SOC Analyst Shift Lead
$92,000–$153,000 year
On-siteSan Antonio, Texas, United States or Hanover, Maryland, United States
Job Summary
Monitor security alerts and events in the Security Operations Center (SOC) and perform initial triage, analysis, and escalation. Investigate potential security incidents using SIEM, endpoint, network, and other security tools to determine scope, impact, and next steps. Document findings, actions taken, and incident details clearly and accurately in accordance with SOC procedures and reporting requirements. Escalate confirmed or high-risk incidents to senior analysts or incident response teams when appropriate. Support threat detection, alert tuning, and ongoing improvement of SOC monitoring processes and playbooks. Collaborate with internal teams to gather information, support investigations, and help protect enterprise systems and data. Stay current on common cyber threats, vulnerabilities, and attacker tactics, techniques, and procedures (TTPs).
Required Qualifications
- US Citizenship
- Ability to Obtain Public Trust
- Must be able to OBTAIN and MAINTAIN a PUBLIC TRUST
- Candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding
- Minimum of SIX (6)+ overall years of work experience
- Experience in cybersecurity, information technology, or a related technical support role
- Strong understanding of security operations, incident response, and common cyber threats
- Familiarity with SIEM tools, log analysis, and endpoint or network security concepts
- Strong analytical and problem-solving skills
- Ability to prioritize and respond to alerts in a fast-paced environment
- Excellent written and verbal communication skills
- Attention to detail and documentation accuracy
- Ability to work collaboratively with cross-functional teams
- Ability to follow established procedures
- High school diploma or equivalent
- Associate's or bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field
- Prior experience leading SOC shifts
- Prior experience mentoring jr. analysts
- Must be able to work full time
- Must be able to support SOC operations as needed
Desired Qualifications
- Active PUBLIC TRUST or SUITABILITY
- Experience with tools such as Splunk, QRadar, Microsoft Sentinel, or similar SIEM platforms
- Security certifications such as Security+, CySA+, GSEC, or equivalent
- Exposure to incident response, threat hunting, vulnerability management, or malware analysis
- Basic scripting or automation skills (Python, PowerShell, or similar)
- Knowledge of frameworks such as MITRE ATT&CK, NIST, or CIS controls
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.