage, scoping, containment, evidence preservation, escalation, vulnerability prioritization, and post-incident remediation.

Nice to have

  • Experience with CrowdStrike Falcon, Palo Alto, Tenable, Elastic Security, Microsoft GCC High, Entra ID, AWS security telemetry, or similar tools.
  • Experience with detection engineering, threat hunting, MITRE ATT&CK, or scripting in Python, PowerShell, or Bash.
  • Security+, CySA+, GCIH, GCIA, or comparable security operations certification.
  • Experience supporting aerospace, defense, national security, ATO, RMF, or other regulated technical environments.

Culture & Benefits

  • Equity participation and a fast-growing startup environment.
  • Company-paid medical, dental, and vision insurance for employees and dependents, plus life insurance.
  • Paid vacation, paid holidays, parental leave, and childcare reimbursement for work-related travel.
  • 401(k) plan with employer matching.
  • Catered lunch, unlimited snacks, office socials, sports activities, and family gatherings.
  • In-person collaboration at the Playa Vista office with workspace and productivity equipment provided.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →