Назад
Company hidden
7 часов назад

SOC Analyst (Cybersecurity)

123 850 - 161 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
SOC Analyst (SIEM/Cybersecurity): Monitoring, investigating, and improving security detections across cloud, endpoint, network, and application environments with an accent on SIEM operations, alert triage, detection tuning, and incident response. Focus on analyzing telemetry, mapping attack chains with MITRE ATT&CK, contributing to SOAR and AI-assisted workflows, and reducing false positives and response times.

Location: US, remote; up to 5% travel may be required. Only US persons can interview, and eligibility for a US Federal Security Clearance is required.

Salary: $123,850–$161,000 annually, plus equity in the form of stock options.

Company

hirify.global is a remote cybersecurity product company developing NodeZero, a platform for autonomous penetration testing and security assessment operations.

What you will do

  • Monitor, detect, triage, investigate, and respond to security events using an enterprise SIEM.
  • Support log ingestion, parsing, normalization, and telemetry health across AWS, Okta, endpoints, firewalls, and SaaS sources.
  • Build dashboards, visualizations, KPIs, and reporting that measure security visibility and SIEM effectiveness.
  • Tune and test behavioral, heuristic, and signature-based detection rules to improve fidelity and reduce false positives.
  • Perform structured investigations, root-cause analysis, attack-chain mapping, and remediation guidance for escalated alerts.
  • Contribute to response playbooks, proactive threat hunting, SOAR automation, and AI-assisted SOC workflows.

Requirements

  • 3–6 years of experience in a SOC or security analyst role, or equivalent hands-on security operations experience.
  • Hands-on experience with SIEM monitoring, alert triage, detection tuning, and incident response; Elastic SIEM, Splunk, Microsoft Sentinel, or QRadar experience required.
  • Proficiency with KQL, Lucene, or SPL and scripting in Python, Bash, or PowerShell.
  • Experience with at least one major cloud platform: AWS, GCP, or Azure, including relevant security tooling.
  • Working knowledge of MITRE ATT&CK, NIST, and CIS, plus strong log analysis, telemetry, event correlation, and documentation skills.
  • Must be a US person and eligible to successfully secure a US Federal Security Clearance.

Nice to have

  • Security+, CySA+, GCIA, GCIH, or Elastic Certified Analyst certification.
  • Experience with EDR/XDR, enterprise AI platforms, prompt and agent tooling, or agentic investigation workflows.
  • Experience mentoring junior analysts, improving processes, or working in a high-growth SaaS or cybersecurity company.

Culture & Benefits

  • Remote work with a collaborative, respectful, ownership-oriented, and results-focused culture.
  • Health, vision, and dental insurance for employees and families.
  • Flexible vacation policy and generous parental leave.
  • Career development opportunities, equity, and competitive compensation.
  • Chicago office available for roles that require regular in-office presence; this role is remote.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →