SOC Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
SOC Analyst (Cybersecurity): Security monitoring and incident response across on-premises and cloud environments with an accent on SIEM/EDR/XDR event investigation, log correlation, and detection tuning. Focus on threat hunting, vulnerability management advisory, and improving security posture through secure configuration and control improvements.
Location: Remote (US)
Salary: $113,800–$139,000 annually
Company
is a real estate analytics, data solutions, and valuation technology company building confidence in real estate decisions.
What you will do
- Monitor, investigate, and respond to security alerts across SIEM, EDR/XDR, IDS/IPS, firewalls, cloud, identity, and endpoint security platforms.
- Conduct incident response and threat hunting, including alert triage, investigation, root cause analysis, containment recommendations, and follow-up actions.
- Use SIEM and related tools to correlate events, analyze logs, tune detections, reduce false positives, and improve alert fidelity.
- Analyze endpoint, authentication, firewall, VPN, cloud, and network activity to identify indicators of compromise and suspicious behavior.
- Advise on vulnerability management by reviewing findings, assessing technical risk, prioritizing remediation, validating closure, and communicating exposure and business impact.
- Provide security guidance for system hardening and secure configuration using CIS Benchmarks, vendor guidance, and organizational standards.
Requirements
- Location: Must be based in the US
- 5+ years of security experience with deep SOC experience in threat detection, incident response, and security event investigations.
- Proven experience investigating real security events using SIEM, EDR/XDR, firewall, identity, endpoint, cloud, or network telemetry.
- Strong understanding of incident response, threat hunting, attacker tactics, log analysis, event correlation, detection tuning, and security investigation workflows.
- Experience with vulnerability management: reviewing findings, assessing technical risk, prioritizing remediation, and advising system owners.
- Working knowledge of Windows, macOS, Linux, Active Directory, cloud environments, networking, endpoint security, CIS Benchmarks, NIST, CIS Controls, RMF, MITRE ATT&CK, and common protocols (DNS, HTTP/S, LDAP, SMB, Kerberos, SAML, OAuth).
Nice to have
- Relevant security certification (preferred: CompTIA CySA+, CompTIA CASP+, GIAC GCIH, GIAC GCIA, GIAC GSOC, GIAC GMON) or equivalent blue-team/SOC/IR/threat-hunting certification.
Culture & Benefits
- Comprehensive medical, dental, and company-paid vision insurance.
- 401(k) retirement plan with employer match and company contributions to health savings funds (with a high deductible plan).
- 401(k) retirement plan with employer match and paid time off (PTO) plus paid holidays.
- 401(k) retirement plan with employer match and employer-paid short-term disability coverage; access to Galileo (virtual primary care) and Rula (virtual mental health).
- Profit-sharing bonus program, communication stipends, and referral bonuses.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →